
1. The snapshot problem
A security questionnaire describes one moment. By the time it is signed, returned, filed and read, the vendor has shipped forty deploys, rotated two thirds of their on-call rota and possibly changed sub-processors. Nothing in the document says so, and nothing in the process would notice.
That is not a failure of the questions. It is a failure of the medium: a spreadsheet cannot expire.
2. What a control actually proves
There is a difference between a vendor asserting that they encrypt data at rest and a certificate that demonstrates the control was tested by someone with their name on the line. The first is a claim. The second is evidence, and evidence carries a date.
“If your only artifact is a filled-in form, your risk register is a record of what a salesperson believed in March.”
3. Continuous beats comprehensive
Teams respond to the snapshot problem by making the questionnaire longer. Three hundred questions do not fix a stale answer — they make it slower to collect and harder to read, and they push the vendor toward copy-pasting last year’s responses.
The better trade is fewer questions and a live feed: a monitored trust portal, a certificate that re-validates, and an alert when a report lapses.
4. What to do on Monday
Take your current questionnaire and mark each question with the artifact that would answer it better. In most programmes, between a third and a half of the questions have a public, dated artifact behind them. Those are the ones to stop asking.

About Sarah Jenkins
Sarah leads compliance at Urengi. She spent eight years running third-party risk programmes inside regulated fintechs, and now writes about the gap between what a questionnaire asks and what an audit actually accepts.




