Yes, when the goal is to decide risk rather than archive paperwork. A complete questionnaire is not useful if it does not change the decision, and external evidence often closes blind spots faster than narrative answers. The priority should be timely, risk-relevant assurance for vendors that can actually affect the business.
Why evidence should outweigh questionnaire completeness
Questionnaires are useful for structuring a review, but they are only a proxy for actual control state. If the answers are complete but not verifiable, they can create false confidence and slow decision-making. Evidence is more valuable when it shows what is really deployed, who can access what, and whether the vendor’s controls are current enough to support a business decision.
That matters because third-party risk is usually about exposure, not paperwork. A polished narrative can hide stale access, weak offboarding, or undocumented integrations, while a small set of strong artefacts can quickly show whether the vendor is trustworthy enough for the relationship being proposed.
When third-party access or secrets are part of the relationship, evidence about actual tokens, credentials, and access paths is more decision-useful than broad claims of compliance. The Top 10 NHI Issues and the Ultimate Guide to NHIs, Key Challenges and Risks both reflect why hidden access sprawl and unmanaged credentials are more consequential than a fully filled-in questionnaire.
What evidence changes the decision
The evidence that matters most is the evidence that changes your risk judgement. That usually includes proof of access governance, recent rotation or revocation activity, scope of third-party connectivity, and independent validation that the vendor can actually detect and respond to misuse.
If the vendor cannot produce artefacts that show active control over privileged access, external integrations, or secret lifecycle, then a complete questionnaire should not move the decision very far. The right question is not whether the questionnaire is finished, but whether the evidence reduces uncertainty about the paths that could harm your business.
Real incidents show the value of grounding decisions in evidence rather than declarations. Salesloft OAuth token breach, BeyondTrust breach 2024, and Slack GitHub breach 2022 all show how third-party tokens or support access can become the fastest route from “trusted integration” to real compromise.
How to balance assurance with speed
Prioritisation should be risk-based, not template-based. A low-impact supplier may only need a completed questionnaire and a few supporting artefacts, while a vendor with production access, customer data reach, or privileged connectivity should be expected to provide stronger evidence before approval.
Use a tiered review model: start with the controls that affect blast radius, then ask for evidence that those controls are operating now. That usually means access logs, recent offboarding or rotation proof, architecture or data-flow diagrams, and independent assurance where the relationship is large enough to justify it.
The best external evidence is often specific enough to confirm the control is operating, but not so broad that it becomes another narrative response. The EU Digital Operational Resilience Act (DORA) and the SOC 2 Trust Services Criteria (AICPA) are useful examples of why third-party assurance should be tied to operational resilience and control evidence, not treated as a checkbox exercise.
Risk and Threat Considerations
Questionnaire completeness can hide the exact failure mode third-party risk teams are trying to avoid, namely unverified trust. Attackers and careless vendors alike exploit the gap between what a supplier says it does and what it can actually prove under pressure.
Failure mechanism: Organisations overweight self-reported answers, underweight artefacts, and miss exposed tokens, stale access, weak offboarding, or unscoped integrations that create a direct path into sensitive systems.
Impact: The result is approval of a supplier that appears well controlled on paper but still has enough real access to enable data theft, persistence, or downstream compromise.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022, DORA and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| CIS Controls v8 | CIS-15 — Service Provider Management | Govern third-party relationships and require risk-based assurance for suppliers. |
| Recommendation — Assess suppliers on verified control evidence before granting or retaining access. | ||
| NIST SP 800-53 Rev 5 | SA-9 — External System Services | Covers security requirements and evidence for services provided by external parties. |
| Recommendation — Define required evidence and security obligations for external services before integration. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Requires supplier relationships to be managed with appropriate security requirements and assurance. |
| Recommendation — Set supplier security expectations and verify supporting evidence before approval. | ||
| DORA | ICT Third-Party Risk Management — ICT Third-Party Risk Management | Directly addresses third-party assurance and resilience for critical vendors. |
| Recommendation — Use risk-based evidence to assess critical ICT suppliers and their resilience. | ||
| SOC 2 (AICPA) | CC2.1 — Communication and Information | SOC 2 evidence often informs third-party assurance decisions about control operation. |
| Recommendation — Request current SOC 2 evidence where vendor assurance materially affects trust decisions. | ||
Practitioner Guidance
What to prioritise: For vendors that can affect production, customer data, or privileged access, prioritise evidence that proves current control operation over narrative completeness. A partially answered questionnaire with strong artefacts is usually more decision-useful than a perfect form with no validation.
Decision rule: If the vendor’s evidence does not change the risk decision, treat it as incomplete regardless of questionnaire score. If the evidence shows active access, token, or offboarding weakness, escalate before requesting more prose.
What to verify: Verify that the artefacts cover the exact relationship in scope, not a different environment, product, or subsidiary. The common mistake is accepting generic compliance proof when the real question is whether this supplier can still reach your systems today.
Practitioner takeaway: Complete questionnaires are useful for intake, but defensible third-party decisions come from evidence that narrows actual exposure, not from paperwork that merely looks finished.
Related resources from NHI Mgmt Group
- When should organisations prioritise continuous monitoring over relying on questionnaire responses alone for third-party risk decisions?
- When should organisations prioritise third-party risk management over more advanced security initiatives?
- When should organisations prioritise technology and automation over manual third-party risk tracking?
- When should organisations prioritise a third-party secrets manager over storing credentials in the access platform?