Your organization's identity verification is only as secure as your vendor's infrastructure. The breach of 153 million driving license records at IDscan.net, a supplier for Hertz, Target, FedEx, and other major enterprises, underscores the critical importance of third-party risk management in identity verification processes.
This checklist helps you evaluate and monitor identity verification vendors before they become your organization's liability. Each item includes the specific evidence you need to see and what "good" looks like in practice.
Prerequisites
Before you start this assessment, gather:
- Your current identity verification vendor contracts and SLAs
- A list of all third-party services that process identity documents or Personally Identifiable Information (PII)
- Your organization's data classification policy
- Compliance requirements (GDPR, CCPA, SOC 2, ISO 27001) that apply to your operations
- Contact information for vendor security and compliance teams
You'll need access to vendor documentation and the authority to request security assessments. If you don't have procurement or legal support, get it now. This isn't a technical-only review.
Vendor Security Posture Checklist
1. Data Storage and Encryption
Done when: You've verified that identity documents are encrypted at rest using AES-256 or stronger, with documented key management procedures that include key rotation schedules and Hardware Security Module (HSM) integration.
What good looks like: The vendor provides a detailed encryption architecture document showing separate encryption keys per customer, automated rotation every 90 days, and HSM-backed key storage. You receive evidence of third-party validation.
2. Access Controls for Identity Data
Done when: You've confirmed the vendor implements Role-Based Access Control with documented approval workflows, enforces Multi-Factor Authentication for all administrative access, and maintains audit logs of every identity document access.
What good looks like: The vendor shows you their access control matrix, demonstrates their approval workflow in action, and provides sample audit logs showing timestamp, user, document ID, and action taken. They can prove that fewer than five people have production database access.
3. Data Retention and Deletion
Done when: You've documented the vendor's retention policy, verified they honor deletion requests within your required timeframe, and confirmed they delete data from backups.
What good looks like: The vendor contract specifies retention periods that match your compliance requirements, includes a deletion API or process you've tested, and provides a certificate of destruction after data deletion that covers all storage tiers.
4. Third-Party Penetration Testing
Done when: You've reviewed penetration test reports from the last 12 months conducted by an independent firm, verified that critical findings were remediated, and confirmed testing scope included identity document processing systems.
What good looks like: The vendor provides a full penetration test report showing testing of document upload, storage, and retrieval systems. Critical findings have remediation evidence. Testing occurs at least annually.
5. Incident Response Plan
Done when: You've reviewed the vendor's incident response plan, confirmed it includes customer notification procedures with specific timeframes, and verified they've conducted tabletop exercises in the last year.
What good looks like: The plan specifies notification within 24 hours of a confirmed breach, includes your security team's contact information, and defines what constitutes a reportable incident. The vendor provides evidence of their last tabletop exercise and any improvements made afterward.
6. Compliance Certifications
Done when: You've verified current SOC 2 Type II certification (or equivalent), confirmed the audit scope includes identity verification systems, and reviewed any exceptions or qualifications in the report.
What good looks like: The SOC 2 report is less than 12 months old, covers all systems that process your data, and shows zero qualified opinions. The vendor proactively shares upcoming audit schedules and invites you to submit specific control testing requests.
7. Subprocessor Disclosure
Done when: You've received a complete list of all subprocessors who may access identity data, verified each has appropriate security controls, and confirmed you'll receive notice before new subprocessors are added.
What good looks like: The vendor maintains a public subprocessor list, updates it within 30 days of changes, and provides Data Processing Agreements for each subprocessor. You can object to new subprocessors before your data is shared.
8. Data Breach History
Done when: You've asked directly about previous breaches, reviewed any public disclosures, and assessed how the vendor responded and what controls they implemented afterward.
What good looks like: The vendor discloses any previous incidents transparently, shows root cause analysis documents, and demonstrates specific control improvements. If they claim zero breaches, verify their detection capabilities.
9. Contractual Liability and Insurance
Done when: You've confirmed the contract includes specific liability terms for data breaches, verified the vendor carries cyber insurance with adequate coverage, and documented your rights to audit.
What good looks like: The contract specifies liquidated damages or liability caps that match your potential exposure, requires cyber insurance of at least $5 million, and grants you audit rights with reasonable notice.
10. Data Residency and Cross-Border Transfers
Done when: You've documented where identity data is stored and processed, confirmed this meets your compliance requirements, and verified appropriate transfer mechanisms are in place.
What good looks like: The vendor provides a data flow diagram showing every location where your data may exist, confirms data never leaves approved jurisdictions, and maintains current Standard Contractual Clauses if EU data is involved.
Common Mistakes
Accepting vendor questionnaires without verification. Security questionnaires are a starting point, not evidence. Request proof for every "yes" answer that matters.
Assuming compliance certifications cover your use case. SOC 2 reports have defined scopes. Read the actual report to confirm identity verification systems were tested.
Ignoring the vendor's vendors. Subprocessors inherit all the same risks. If your vendor uses cloud storage, you need to know which provider, in which region, and under what controls.
Treating this as a one-time assessment. Vendor security posture changes. Schedule quarterly reviews of critical vendors and annual full reassessments.
Skipping the breach response test. Ask your vendor to walk through their notification process with your team. If they can't explain who calls whom within the first hour, their incident response plan is theoretical.
Next Steps
Start with your highest-risk vendor, the one processing the most sensitive identity data or supporting your most critical business process. Complete this checklist within 30 days.
For any item you can't mark "done," document the gap and assign a remediation owner. If the vendor can't provide evidence for items 1, 2, 5, or 6, start evaluating alternatives immediately.
Build this assessment into your vendor onboarding process. No identity verification vendor should go live without completing this checklist. Remember, you're not auditing your vendor to be difficult. You're protecting the people whose identity documents you're asking them to trust you with.




