The main mistake is treating due diligence as a static snapshot instead of an ongoing control. Questionnaires can miss changes in posture, new exposures, or deteriorating compliance after onboarding. Strong programmes combine initial review with continuous monitoring, because a vendor that looked acceptable last quarter can become a material risk as its environment, access, or controls change.
Why one-and-done vendor questionnaires create blind spots
A questionnaire is only a point-in-time signal. It tells you what a vendor could evidence on the day it answered, not whether its controls, exposures, or dependencies stayed stable after onboarding. The mistake is assuming the procurement milestone equals risk closure, when the real control problem is whether the vendor remains within tolerance over time.
That gap matters because vendor risk is dynamic. Security posture can change after a major release, a cloud migration, a subcontractor change, a policy exception, or a control failure elsewhere in the vendor’s environment. If the review process stops at intake, the buyer loses visibility into those changes until something breaks or the vendor discloses them.
What a questionnaire can tell you, and what it cannot
Questionnaires are useful for standardising baseline disclosures, forcing ownership questions, and documenting minimum assurance. They are not sufficient on their own because they mostly capture declared intent and current self-attestation, not real-time evidence of drift, concentration risk, or emerging exposure. A strong answer on paper can coexist with weak change control, expired assurances, or new third-party dependencies.
The practical failure is over-trusting static artefacts. Organisations often treat a completed form as proof of continuing control, when it is really just input to a broader assurance process. If the vendor has ongoing access to data, systems, or business processes, the buyer needs a way to notice when that access context or control environment changes.
Continuous assurance does not mean monitoring everything equally. It means deciding which vendor changes are material enough to revisit, such as scope expansion, new privileged access, control regressions, incident disclosures, or material changes in financial or operational stability. That is the difference between periodic paperwork and actual third-party risk management.
How mature programmes move from intake review to continuous assurance
Mature vendor programmes separate onboarding due diligence from lifecycle oversight. The initial assessment establishes a baseline, but then the organisation tracks the vendor’s risk over time through renewal reviews, control attestations, incident notifications, security ratings where appropriate, contractual reporting obligations, and internal ownership of the vendor relationship. The control objective is not constant surveillance, it is timely detection of material change.
That lifecycle view also changes internal accountability. Procurement may collect the questionnaire, but business owners, security, privacy, legal, and risk functions should know who acts when the vendor’s posture changes. Without named owners and review triggers, the programme becomes a filing exercise rather than a control system.
Organisations should also make the review cadence proportional to exposure. Vendors with limited access and low sensitivity may justify lighter review, while vendors handling sensitive data, critical workloads, or privileged integrations need stronger evidence and faster revalidation. SOC 2 Trust Services Criteria (AICPA) is often used as one way to structure that ongoing assurance, but the key point is the discipline of reassessment, not the formality of the questionnaire itself.
Risk and Threat Considerations
The main risk is stale assurance: a vendor that was acceptable at onboarding can later become a material exposure because its environment, subcontractors, access, or controls changed. That creates blind spots in confidentiality, availability, and compliance, especially where the vendor has access to production systems or regulated data.
Failure mechanism: Static questionnaires do not detect post-onboarding drift, so control failures, incidents, or new third-party dependencies can persist unnoticed until they affect your environment or data.
Impact: Organisations may continue granting access, renew contracts, or accept residual risk on the basis of outdated evidence, which can enlarge breach impact, operational disruption, and regulatory exposure.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 sets the technical controls, while SOC 2 (AICPA) and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| SOC 2 (AICPA) | CC3.1 — Risk Assessment | Vendor due diligence needs ongoing reassessment of changing third-party risk. |
| CC9.2 — Risk Mitigation | Ongoing vendor oversight is a risk response, not a one-time procurement step. | |
| Recommendation — Reassess vendor risk when scope, controls, or dependencies materially change. Maintain periodic third-party monitoring and escalation for material deviations. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier relationships require continuing security oversight across the vendor lifecycle. |
| A.5.22 — Monitoring, review and change management of supplier services | This directly addresses post-onboarding changes in supplier service risk. | |
| Recommendation — Define and operate supplier security reviews throughout the relationship. Monitor supplier changes and review security impact whenever service conditions shift. | ||
| NIST CSF 2.0 | GV.SC-01 — Supply Chain Risk Management Strategy | Vendor due diligence is part of an ongoing supply chain risk strategy. |
| GV.RM-07 — Supplier Risk Management | The question is fundamentally about managing changing third-party risk. | |
| Recommendation — Set a lifecycle strategy for supplier assurance, escalation, and review. Track supplier risk continuously and update treatment when conditions change. | ||
Practitioner Guidance
What to prioritise: Treat every high-impact vendor as a living control relationship, not a procurement checkbox. The first question should be whether the vendor’s access, data handling, or service criticality makes periodic revalidation mandatory.
What to verify: Look for change triggers, not just annual attestations, and require evidence that somebody reviews incidents, scope changes, subcontractors, and control exceptions between formal reviews. If the vendor cannot show a current review trail, assume the assurance picture is stale.
Decision rule: If a vendor can affect production, sensitive data, or regulated processes, do not rely on a single questionnaire as the control. Use it as baseline evidence, then pair it with renewal checks, event-driven reassessment, and contractual notification duties.
Practitioner takeaway: The question is not whether the vendor answered honestly last quarter, it is whether your programme is designed to notice when that answer is no longer true.
Related resources from NHI Mgmt Group
- What do organisations get wrong when they treat AI red teaming as a one-time assessment?
- What do organisations get wrong when they treat KYC as a one-time onboarding step?
- What do organisations get wrong when they treat access requests as a one-time approval instead of an ongoing control?
- What do organisations get wrong when they treat certification as a one-time achievement?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 25, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org