Employee survey vendor security checklist: SOC 2, ISO 27001, SSO

SOC 2, ISO 27001, data handling, access control, data residency, and AI transparency are the security requirements every employee survey vendor must meet before you sign.

Ask your vendor the right security questions

"Who can see our survey results?"
You
How to run the vendor review
Written by
Dhanya Satheesh, Content Marketer at CultureMonkey
Dhanya Satheesh · Content Marketer
50+ articles on survey design, vendor evaluation, and where engagement programs break down.
Data verified by
Engineering and Compliance Team
CultureMonkey's engineering and compliance team verified the certification, SSO, access-control, and AI-control statements on this page against primary sources.
Published
11 min read
TL;DR
  • An employee survey vendor security checklist is a structured set of questions covering six areas: certifications and audit evidence, data handling and encryption, access control and SSO, hosting and data residency, privacy and anonymity, and incident response. Use it to verify a vendor's security posture before signing a contract.
  • For certifications, SOC 2 (ask for Type II, which shows controls worked over time, not just on one day) and ISO 27001 (an independently audited certification for how the whole organisation manages security) are not interchangeable: a vendor can hold one without the other.
  • For access, require SAML/IDP SSO (a secure single sign-on standard, compatible with Okta and Azure AD), role-based access with least-privilege defaults (so each person only sees what their job requires), and page-level security over who can view which results.
  • For AI, ask per feature: is it on by default or opt-in, and can each feature be switched off?
  • A vendor security review is multi-stage; send the NDA and full docs up front, and expect weeks to months.
01

What should an employee survey vendor security checklist cover?

The short answer is six areas: certifications and audit evidence, data handling and encryption, access control and SSO, hosting and data residency, privacy and anonymity plus AI, and incident response and support. Cover all six before you sign, not just the one your last vendor happened to volunteer. Start from CultureMonkey's security and compliance page to see how one vendor presents this, then hold every finalist to the same bar.

Certifications and audit evidence
Ask for a current SOC 2 report and an ISO 27001 certificate, plus a recent penetration-test summary (an independent hacker-style test of the system's defences), so the vendor's security is independently verified rather than self-asserted.
Data handling and encryption
Confirm encryption in transit and at rest (so data is protected both while it travels and while it is stored), a written retention and deletion policy, a full sub-processor list (third-party tools or services the vendor uses to process your data), and a committed breach-notification timeframe in writing (how quickly they are required to tell you if something goes wrong).
Access control and SSO
Require SAML/IDP-based single sign-on (the technical handshake that connects your company's existing login system to the survey tool), role-based least-privilege access, and page-level security over who sees which results.
Hosting and data residency
Ask where the data is hosted and with which cloud provider, and whether you can choose or confirm the specific region your survey data lives in.
Privacy and anonymity plus AI
Look for configurable anonymity thresholds, the ability to hide free-text and names below them, and clear, per-feature control over any AI analysis of survey comments.
Incident response and support
Expect a documented incident-response process, a named security contact or escalation path, and responsive support if you detect a suspected security issue.
02

25+ Security questions to send your employee survey vendor

Send this checklist to any employee survey vendor, as-is, in an RFP or a live security review. Every item is a yes/no question, not a vague area to discuss. For the broader commercial and implementation review around it, pair it with a full vendor evaluation checklist.

01Certifications and audit evidence

02Data handling and encryption

03Access control and SSO

04Hosting and data residency

05Privacy, anonymity and AI

06Incident response and support

03

Should I ask a survey vendor for SOC 2 or ISO 27001?

SOC 2 and ISO 27001 are not interchangeable, and a vendor holding one does not automatically hold or need the other. ISO 27001 is an internationally recognised standard; SOC 2 is an AICPA-defined framework. Know what each actually proves before you accept either as sufficient, and match it to what your own compliance team requires when you shortlist employee engagement survey tools.

