I was reviewing a third party that had been acquired by another company.

The parent organization had already gone through a recent assessment, so the obvious question was whether I actually needed to assess the acquired service separately.

On the surface, it would have been easy to say no.

They were now part of the same company. There was already an assessment on record. Reusing it would avoid putting another vendor through work that might already have been done.

But I didn’t know whether that assessment had actually covered the acquired service.

So I went back to the person who had completed the parent company’s assessment and asked a very specific question: did the acquired company or service appear anywhere in the evidence you reviewed?

The answer was no.

That settled it for me.

The organizations may now have been under the same ownership, but the previous assessment hadn’t established anything about this particular service.

We still needed to assess it.

What interested me was how easy it would have been to let the acquisition answer more than it actually did.

An acquisition tells me who owns the company.

It doesn’t automatically tell me that the acquired service has moved onto the parent company’s systems, adopted the same policies, joined the same control environment, or is covered by the same evidence.

Some of those things may happen quickly. Others may take years. Some may never happen at all.

And an assessment of the parent company can be completely valid without covering everything the company acquires later.

That was important here.

The previous assessment wasn’t wrong or incomplete because the acquired service wasn’t in it. It simply had a scope, and this service wasn’t part of it.

That can become harder to see once company records start getting consolidated.

The vendor record may show the parent company. Contracts or tax information may change. Contacts may start using the parent company’s email domain. Internally, everyone may already talk about the two organizations as one company.

None of that tells me what was actually validated in the previous assessment.

For that, I have to go back to the assessment itself.

What service was in scope? Which systems and environments did the evidence cover? Which organization did the documentation apply to? Was the acquired service actually represented anywhere?

If the answers show that the previous assessment really did cover the acquired service, then reusing some of that work may make sense.

In this case, they didn’t.

The acquired service wasn’t represented in the evidence used for the previous assessment, so I couldn’t treat the parent company’s assessment as coverage for it.

The case also made me think about what should happen in the system when an acquisition is recorded.

Changing the company name or ownership field isn’t enough.

That change should make the existing assessment history visible and show which services were actually covered. If the acquired service isn’t tied to any previous assessment, that should be easy to see.

The system doesn’t have to decide whether a new assessment is needed.

But it can make sure someone doesn’t accidentally treat “same owner” as “already assessed.”

When a vendor is acquired, what evidence tells you the previous assessment actually carries forward to the service you’re relying on now?

Reply

Avatar

or to participate