| ▲ | louthy 4 hours ago | |
If you want to be certified for SOC or ISO in the US you have to check all your suppliers too. You can’t outsource your responsibility if you want to comply. I know this because I have been through it in the US, EU, and UK. If your supplier has these compliance audits in place and has the documentation to prove it, this isn’t “absolving”, it’s literally the diligence process. But a “shell company”, as per your original comment, is not going to reach a compliance threshold to allow the diligence chain to succeed. Just from a business continuity point of view they would fail, but there are plenty of other areas that would be problematic from a compliance standpoint. | ||