Skip to main content

New: AI Privacy Impact Assessments for teams shipping AI features. Learn about AI-PIAs

Vendor security reviews · Nonprofit

Vendor Security Review & Questionnaire Support for Member Associations & Professional Regulators

A vendor security review examines the platform you are about to trust with registrant, complaint or member data before the contract is signed, not after a CNO- or CPA Canada-style incident forces the question. We read the vendor's evidence, map where biometric and cross-border data actually goes, and mark up the contract clauses that matter, whether you are replatforming to Thentia or Alinity, adding a remote-proctoring vendor, or renewing your AMS.

Reviewed by the Privacy Horizon team · Last reviewed

What you're protecting

The vendor platforms carrying your registrant and complaint files

A regulator's most sensitive data spends most of its working life inside a handful of outside systems, each deserving scrutiny proportional to what it holds.

The regulatory core or AMS itself

Whether you run Thentia Cloud, Alinity, iMIS, Member365 or a Salesforce-based platform in the Fonteva or Nimble class, this single system typically holds registration, complaints, renewals and payments together, making it the highest-stakes review you run.

Remote-proctoring and exam vendors

Providers such as Meazure Learning, Pearson VUE, Examity or Proctorio collect candidate ID, video and sometimes biometric templates alongside accommodation evidence, all of it your problem the moment a candidate complains.

Payment processors on the renewal portal

Card processors like Moneris or Stripe sit inside your busiest annual window, and their integration choices shape how much card data ever touches your own systems.

Election and voting platforms

Council elections run through providers such as Simply Voting or ElectionBuddy, handling voter eligibility and ballot data during exactly the moments governance disputes are most likely to surface.

Regulatory map

Why this sector's contracts turn vendor vetting into a duty

Outsourcing the platform never outsources the accountability, and several regimes make pre-contract diligence explicit rather than optional.

Law 25's assessment before data leaves Quebec

Where Quebec's private-sector Act reaches your organization, communicating personal information outside the province requires a privacy assessment concluding it will receive adequate protection, which for a US exam or AMS vendor means doing the work before signing.

Primary source →

Alberta PIPA's notice for outside-Canada providers

Section 13.1 requires notifying individuals when a service provider outside Canada will handle their information, a duty that starts with knowing exactly where your AMS or proctoring vendor hosts and processes data.

Primary source →

FIPPA accountability for BC public bodies

A governing body in FIPPA Schedule 3 remains accountable for personal information in a contractor's hands, so procurement needs safeguard, breach-notice and access-request cooperation terms with real teeth.

Primary source →

Section 36 confidentiality flows down to vendors

A platform hosting complaint or discipline files inherits the same statutory confidentiality expectation your staff and council carry, and the contract needs to say so explicitly rather than assume it.

Primary source →

The OPC's biometrics bar for exam vendors

Express consent, verification over identification, minimal data and destruction after purpose are the standard your proctoring vendor's contract and configuration both need to meet, not just its marketing claims.

Primary source →

What goes wrong

What a bad vendor choice has already cost bodies like yours

The sector's defining incidents keep tracing back to a platform decision made without this kind of scrutiny.

  • Proctoring vendors that fell short on consent

    An OPC-funded uOttawa report found Respondus, Proctorio, ProctorU and Examity lacked clear individual consent and carried discrimination risk, findings a pre-contract review would surface before candidates ever sit an exam.

    Source →

  • Concentration risk in a handful of shared platforms

    When most bodies in a profession run on the same two or three AMS or credentialing vendors, one supplier's weakness becomes many organizations' exposure at once, which is why the review checks the vendor's own posture, not just its client list.

  • Backups and subprocessors nobody asked about

    A platform's marketing rarely mentions who its hosting, support or analytics subprocessors are, or how long backups persist after a registrant's record is supposedly deleted. The review asks both questions directly.

  • Breach terms that leave you notified last

    A vendor's own timeline for confirming an incident can leave a regulator explaining a breach to registrants before the vendor has even finished its investigation. We negotiate notice windows and cooperation duties into the agreement up front.

Our vendor security reviews for member associations & professional regulators

What the review covers before a contract is signed

The service applies structured assessment to the vendor's evidence and the contract in front of you, sized to what the platform will actually hold.

Late-Night Developer: Hands of a Programmer at Work
  1. Evidence collection and reading

    We obtain and interpret SOC 2 reports, ISO certificates and questionnaire responses for your AMS, credentialing platform or proctoring vendor, separating substance from sales material.

