A vendor risk assessment for CRE debt management software is the review your IT, compliance and finance teams perform, on evidence rather than answers, before loan documents, rent rolls, operating statements and lender correspondence are stored and processed by a third party. It covers how the vendor protects the data, who can see it, what happens when the vendor’s systems fail, what happens when the vendor fails, and how you get your data back. Most vendors in this category will answer the questionnaire you send. The useful exercise is knowing which answers matter and what evidence to require.
LoanBoss publishes its security posture and provides a completed vendor risk assessment on request. We have used our own document as the basis for the checklist below, and we have tried to write it so it applies to any vendor.
Why debt software deserves a real assessment
Property accounting systems have been through this review. Debt platforms often have not, because they arrived later and were bought by finance rather than IT. Yet a debt platform holds the most sensitive documents in the firm: loan agreements with pricing, guaranties with personal financial information, covenant positions, and hedge confirmations. Institutional investors and lenders increasingly ask owners how that data is protected. The assessment is a fiduciary exercise, not a formality.
The checklist
Security controls
- Independent audit. An annual SOC 2 Type II report covering security, availability and confidentiality, from a recognized auditor, unredacted, with a bridge letter if the period has lapsed. A Type I report or a self-attestation is not equivalent. See SOC 2 Type II and loan management software.
- Encryption. In transit with TLS 1.2 or higher; at rest with AES-256. Ask where keys are managed.
- Access control. Role-based permissions granular enough to give an auditor read-only access to one entity’s loans. Multi-factor authentication. Access logs retained and reviewable.
- Vulnerability management. Patching cadence, penetration testing frequency, and who performs it.
- Personnel. Background checks, security training, and how contractor access is controlled.
Data governance
- Ownership. The contract should state that the customer owns its data and the vendor has no right to use it beyond providing the service.
- Segregation. How customer data is isolated from other customers’.
- Subprocessors. Cloud provider, any offshore abstraction or support teams, AI services. Ask for the list and the notification process when it changes.
- AI use. If the vendor uses AI for document extraction, ask whether your documents train any model and where inference runs.
- Retention and deletion. What is deleted at termination, when, and how it is certified.
Continuity
- Architecture. Multi-region, redundant infrastructure. Automated backups with tested restores.
- DR and BCP. A documented, tested disaster recovery plan and business continuity plan with recovery time and recovery point objectives.
- Uptime. Historical availability and the commitment in the contract.
- Vendor viability. Ownership, funding, years in operation, customer concentration. A debt platform that disappears mid-quarter is a continuity event.
Exit
- Export. Every loan abstract, calculation and report exportable in a usable format, by the customer, without vendor assistance.
- Transition assistance. What the vendor provides at termination and for how long.
- Escrow. Rarely needed for SaaS, but ask if the platform is core to your compliance.
What LoanBoss provides
For each item above, this is what we publish and provide:
- Annual, independent SOC 2 Type II audits validating security, availability and confidentiality controls, with the full unredacted report available for your compliance team.
- TLS 1.2+ in transit and AES-256 at rest, on redundant cloud infrastructure.
- Granular role-based permissions so team members, partners and auditors see only the data they need, with all access logged for an auditable trail.
- Multi-region, highly available architecture with automated backups and a tested DR and BCP.
- A completed vendor risk assessment, which we describe on loanboss.com as the most comprehensive you will find, available for download so your IT and compliance teams can start from a finished document.
