August 19, 2026 · Innovate NorthTech
How to Vet SaaS Vendors When You Don't Have a CISO
Your cyber insurance renewal just arrived. Page four has a new section asking how you manage third-party vendor risk. You have a few dozen employees, no Chief Information Security...
- vendor-risk
Your cyber insurance renewal just arrived. Page four has a new section asking how you manage third-party vendor risk. You have a few dozen employees, no Chief Information Security Officer, and dozens of SaaS applications floating around your company. You cannot justify a five-figure annual bill for an enterprise risk management platform. So what do you actually do?
Let us be honest. It is rarely your core HR platform that causes a data breach. Workday and BambooHR spend millions on security. The real threat is the free PDF compressor your marketing coordinator used to shrink a client report. Or the free version of ChatGPT that a sales rep is using to summarize confidential client transcripts, completely unaware that the data is being ingested into a public model.
When you do not have a dedicated security team, vendor risk management usually defaults to doing nothing until the auditors or insurance brokers yell at you. But ignoring it is no longer an option. Toronto businesses are facing stricter compliance demands from their own enterprise clients. Here is how a small IT team can run a vendor risk program without drowning in spreadsheets.
Step 1: The “Kill It With Fire” Inventory
You cannot secure what you do not know exists. Before you start sending out security questionnaires, you need to find the shadow IT.
Do not ask your team what they use. They will forget half of it. Instead, look at the money and the access. Pull the last quarter of corporate credit card history and look for small recurring software charges. Then, go into Microsoft Entra ID (formerly Azure AD) or Google Workspace. Look at the OAuth permissions. You will likely find dozens of random applications with read and write access to your company emails or files.
Revoke access for anything that has not been used in three months. Cancel the credit card subscriptions for redundant tools.
Step 2: The Three-Tier Triage
Do not treat every vendor equally. A 100-person firm does not have the hours to vet a graphic design tool the same way they vet a payroll provider. Divide your vendors into three buckets.
- Tier 1: Core systems containing sensitive customer data, financials, or source code. Think Microsoft 365, Salesforce, or AWS.
- Tier 2: Operational tools that hold internal data but not the crown jewels. Think Slack, Asana, or Mailchimp.
- Tier 3: The junk drawer. Tools with no access to sensitive data, like a digital whiteboard or a basic stock photo subscription.
Spend most of your time on Tier 1. Tier 3 vendors get a quick glance at their privacy policy and a credit card swipe.
Step 3: Ditch the 200-Question Spreadsheet
Enterprise companies love sending massive Excel spreadsheets to assess risk. If you send a 200-question document to a vendor for a small contract, they will ignore you.
Keep it simple. Ask Tier 1 and Tier 2 vendors for their SOC 2 Type II report. When they send it, do not just file it away. Open it and scroll to Section 4 to look for exceptions. If the auditor noted that the vendor failed to revoke system access for terminated employees, that is a red flag you actually need to care about.
If they do not have a SOC 2, ask for a completed CAIQ (Consensus Assessments Initiative Questionnaire). This is a standard document most reputable software companies keep on hand.
Also, check their data residency. If you are a Canadian business dealing with government or healthcare clients, you need to know if your data is sitting in a Toronto data centre or if it is hosted in the US and subject to foreign jurisdiction.
Step 4: Use Cheap or Free Tools
You do not need to buy a massive governance platform like OneTrust. If you are already using compliance automation software like Vanta or Drata for your own SOC 2 prep, use their built-in vendor modules. They are included in what you already pay for those platforms.
If you have zero budget, use the Whistic Trust Catalog. It is a free database where you can view security profiles for thousands of vendors. For tracking renewal and compliance expiration dates, a simple SharePoint list or Airtable base is entirely sufficient for a company with under 100 vendors.
Stop the Bleeding
A vendor risk review is useless if employees keep adding new software behind your back. You need to block third-party app installations at the admin level. In Google Workspace and Microsoft 365, change the settings so users cannot grant apps access to their accounts without IT approval. Write a one-page policy that says if it touches company data, IT needs to see it first. Make the approval process fast, or people will find a way around it.
How we approach this
At Innovate NorthTech, we know that a 50-person company cannot operate like a bank. We usually start by pulling your Microsoft 365 or Google Workspace logs to see exactly what applications are already connected to your environment. Then, we help you build a lightweight, automated approval workflow using the tools you already pay for. If you are struggling to satisfy a cyber insurance broker or an enterprise client’s security demands, send us a note. We can help you build a vendor risk process that actually works for your scale.