DimensionSOC 2ISO 27001
What it isA US-originated independent security audit report on how a vendor controls and protects data.An internationally recognized certification for an information security management system (a formal, audited rulebook for how they protect data).
ScopeFocuses on a recognised set of security, availability, and confidentiality standards.Focuses on a documented ISMS covering the organization's information-security practices broadly.
Type I vs. Type IIType I reviews control design at a single point in time; Type II reviews whether those controls operated effectively over a period, typically 6-12 months.No Type I/II distinction; certification is a point-in-time audit with recurring annual surveillance audits.
How it's deliveredA report, typically shared with customers under NDA.A certificate, often listed or referenced publicly.
What to requestThe Type II report specifically, not just Type I.The certificate, and ideally the Statement of Applicability.

Request the SOC 2 Type II report specifically, a Type I only confirms controls were designed correctly on one day, not that they worked over time.

Neither one alone tells you everything. A vendor can hold a spotless SOC 2 Type II and still lack ISO 27001, or vice versa, ask for whichever your own compliance team requires, and don't assume one substitutes for the other.

04

How should a vendor handle and protect employee survey data?

Beyond certifications, four data-handling practices matter most for employee survey data specifically: encryption, retention and deletion, sub-processor disclosure, and a written breach-notification commitment. GDPR Article 33 requires notification within 72 hours of a breach — a standard worth holding any vendor to, regardless of jurisdiction.

01
Encryption in transit and at rest
What to ask for
Ask whether survey data is encrypted both in transit and at rest, and how.
Why it matters
In transit protects responses as they travel; at rest protects them in storage. One without the other leaves a gap.
02
Retention and deletion
What to ask for
Ask for a written retention and deletion policy, including what happens to your organization's data at contract termination.
Why it matters
You need certainty your data will not persist on a vendor's servers after you leave.
03
Sub-processor disclosure
What to ask for
Ask for a full list of sub-processors and their locations, not just a note that sub-processors exist.
Why it matters
Every sub-processor is another company touching your employees' data, and another link to vet for transfers.
04
Breach notification
What to ask for
Ask for a specific breach-notification timeframe in writing, not a vague 'prompt notification' promise.
Why it matters
Regulations like GDPR require you to notify affected employees within a specific window after a breach. A vague 'prompt notification' promise gives you nothing to hold the vendor to.
$4.99M
avg. breach cost

The global average cost of a data breach, in USD, a 12% increase over last year and a record high, driven by higher detection, escalation, and lost business costs.

Source: IBM Cost of a Data Breach Report, 2024
05

How do I control who can see employee survey results?

Least-privilege access matters more for employee survey data than for most SaaS tools, because the whole point of the data is that most people in your company should never see individual responses.

RequirementWhat to ask forWhy it matters
01SSO via SAML/IDP metadataAsk whether SSO works with your existing identity provider using SAML/IDP metadata (the technical handshake that links your existing company login system to the survey tool) — Okta, Azure AD, or another SAML-based IDP.This means the survey tool uses your company's existing login system (like Okta or Azure AD) rather than creating a separate set of usernames and passwords. Treat any claim of a native one-click connector with caution, and confirm the actual method.
02Role-based, least-privilege accessAsk whether access is role-based with least-privilege defaults.Most people in your company should never see individual responses; roles enforce that as a default setting, not something that relies on people manually remembering to restrict access.
03Page-level security and sub-admin scopingAsk whether admins can be scoped to specific teams or departments, and whether page-level security controls who sees which results.Scoping limits exposure, so a regional admin cannot read another division's raw feedback.
Beverly Wise
Chief Impact Officer, LINKBANK
Case studyLINKBANK

CultureMonkey helped us incorporate our 7 unique engagement drivers into a research-backed, customized framework. Secure Paylocity integration removed manual uploads and improved data reliability across teams. We reached a 90% company-wide participation rate and over 50 managers gained visibility into team-specific sentiment.

90%
company-wide participation rate
8+
engagement score achieved
50+
managers gained team visibility
15+
engagement drivers tracked
06

How do I find out where a vendor stores my data?

