Join our Newsletter — 33% off our NHI Course
Home› FAQ› Governance, Ownership & Risk› Should organisations prioritise third-party risk evidence over questionnaire…
Governance, Ownership & Risk

Should organisations prioritise third-party risk evidence over questionnaire completeness?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Governance, Ownership & Risk

Yes, when the goal is to decide risk rather than archive paperwork. A complete questionnaire is not useful if it does not change the decision, and external evidence often closes blind spots faster than narrative answers. The priority should be timely, risk-relevant assurance for vendors that can actually affect the business.

Why evidence should outweigh questionnaire completeness

Questionnaires are useful for structuring a review, but they are only a proxy for actual control state. If the answers are complete but not verifiable, they can create false confidence and slow decision-making. Evidence is more valuable when it shows what is really deployed, who can access what, and whether the vendor’s controls are current enough to support a business decision.

That matters because third-party risk is usually about exposure, not paperwork. A polished narrative can hide stale access, weak offboarding, or undocumented integrations, while a small set of strong artefacts can quickly show whether the vendor is trustworthy enough for the relationship being proposed.

When third-party access or secrets are part of the relationship, evidence about actual tokens, credentials, and access paths is more decision-useful than broad claims of compliance. The Top 10 NHI Issues and the Ultimate Guide to NHIs, Key Challenges and Risks both reflect why hidden access sprawl and unmanaged credentials are more consequential than a fully filled-in questionnaire.

What evidence changes the decision

The evidence that matters most is the evidence that changes your risk judgement. That usually includes proof of access governance, recent rotation or revocation activity, scope of third-party connectivity, and independent validation that the vendor can actually detect and respond to misuse.

If the vendor cannot produce artefacts that show active control over privileged access, external integrations, or secret lifecycle, then a complete questionnaire should not move the decision very far. The right question is not whether the questionnaire is finished, but whether the evidence reduces uncertainty about the paths that could harm your business.

Real incidents show the value of grounding decisions in evidence rather than declarations. Salesloft OAuth token breach, BeyondTrust breach 2024, and Slack GitHub breach 2022 all show how third-party tokens or support access can become the fastest route from “trusted integration” to real compromise.

How to balance assurance with speed

Prioritisation should be risk-based, not template-based. A low-impact supplier may only need a completed questionnaire and a few supporting artefacts, while a vendor with production access, customer data reach, or privileged connectivity should be expected to provide stronger evidence before approval.

Use a tiered review model: start with the controls that affect blast radius, then ask for evidence that those controls are operating now. That usually means access logs, recent offboarding or rotation proof, architecture or data-flow diagrams, and independent assurance where the relationship is large enough to justify it.

The best external evidence is often specific enough to confirm the control is operating, but not so broad that it becomes another narrative response. The EU Digital Operational Resilience Act (DORA) and the SOC 2 Trust Services Criteria (AICPA) are useful examples of why third-party assurance should be tied to operational resilience and control evidence, not treated as a checkbox exercise.

Risk and Threat Considerations

Questionnaire completeness can hide the exact failure mode third-party risk teams are trying to avoid, namely unverified trust. Attackers and careless vendors alike exploit the gap between what a supplier says it does and what it can actually prove under pressure.

Failure mechanism: Organisations overweight self-reported answers, underweight artefacts, and miss exposed tokens, stale access, weak offboarding, or unscoped integrations that create a direct path into sensitive systems.

Impact: The result is approval of a supplier that appears well controlled on paper but still has enough real access to enable data theft, persistence, or downstream compromise.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

CIS Controls v8 and NIST SP 800-53 Rev 5 set the technical controls, while ISO/IEC 27001:2022, DORA and SOC 2 (AICPA) define the regulatory obligations.

FrameworkControl / ReferenceRelevance
CIS Controls v8CIS-15 — Service Provider ManagementGovern third-party relationships and require risk-based assurance for suppliers.
Recommendation — Assess suppliers on verified control evidence before granting or retaining access.
NIST SP 800-53 Rev 5SA-9 — External System ServicesCovers security requirements and evidence for services provided by external parties.
Recommendation — Define required evidence and security obligations for external services before integration.
ISO/IEC 27001:2022A.5.19 — Information security in supplier relationshipsRequires supplier relationships to be managed with appropriate security requirements and assurance.
Recommendation — Set supplier security expectations and verify supporting evidence before approval.
DORAICT Third-Party Risk Management — ICT Third-Party Risk ManagementDirectly addresses third-party assurance and resilience for critical vendors.
Recommendation — Use risk-based evidence to assess critical ICT suppliers and their resilience.
SOC 2 (AICPA)CC2.1 — Communication and InformationSOC 2 evidence often informs third-party assurance decisions about control operation.
Recommendation — Request current SOC 2 evidence where vendor assurance materially affects trust decisions.

Practitioner Guidance

What to prioritise: For vendors that can affect production, customer data, or privileged access, prioritise evidence that proves current control operation over narrative completeness. A partially answered questionnaire with strong artefacts is usually more decision-useful than a perfect form with no validation.

Decision rule: If the vendor’s evidence does not change the risk decision, treat it as incomplete regardless of questionnaire score. If the evidence shows active access, token, or offboarding weakness, escalate before requesting more prose.

What to verify: Verify that the artefacts cover the exact relationship in scope, not a different environment, product, or subsidiary. The common mistake is accepting generic compliance proof when the real question is whether this supplier can still reach your systems today.

Practitioner takeaway: Complete questionnaires are useful for intake, but defensible third-party decisions come from evidence that narrows actual exposure, not from paperwork that merely looks finished.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org