Questionnaire gap analysis is the process of reviewing vendor responses to find missing, incomplete, or inconsistent security information. It helps teams identify where follow-up is needed and where answers do not support the stated risk posture. In practice, it improves consistency, accelerates review, and sharpens remediation planning.
Expanded Definition
Questionnaire gap analysis is a structured review of security questionnaires, due diligence forms, and vendor assessments to find omissions, contradictions, vague claims, or answers that cannot be verified. In NHI and IAM programs, it is especially important when a questionnaire is used to evaluate service accounts, agent access, secrets handling, federation, or privileged workflows rather than only human identities.
The term is sometimes treated as a simple completeness check, but that is too narrow. A true gap analysis compares the response against the security outcome the question is meant to prove, then identifies where the answer is unsupported, outdated, or internally inconsistent. That matters because questionnaires often summarize controls that are actually enforced elsewhere, such as key rotation, token lifecycle management, or approval workflows. Standards such as NIST SP 800-53 Rev 5 Security and Privacy Controls provide a useful control-oriented reference point, but no single standard governs questionnaire gap analysis itself yet.
At NHIMG, this is treated as an assurance discipline, not a paperwork task. The most common misapplication is marking a questionnaire “complete” when responses are present but do not actually substantiate the claimed control condition, which occurs when reviewers accept narrative answers without evidence.
Examples and Use Cases
Implementing questionnaire gap analysis rigorously often introduces review overhead, requiring organisations to weigh faster procurement decisions against stronger assurance and follow-up depth.
- A vendor states that all secrets are centrally managed, but gives no detail on rotation frequency, break-glass access, or whether service accounts are excluded from the process.
- An AI platform questionnaire says agents use least privilege, yet the response does not explain how tool permissions are scoped, approved, or revoked across environments.
- A partner security review claims encryption in transit, but omits how API keys, tokens, and certificates are inventoried, which makes the answer incomplete for NHI risk review.
- An assessors’ follow-up finds that a control attestation is copied from a prior year and no longer matches current architecture, requiring a new evidence request and risk re-rating.
- In a high-risk onboarding flow, teams use a gap matrix to map each unanswered item to remediation, escalation, or compensating control before integration proceeds.
For deeper context on credential abuse and exposure patterns, see DeepSeek breach and the NIST control baseline in NIST SP 800-53 Rev 5 Security and Privacy Controls.
Why It Matters in NHI Security
Questionnaire gap analysis matters because NHI risk is often hidden behind confident language. A vendor may describe strong governance while leaving unanswered questions about token custody, agent permissions, secret rotation, or delegated access. Those omissions create false assurance, especially when procurement teams treat the questionnaire as a final control rather than a starting point for validation.
This becomes more urgent when research shows how quickly exposed credentials are exploited. NHIMG reports that when AWS credentials are exposed publicly, attackers attempt access within an average of 17 minutes, and as quickly as 9 minutes in some cases, in LLMjacking: How Attackers Hijack AI Using Compromised NHIs. That speed means questionnaire gaps are not administrative noise; they can conceal active exposure windows. The same review discipline also helps teams interpret evidence against a control baseline such as NIST SP 800-53 Rev 5 Security and Privacy Controls, rather than relying on self-attestation alone.
Organisations typically encounter the operational cost of questionnaire gaps only after a breach, failed audit, or blocked integration, at which point gap analysis becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63 and NIST Zero Trust (SP 800-207) set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Questionnaire gaps often hide weak NHI inventory and ownership details. |
| NIST CSF 2.0 | GV.RM-04 | Risk management depends on identifying unanswered or unsupported vendor claims. |
| NIST SP 800-63 | IAL2 | Identity assurance questions often need stronger evidence than narrative answers provide. |
| NIST Zero Trust (SP 800-207) | Zero trust reviews depend on validating access claims, not accepting them at face value. |
Require evidence for NHI inventory, owners, and lifecycle assertions before accepting vendor responses.
Related resources from NHI Mgmt Group
- How should organisations use a Zero Trust gap analysis in practice?
- What breaks when a CMMC gap analysis is treated like paperwork instead of validation?
- How do security teams know whether a CMMC gap analysis is producing usable results?
- What is the difference between a data map and a gap analysis for CCPA compliance?