They create a snapshot of declared controls, but they do not verify enforcement, evidence freshness, or whether access was removed when the vendor relationship changed. That leaves organisations with documented trust instead of controlled trust, which is especially risky when vendors hold privileged or non-human access to sensitive systems.
Why questionnaires only measure declared control posture
Third-party questionnaires are useful as a first-pass intake control, but they mainly record what a vendor says about policy, process, and ownership. They do not prove that controls are operating, that exceptions are contained, or that the control set still matches the current integration. In practice, they are a governance artifact, not an assurance mechanism.
The gap matters because vendor risk is rarely static. Access paths, hosted tools, support arrangements, and subcontractors can change after the questionnaire is completed, while the paper trail stays unchanged. That is why a questionnaire can look complete even when the real exposure has already moved.
Questionnaires also tend to overstate uniformity. A vendor may have one good answer for one business unit and a weaker reality in another, or may describe a control that exists only for certain systems. When the check stops at self-attestation, the buyer misses scope boundaries, compensating controls, and whether the declared practice is actually enforced.
Where the trust model breaks down in vendor relationships
The real failure is not simply “bad questionnaires”, it is relying on documented trust after the relationship has changed. A vendor can become a higher-risk dependency once it gains privileged, API, or support access, and that access can persist long after the original business case has ended. The answer on the page already captures the core issue: the control is not whether access was claimed, but whether it was removed, rotated, or constrained when the relationship changed.
This is where vendor management and access governance meet. If the third party holds credentials, tokens, certificates, or administrative pathways, then the relevant question is whether those credentials are still active, whether they are scoped narrowly, and whether offboarding actually happened. Without that proof, the organisation is trusting a declaration instead of a revocable access state.
For that reason, the strongest practical checks are evidence of enforcement and lifecycle change, not just a filled-in questionnaire. A vendor can answer “yes” to least privilege, logging, or rotation while still retaining stale entitlements or unattended secrets in real environments. The control failure is hidden because the questionnaire does not naturally surface drift.
What effective third-party control evidence should show
A useful vendor control review should connect the questionnaire to evidence that can be tested. That means asking for artefacts that demonstrate access review, credential rotation, offboarding, logging, and exception handling rather than only control descriptions. It also means verifying that the evidence is recent enough to reflect the current integration, not a prior audit cycle.
For access-heavy vendors, the most important evidence is usually operational: current entitlement lists, recent revocation records, token or key rotation history, and proof that unused accounts were removed. If a vendor touches sensitive systems, a contractual statement is not enough unless it is backed by observable enforcement.
This is especially important where the vendor is part of a broader software or SaaS chain. A questionnaire may say the provider uses secure processes, but the buyer still needs confidence that inherited access, delegated support, and downstream integrations are being actively governed. Slack GitHub breach 2022 is a good reminder that third-party token exposure can turn an ordinary vendor relationship into direct repository access.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5, CSA Cloud Controls Matrix and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Vendor access must be provisioned, reviewed, and removed when relationships change. |
| IA-5 — Authenticator Management | Questionnaires cannot prove the lifecycle of vendor tokens, keys, or secrets. | |
| Recommendation — Require current account inventories and revoke vendor access when it is no longer needed. Verify rotation, revocation, and storage practices for vendor authenticators. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Third-party questionnaires are part of supplier governance and ongoing assurance. |
| Recommendation — Review supplier security obligations and maintain evidence-based assurance over vendors. | ||
| CSA Cloud Controls Matrix | IAM — Identity & Access Management | Vendor questionnaires fail when access governance is not backed by enforcement evidence. |
| Recommendation — Validate that third-party access is least-privileged, monitored, and removed on offboarding. | ||
| CIS Controls v8 | CIS-5 — Account Management | The question concerns whether vendor accounts and access are actually removed or constrained. |
| Recommendation — Inventory third-party accounts and disable stale access paths promptly. | ||
Practitioner Guidance
What to verify: Treat the questionnaire as a screening tool and verify the controls that actually change blast radius: live access, credential age, revocation records, and whether the vendor still has the same integration scope. If the vendor can authenticate to production, the review should require evidence that access is constrained and removable, not merely described.
Decision rule: If the vendor holds privileged or non-human access, move beyond questionnaire review and require evidence of enforcement before renewal or expansion. If the vendor only handles low-risk, non-sensitive services, the questionnaire may be acceptable as part of a lighter-touch review, but it should still be paired with periodic revalidation.
Common mistake: Teams often treat a completed questionnaire as proof that offboarding happened. That is the wrong inference, because the document may be current while the access state is not.
Practitioner takeaway: A third-party questionnaire should confirm that controls exist, but only evidence confirms that the controls still govern the vendor’s real access.
Related resources from NHI Mgmt Group
- How should security teams use third-party risk questionnaires in vendor onboarding?
- Why do traditional vendor questionnaires fall short for modern third-party risk management?
- What breaks when organisations rely on vendor questionnaires instead of continuous third-party identity monitoring?
- What breaks when organisations rely on static questionnaires to assess third-party script and AI risk?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org