Don't assume any vendor's hosting setup, ask directly. At minimum, require a named hosting region and cloud provider, and ask whether region choice is available for your requirement.

  1. Where is our data hosted, and which cloud provider do you use?
  2. Can we choose or confirm a specific hosting region for our data?
  3. Will you sign a Data Processing Agreement covering any international data transfers?

This is deliberately the light version. For the full requirements checklist, region-by-region rules, and vendor-question list, see data residency and GDPR for employee surveys.

07

What should I ask about anonymity and AI in employee surveys?

Anonymity controls and AI transparency are two separate questions buyers often blur together. Ask about both specifically, and ask about AI twice: once about what runs by default, and once about what you can switch off.

Anonymity
Ask for configurable anonymity thresholds that suppress reporting below a minimum response count, and the ability to hide free-text comments and names below that threshold. The line between anonymous and confidential feedback matters here; see anonymous vs confidential surveys.
AI enablement: is it on by default?
AI analysis is not automatically on at every vendor, so ask first whether it runs by default. For example, CultureMonkey's AI text analysis, which powers Comment Analytics and Topic Explorer, is enabled per account rather than switched on automatically for every customer.
AI opt-out: can it be switched off?
Opt-out control often varies by individual AI feature inside the same product, so ask feature by feature rather than accepting a single yes. For example, CultureMonkey's AI-suggested actions are governed by a named account-level setting, "Hide suggested actions in reports," which hides the suggestion prompt from reports entirely, and which is switched off by default on some plans.

Ask any vendor for both answers in writing, per AI feature, not as a single yes or no about "AI."

Case studyCerence AI
86%
survey participation rate
8.0
overall engagement score
73.9%
workforce highly engaged
18%
regional engagement gap surfaced

Cerence AI drove 86% survey participation across a global, multilingual workforce of 1,200+ employees, surfacing an 18% regional engagement gap that had previously gone undetected.

08

How do I run a vendor security review without it dragging on?

A vendor security review is not a single step, it's a multi-stage process, and the biggest delays come from documentation requests that go back and forth instead of arriving all at once. Pulling these requirements into one place keeps them from resurfacing late; a survey vendor RFP template is the natural home for them.

Healthcare / BPO

HIPAA, Okta, and US residency

A healthcare and BPO buyer required HIPAA alignment, government-contract-grade security, an existing Okta integration, and US data residency before the review could even begin.

Retail

A six-month InfoSec review

A retail buyer ran a roughly six-month InfoSec review that required ISO 27001 and SOC 2 evidence at multiple stages.

Manufacturing

Banking-grade specifications

A manufacturing buyer applied banking- and government-grade security specifications to a survey purchase.

  • Request the NDA and documentation together, up front, rather than one document at a time.
  • Expect a multi-stage review and budget calendar time for it, especially in regulated industries.
  • Set up allowlisting with your IT team early, so that survey invitation emails and reminders are not blocked by your company's spam filters when the survey goes live.
Jerrell Moore
Jerrell Moore
Executive Advisor, former CHRO
Cadence Bank
S06 E09
"I've had employees say 99.9 percent of the time: just tell me the truth, even if it hurts. Do not sugarcoat it and share with me what you can in real time. Speed and trust reinforce each other when anchored in clarity."
10

How CultureMonkey meets the vendor security checklist

Every item on this checklist maps to something your InfoSec or Legal team can verify directly. Here is how CultureMonkey addresses each area: use these as starting points for your own review, not as a substitute for it. Current certifications and documentation are on the security and compliance page.

SOC 2 Type II and ISO 27001

CultureMonkey holds both certifications. Current reports and certificates are available on the trust page for your InfoSec reviewers to pull directly.

Encryption in transit and at rest

All data is encrypted in transit over TLS and at rest using AES-256. The standard and key management details are available in the security documentation.