We consider ourselves a fiduciary partner rather than a software provider. That is a claim; the documents are the evidence.
| Checklist area | Evidence to require | What LoanBoss provides |
|---|---|---|
| Security controls | Annual SOC 2 Type II covering security, availability and confidentiality, unredacted, with a bridge letter if the period has lapsed; TLS 1.2+ in transit and AES-256 at rest; role-based access with MFA and retained access logs | Annual independent SOC 2 Type II audits covering those three criteria, with the full unredacted report; TLS 1.2+ in transit and AES-256 at rest; granular role-based permissions with all access logged |
| Data governance | Ownership clause, customer segregation, subprocessor list and change notification, AI use disclosure, deletion at termination | Abstraction performed by an in-house team; other items not stated |
| Continuity | Multi-region redundancy, automated backups with tested restores, documented and tested DR and BCP with recovery objectives, uptime history, vendor viability | Multi-region, highly available architecture with automated backups and a tested DR and BCP |
| Exit | Export of every abstract, calculation and report by the customer without vendor assistance; transition assistance; escrow if the platform is core to compliance | Not stated |
| Completed assessment | A finished vendor risk assessment your IT and compliance teams can start from | Available for download |
What a weak answer looks like
Vendors rarely refuse a question. They answer it softly. Some translations:
- “We follow industry-standard security practices.” No independent audit. Ask for the SOC 2 Type II report.
- “We are SOC 2 compliant.” Possibly a Type I, possibly lapsed. Ask for the type, the period and the bridge letter.
- “Data is encrypted.” In transit, at rest, or both, with what. Ask for TLS version and at-rest algorithm.
- “We use a leading cloud provider.” The provider’s controls are not the vendor’s. Ask for the vendor’s own report and the provider’s as a subservice organization.
- “Backups are performed regularly.” Ask for frequency, retention, and the date of the last tested restore.
- “We have never had a breach.” Ask about the incident response plan and whether it has been exercised.
- “Your data is yours.” Ask to see the clause, and the export mechanism.
- “Our AI does not train on customer data.” Ask where inference runs, which model provider, and whether prompts are retained.
Sizing the assessment to the risk
An owner with ten loans and no institutional investors can run a lighter review: the SOC 2 report, the encryption and access answers, the exit clause. A fund manager with institutional LPs, an audit committee and lender due diligence should run the full checklist, involve IT and legal, and refresh annually. The data is the same sensitivity in both cases; the consequences of a gap are not. A reasonable rule: the assessment should take about as long as the platform’s onboarding takes your team, and no longer.
Running the assessment efficiently
- Send your standard questionnaire, but attach the checklist above and ask for evidence, not answers.
- Request the SOC 2 report under NDA first. It answers half the questionnaire.
- Ask IT to review the architecture and access sections; ask legal to review ownership, subprocessors and exit; ask finance to review continuity and viability.
- Keep the assessment on file and refresh it annually with the new SOC 2 report.
Frequently Asked Questions
Our lender asked how our debt data is protected. What do we send?
The vendor’s SOC 2 summary and your own access policy. Lenders are used to reviewing SOC 2 reports.
Is on-premises safer?
Rarely, for a firm without a security team. A SOC 2 Type II cloud platform with tested DR is usually stronger than a server in an office.
What if the vendor uses offshore teams for abstraction?
Ask where the documents are processed, under what access controls, and whether it is disclosed as a subprocessor. LoanBoss abstraction is performed by an in-house team.
How often should we reassess?
Annually, on receipt of the new SOC 2 report, and whenever the vendor changes ownership or subprocessors.
What is the minimum evidence to require from any vendor?
An annual SOC 2 Type II report covering security, availability and confidentiality, unredacted, with a bridge letter if the period has lapsed. A Type I report or a self-attestation is not equivalent. Request it under NDA first, because it answers half the questionnaire.
Related reading
- SOC 2 Type II and loan management software
- RFP criteria for a CRE debt management system
- Implementation timelines and what onboarding should include
- JLL Debt Management System alternatives
- Best CRE debt management software 2026
This guide reflects publicly available information as of September 2026. Regulatory references are provided for context and are not legal advice.
Sources
- AICPA, SOC 2 Trust Services Criteria (Security, Availability, Confidentiality)
- NIST Cybersecurity Framework 2.0 and NIST SP 800-161, supply chain risk management
- OCC Bulletin 2023-17, Interagency Guidance on Third-Party Relationships
- LoanBoss security page and vendor risk assessment documentation, loanboss.com