Join our Newsletter — 33% off our NHI Course
Home FAQ Governance, Ownership & Risk What breaks when vendor assessments rely on questionnaires…
Governance, Ownership & Risk

What breaks when vendor assessments rely on questionnaires instead of access evidence?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated September 16, 2026 Domain: Governance, Ownership & Risk

They break at the point where paper controls diverge from actual exposure. A vendor can describe strong policies and still hold excessive, standing, or unmonitored access. Security teams should treat access scope, session logs, and revocation state as the real assessment evidence, because those are the controls that determine damage if the vendor is compromised.

Why This Matters for Security Teams

Questionnaires are good at collecting claims, but weak at proving enforcement. When a vendor says it has least privilege, rotation, or offboarding in place, that statement does not show whether access is actually scoped, monitored, or revoked in time. The assessment therefore risks approving a relationship based on policy language while the real blast radius remains unchanged. That gap matters most when the vendor can touch production systems, customer data, or administrative consoles. Access evidence turns the review from a promises exercise into a control test. Session logs, entitlement exports, approval trails, and revocation records show whether access is standing, shared, overbroad, or stale. They also reveal whether the vendor can be constrained quickly after an incident. This is the same reason security teams treat configuration evidence as stronger than policy statements in other parts of the stack: the control is only real if it is observable. A questionnaire can still be useful as a scoping tool, but it should not be the final proof. In practice, many third-party reviews only uncover excessive access after an incident, because the original assessment stopped at attestation instead of asking for evidence.

How It Works in Practice

A strong vendor assessment starts with the access paths that matter, not with the wording of the questionnaire. The reviewer should ask for evidence that shows what the vendor can actually do, when that access was granted, and how it is removed. That usually means reviewing live or recent exports rather than relying on a static control narrative. The most useful evidence categories are:
  • Current entitlements, including roles, groups, API scopes, and system accounts.
  • Session or audit logs that show how access is used and whether it is monitored.
  • Approval and exception records that explain why elevated access exists.
  • Revocation or offboarding evidence that shows access can be removed promptly.
  • Rotation or expiry evidence for any credentials that remain in use.
For higher-risk vendors, the assessor should compare declared access against actual access. A vendor may answer “yes” to a questionnaire item about least privilege while still holding standing access across multiple environments, or while retaining credentials after the engagement has ended. If the evidence set cannot show scope, recency, and removal, the assessment is incomplete even if the questionnaire is fully filled out. The most useful comparison is between the vendor’s described process and the real administrative state in the target system. The NHI and Secrets Risk Report is a useful reference point for why declared controls often diverge from operational reality when credentials and access paths are not continuously governed. These controls tend to break down when access is brokered through shared admin accounts or long-lived credentials because the questionnaire can describe governance, but it cannot prove who still has effective access.

Common Variations and Edge Cases

Tighter evidence requirements often increase assessment effort, so organisations need to balance review depth against vendor criticality. A low-risk supplier may justify a lighter evidence set, but once a vendor can reach sensitive data, production systems, or administrative functions, the bar should move from attestation to verification. Some vendors will resist sharing raw access evidence. In those cases, a secure read-only export, screenshot, or sampled report can be acceptable if it is current enough to show effective access and revocation state. Best practice is evolving around how much evidence should be requested from smaller vendors, but there is no universal standard that makes a questionnaire alone sufficient for high-impact access. Edge cases usually involve indirect access paths. A vendor may not have direct login access, yet still reach systems through integrations, API keys, delegated admin tools, or support channels. That changes the assessment because the reviewer must inspect the actual control surface, not just named user accounts. It also matters when access is intermittent: temporary access is safer only if it is genuinely time-bounded and can be evidenced as such. A useful rule is to treat any vendor with production reach as a control owner, not just a questionnaire respondent. OWASP Non-Human Identity Top 10 provides a relevant control lens for standing access, overprivilege, and credential governance where the access path is not purely human. The assessment usually fails when organisations accept “we have controls” as evidence, instead of checking whether the access can be demonstrated, bounded, and revoked in the systems that actually matter.

Risk and Threat Considerations

The material risk is false confidence: a questionnaire can make a vendor look controlled while leaving the real access path intact. That creates exposure to overprivilege, stale access, untracked session use, and delayed revocation, all of which widen the damage potential if the vendor is compromised or acts improperly. Failure mechanism: The weakness appears when policy and technical state are disconnected. An attacker who compromises the vendor, or a bad actor inside the vendor, benefits from standing access, reusable credentials, and insufficient monitoring because the assessment never validated whether those controls were truly enforced. Impact: The result is broader blast radius, slower containment, and weaker accountability. Sensitive systems may remain reachable after the relationship should have been narrowed or terminated, and the organisation may not discover the exposure until after data access or administrative misuse has already occurred.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 address the attack and risk surface, while CIS Controls v8 and NIST CSF 2.0 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP Non-Human Identity Top 10NHI-01 — Standing Access and OverprivilegeVendor access evidence must prove current privilege scope, not just policy claims.
NHI-02 — Credential and Secret RotationQuestionnaires do not prove that vendor credentials are rotated or expired on time.
Recommendation — Review live entitlements and remove any standing access that exceeds business need. Require evidence of rotation, expiry, and offboarding for every vendor credential.
CIS Controls v8CIS-6 — Access Control ManagementThird-party assessments hinge on verifying and revoking vendor access in practice.
Recommendation — Enforce least privilege and verify that vendor access is approved, scoped, and revoked.
NIST CSF 2.0PR.AC — Access ControlThe question centers on whether access control is actually enforced, not merely documented.
Recommendation — Validate access control implementation with entitlements, logs, and revocation evidence.

Practitioner Guidance

What to prioritise: Prioritise evidence for vendors that can touch production, sensitive data, or privileged workflows. A filled questionnaire is lower value than a current entitlement export or revocation record when the vendor has real reach.

Decision rule: If the vendor can affect confidentiality, integrity, or availability, require proof of actual access scope before approval. If the evidence is missing or stale, treat the assessment as incomplete rather than compensating with more questionnaire detail.

What to verify: Verify three states specifically: what access exists now, whether it is monitored, and how quickly it can be removed. Those three checks tell you far more about exposure than a policy attestation ever will.

Practitioner takeaway: The strongest vendor assessment asks, “show me the access,” not “tell me the process,” because only enforced access controls determine the real blast radius.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 16, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org