  2. Biometric and proctoring data-flow review

    For any exam vendor, we map what identity data is captured, whether templates or raw images are retained, retention periods and who can access recordings after the sitting.

  3. Cross-border and residency mapping

    Where your registrant, complaint or candidate data will live, transit and back up, checked against Law 25's s. 17 test and Alberta's s. 13.1 notice duty.

  4. Contract clause markup

    Safeguards, breach-notification timelines, audit rights, subprocessor controls and exit terms including certified data return and deletion, marked up for negotiation before signature.

  5. A decision memo for the Registrar and council

    Findings, residual risks and recommended contract conditions in a short document a Registrar can bring to council or a board committee, with technical detail annexed.

How the engagement runs

How a vendor review runs around your renewal and exam calendar

Most reviews complete within a normal procurement cycle, and a migration or exam-season deadline is a scoping input rather than a surprise.

  1. Step 1

    Define the data and the stakes

    We start from what the vendor will hold, registration files, complaint data, exam candidate information or payment details, and set the review's depth accordingly.

  2. Step 2

    Engage the vendor for evidence

    We request assurance reports, questionnaire responses and, where needed, evidence under NDA, and chase the follow-up so your staff are not doing that work.

  3. Step 3

    Analyze and verify claims

    Responses are checked against the actual reports and configuration facts, with vague or missing answers pursued rather than accepted at face value.

  4. Step 4

    Report, negotiate, decide

    You receive the memo and marked-up contract terms; we support the negotiation call if the vendor pushes back on any condition.

What it costs

What determines the price of a regulator's vendor review

The main variables are how many vendors are in scope, whether an exam or proctoring platform with biometric data is involved, how much cross-border exposure the review has to map, and how cooperative the vendor's evidence trail proves to be. A single AMS review with contract markup is well-bounded work; standing up a review process across your full vendor list is a program we can phase.

Ongoing vendor oversight, including annual re-review of your core platforms, is also built into our Virtual Privacy Office retainer for organizations expecting several selections and renewals over time. We quote fixed fees per review after a short intake call.

Member Associations & Professional Regulators: Vendor security reviews questions, answered

Five things above all: where the data and its backups are hosted and for how long; what independent assurance exists, a current SOC 2 Type II or ISO 27001 certificate rather than a marketing badge; how quickly and completely the vendor commits, in contract language, to notifying you of an incident; which subprocessors touch your registrant and complaint data; and what happens at exit, including certified deletion. A vendor unwilling to answer plainly on any of these is answering anyway.

Ask exactly what is captured during a sitting, whether the vendor stores raw video and images or only derived templates, how long each is retained and who can access it afterward, and whether the vendor can demonstrate express consent from candidates rather than assumed acceptance. The OPC's 2025 biometrics guidance gives a concrete checklist: verification rather than identification, minimal data, and destruction once the sitting's purpose is served.

If Law 25 reaches your organization, s. 17 requires a privacy assessment before Quebec candidates' information crosses the border, concluding the vendor's environment offers adequate protection, documented in writing with any mitigating contract terms. Alberta's s. 13.1 separately requires notifying individuals that a service provider outside Canada will handle their information. Both obligations attach to the vendor relationship itself, so we build the assessment into the review rather than treating it as a later legal add-on.

Request the current SOC 2 Type II report under NDA, not a summary letter, and read the auditor's opinion, any noted exceptions, and the complementary user-entity controls, the duties the report assumes you perform, such as managing your own user access and enforcing MFA. A Type I report or a pending audit is a caution flag proportional to how much complaint or exam data the platform holds. If interpreting audit reports is not a skill you want to build in-house, that reading is exactly what this service supplies.

Yes, and peer adoption is a starting point, not a substitute. Wide use across colleges tells you the vendor understands the sector, but it says nothing about your specific configuration, access controls or contract terms, and a shared vendor also means a shared exposure if that platform is ever compromised. We still request current assurance reports and map your own data flows even for a well-known name.

Annually for the platforms holding your registrant, complaint or exam data, refreshing the assurance report and checking for new subprocessors or hosting changes. Re-review immediately on triggers such as a disclosed incident anywhere in the vendor's client base, an acquisition of the vendor, a major feature launch like new biometric capture, or your own move into a new province with different notice duties.

What's Protecting Your Business from the Next Threat?

Don't wait for a breach to expose your vulnerabilities. Let Privacy Horizon secure your data, ensure compliance, and build lasting trust.

(647) 622-2644

Free, no obligation

Get a quote

Tell us what you need and we'll come back within one business day with a tailored quote.

We only use your details to respond to this request.