Third-party risk · SOC review

Your team spends three hours reading each SOC report. It should take ten minutes.

Assurewright reads vendor SOC 1 and SOC 2 reports, surfaces the exceptions that actually matter, and keeps a record of every review decision that holds up when an examiner asks.

Built by a former Head of Internal Audit. Currently working with a small number of design partners.

Demo video coming soon A full walkthrough is being recorded now. In the meantime, get in touch for early access and I'll show you the platform directly. Contact for early access
Full walkthrough — vendor intake, live SOC 2 analysis, reviewer decisions, contract negotiation, and the audit trail.
The problem

Vendor assurance doesn't fail loudly. It fails quietly.

Most third-party risk programs are one busy afternoon away from approving a vendor nobody actually vetted.

A SOC 2 Type II runs 40 to 100 pages. Reading one properly takes two to four hours, and a mid-sized program reviews 50 to 200 a year.
The findings that matter are buried: a qualified opinion, exceptions in the testing tables, carved-out subservice organisations, complementary user entity controls you're expected to operate.
The requestor's answers and the vendor's own questionnaire routinely contradict each other, and nobody is comparing them line by line.
When an examiner asks why a vendor was approved, the reasoning is scattered across email threads and somebody's memory.
How it works

Read the report. Route the risk. Record the decision.

📄

Reads the actual report

Extracts and analyses the document itself — auditor's opinion, report type and period, testing exceptions, carve-outs and CUECs — then presents the findings with the supporting passage highlighted.

🔀

Routes by real risk

The answers drive the workflow. Personal data pulls in Privacy, system access pulls in Network Security, non-standard payment terms pull in Accounts Payable. Configurable without a developer.

⚖️

Compares both sides

The requestor's intake answers and the vendor's own questionnaire are checked against each other. Contradictions on MFA, encryption or data handling are flagged before anyone approves.

🛡️

Stops blind approvals

Reviewers cannot approve a vendor without attesting that they reviewed each flagged finding. Rejecting or asking for more information carries no such gate.

📝

Handles the paperwork

Send DPAs and contracts to the vendor in-platform, receive their redlines, and see exactly which terms changed — liability caps, breach notification windows, sub-processor rights.

🔎

Leaves a defensible trail

Every decision, rationale, flag, contradiction and workflow change is recorded with who did it and when. The answer to "why did we approve this" is on one screen.

What it catches

The findings a tired reviewer misses at 4pm on a Friday.

Real output from a SOC 2 Type II in the demo — produced from the report itself, not the filename.

AI ANALYSIS — SOC 2 TYPE II
🔴Qualified opinion. The service auditor concluded logical access controls did not operate effectively during the period.
🔴CC6.2 — quarterly access reviews were not performed in Q2 or Q3. Four of twelve months without detective review.
⚠️CC6.3 — three of twenty terminated users retained production access, one for twenty-two days.
⚠️Remediation post-dates the period. Fixes are dated after the report closed, so effectiveness is unproven.

Kevin Burke — founder

I spent my career in internal audit, most recently as a Head of Internal Audit. I've sat on both sides of this process: reviewing vendors under time pressure, and being the person an examiner asks to justify a decision made eighteen months earlier.

Assurewright is the tool I wanted. It encodes the judgement that usually lives in one experienced reviewer's head — which findings matter, which are noise, and what has to be resolved before a vendor gets through.

I'm working with a small group of design partners to shape where it goes next. If third-party risk is your problem, I'd like to hear how you handle it today.

Why this exists

Built by someone who had to sign off on the answer.

Most compliance software is built by engineers who interviewed a compliance team. The difference shows up in what the tool decides to flag — and in what it correctly ignores.

Get in touch

See whether this fits your programme.

Tell me a little about how your team handles vendor reviews today and I'll follow up personally — usually within a day.

This tells me more about whether we're a fit than anything else you could write.

No newsletter, no sequence. Your details go to me and nowhere else.

Thanks — that's come through.

I'll be in touch within a day, usually sooner. If it's urgent, email me directly at .