> For the complete documentation index, see [llms.txt](https://wiki.songer.pro/governance-compliance-risk/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://wiki.songer.pro/governance-compliance-risk/customer-security/security-questionnaires-questions/security-governance/does-your-organization-conduct-an-annual-independent-information-security-review-and-act-upon-the-fi.md).

# Does your organization conduct an annual independent information security review and act upon the fi

## What

An annual security review conducted by an external and independent third party helps to ensure that your implemented security controls are effective in mitigating you company’s security risks.

The length and depth of a security review will typically be scoped out by the independent third party and will help you to understand any gaps in your security and risk management controls.

## Why