SAML/IDP-based SSO

Single sign-on backed by your identity provider's metadata, compatible with Okta, Azure AD, and other SAML 2.0 providers. No separate credential store.

Role-based and page-level access

Scope who sees what by team, hierarchy, or attribute. Sensitive views require explicit permission: access is restricted by default, not by manual memory.

Configurable anonymity thresholds

Set the minimum group size before results appear. If a breakdown would identify a lone individual, that view stays hidden, including across attribute combinations.

AI transparency and controls

AI-generated summaries are account-level opt-in, not on by default. You can disable AI features entirely, and no employee response data is used to train external models.

11

Conclusion

An employee survey vendor security checklist means all six categories, not certifications alone: certifications and audit evidence, data handling and encryption, access control and SSO, hosting and data residency, privacy and anonymity plus AI, and incident response and support. A vendor can be strong on one and weak on another, so evaluate the whole set.

This guide gave you the copy-paste checklist to send, a plain-language SOC 2 versus ISO 27001 explainer, the data-handling practices that matter most, the access-control and residency questions to ask, how to separate anonymity from AI transparency, and how to run the review without stalling the deal.

CultureMonkey supports that review with ISO 27001 certification and a SOC 2 report, SAML/IDP-based SSO compatible with your existing identity provider, role-based and page-level access, configurable anonymity, and account-level control over its AI features. Treat these as things to verify rather than take on faith, and confirm the current details on CultureMonkey's security and compliance page.

12

Frequently asked questions

What is the difference between SOC 2 and ISO 27001?

SOC 2 is a US-originated audit report shared under NDA that examines how a vendor controls access to data. ISO 27001 is an international certification of an information security management system, issued as a public certificate. A vendor can hold one without the other, so ask for whichever your compliance team requires.

What is the difference between SOC 2 Type I and Type II?

Type I confirms controls were designed correctly at a single point in time. Type II confirms they operated effectively over a period, usually 6 to 12 months. Always request the Type II report: it proves controls worked in practice, not just that they existed on paper.

What security questions should you ask an employee survey vendor?

Cover six areas: SOC 2 and ISO 27001 evidence, encryption in transit and at rest, data retention and deletion policy, sub-processors and breach notification, SSO and role-based access, and anonymity plus AI controls. Send them as yes/no questions in an RFP and get the answers in writing.

How is anonymous survey feedback protected from re-identification?

A configurable anonymity threshold suppresses results below a minimum response count, preventing small groups from being singled out. Strong platforms also redact free-text comments below the threshold. Ask any vendor what its default threshold is and whether your team can adjust it.

Is CultureMonkey SOC 2 compliant?

Yes. CultureMonkey holds a SOC 2 report, is ISO 27001 certified, and is GDPR compliant. Request the report under NDA to confirm the current Type and scope.

Is CultureMonkey ISO 27001 certified?

Yes. CultureMonkey is ISO 27001 certified and also holds a SOC 2 report and is GDPR compliant. Ask for the certificate and the Statement of Applicability to confirm the current scope.

Does CultureMonkey support SSO with Okta or Azure AD?

Yes. CultureMonkey supports SAML-based SSO via IDP metadata, so it connects to any SAML-capable identity provider, including Okta and Azure AD. Configuration uses your IDP metadata directly.

Can we opt out of AI analysis of survey comments?

Yes, per feature. CultureMonkey's AI text analysis (Comment Analytics, Topic Explorer) is enabled per account, not on by default. AI-suggested actions can be hidden via an account-level setting. Ask your account team to confirm what is on or off for your plan.

How long does a vendor security review usually take?

Typically a few weeks to three months. Regulated industries (healthcare, finance, manufacturing) run longer. Sending a signed NDA and a complete documentation request in one go, rather than piecemeal, is the single fastest way to cut the timeline.

Reviewing survey vendors against this checklist?

See CultureMonkey's security and compliance posture (SSO, role-based and page-level access, anonymity controls, data handling) and request the documentation your InfoSec team needs.