SA-9 External Service Providers: Same Vendor List, Different Audit Trail

Two agencies. Same checklist answer: external service providers with CJI access are managed under SA-9. Both had Security Addendums executed with their primary vendors. Both rated themselves compliant.

The auditor asked for the triennial audit records for each provider.

Agency A produced the Security Addendums. All current, all signed. The auditor asked about the triennial audits. Agency A explained that the vendors were certified and compliant — some held SOC 2 reports, one was FedRAMP authorized. The auditor noted that SA-9 requires the agency to conduct its own audits of external service providers, not to rely on the provider's own certifications.

Agency B produced the Security Addendums and a provider audit log: four vendors, each with a triennial audit record showing what was reviewed, who conducted the review, when it occurred, and what findings resulted. One provider had a finding that was closed six months later with documented evidence.

The auditor noted Agency A's finding: SA-9 requires the agency to monitor, review, and audit CJI-related service providers on at least a triennial basis. A vendor's own certification is not an agency audit. A SOC 2 report is not an SA-9 audit.

What the control actually requires

SA-9 requires the organization to require external service providers that access, process, store, or transmit CJI to comply with the CJIS Security Policy and applicable state policies. It requires the execution of a Security Addendum. And it requires the agency to audit its service providers at minimum triennially.

The auditing obligation belongs to the agency. The provider's certifications, SOC 2 reports, and attestations are evidence of the provider's own assessment of its controls. They are not evidence that the agency has independently reviewed the provider's posture against the CJIS requirements that apply to the relationship.

What the auditor is looking for

A current inventory of all external service providers with CJI access. Executed Security Addendums for each. Triennial audit records for each provider: what was reviewed, who conducted the review, findings, and disposition. Evidence that the audit cycle is tracked and providers are not past due.

A vendor's compliance certificate is their document. The SA-9 audit record is yours.

The common failure mode

Security Addendums were obtained when vendors were onboarded. Nobody scheduled the triennial audit as a recurring calendar event with a named owner. Years pass. Vendors renew contracts. New vendors are added. The SA-9 audit obligation accumulates and is never fulfilled because nobody is tracking it and nothing in the vendor management process prompts it.

A fifteen-officer department with three cloud vendors, a CAD/RMS provider, and a radio maintenance contractor may have more SA-9 audit obligations outstanding than it realizes.

Read next
What a CJIS CSA Audit Actually Asks For
The shift from having a policy on file to demonstrating a control operates. Concrete contrasts, cited to CJIS Security Policy v6.1.

Written by Dr. Alexis W. Perdereaux-Weekes

DBA · CISA · CISM · CRISC · CDPSE

Founder, CJIS360 LLC


Sources: CJIS Security Policy v6.1, 06/25/2026 — SA-9 External Information System Services; Appendix D CJIS Security Addendum; §1.4 Terminology Used in This Document.

Questions about how this applies to your agency: agency@cjis360.com

Back to the Knowledge Center