Start free trial
Industry Insights

Why traditional questionnaires fail to capture real vendor risk

Traditional point-in-time spreadsheets are outdated the minute they are sent. Discover how real-time evidence vault monitoring captures actual security posture.


Sarah Jenkins

Head of Compliance, Urengi

Published

2 min read

A glowing padlock inside a shield, rendered over a dark server corridor

1. The snapshot problem

A security questionnaire describes one moment. By the time it is signed, returned, filed and read, the vendor has shipped forty deploys, rotated two thirds of their on-call rota and possibly changed sub-processors. Nothing in the document says so, and nothing in the process would notice.

That is not a failure of the questions. It is a failure of the medium: a spreadsheet cannot expire.

2. What a control actually proves

There is a difference between a vendor asserting that they encrypt data at rest and a certificate that demonstrates the control was tested by someone with their name on the line. The first is a claim. The second is evidence, and evidence carries a date.

“If your only artifact is a filled-in form, your risk register is a record of what a salesperson believed in March.”

3. Continuous beats comprehensive

Teams respond to the snapshot problem by making the questionnaire longer. Three hundred questions do not fix a stale answer — they make it slower to collect and harder to read, and they push the vendor toward copy-pasting last year’s responses.

The better trade is fewer questions and a live feed: a monitored trust portal, a certificate that re-validates, and an alert when a report lapses.

4. What to do on Monday

Take your current questionnaire and mark each question with the artifact that would answer it better. In most programmes, between a third and a half of the questions have a public, dated artifact behind them. Those are the ones to stop asking.


About Sarah Jenkins

Sarah leads compliance at Urengi. She spent eight years running third-party risk programmes inside regulated fintechs, and now writes about the gap between what a questionnaire asks and what an audit actually accepts.

Related perspective pieces

A corner meeting room at dusk with floor-to-ceiling windows over a city skyline

How to build a vendor security program that survives real audits

The ultimate guide for newly appointed CISOs. Step-by-step setup to bridge compliance departments with operational engineering teams.


Sarah Jenkins

The exposed movement of a mechanical pocket watch, gears and springs in close focus

Six weeks of email, or two days: the administrative cost of manual vendor chasing

When we audited vendor security lifecycles across 380 fast-growing organizations, the bottleneck wasn't risk calculation—it was the administrative cost of human follow-up. This study unpacks the exact operational timelines.


Zoe Harrington

A dark monitor in a dim office showing a compliance dashboard
Product Updates

1 min read

Introducing the Urengi continuous compliance engine for NIST and ISO

Instantly map evidence artifacts to major global standards. Create audit-ready workspaces dynamically without replicating review actions.


Marcus Vance