Because access changes faster than most assessment cycles. A questionnaire can remain current on paper while the vendor’s integrations, privileges, or data reach have already expanded. The result is a stale classification that lags the actual exposure created by the relationship.
Why periodic vendor assessments miss the real access picture
Periodic assessments are a snapshot of governance, not a live view of access. They can confirm what a vendor said at review time, but they do not track how quickly integrations, delegated permissions, tokens, and support paths change afterwards. In practice, the access relationship can drift long before the next questionnaire is due.
That gap matters because third-party risk is often created by changes in the operating relationship, not by the original onboarding decision. A vendor may add a new SaaS connector, widen API scopes, or inherit access through another supplier without any visible change in the assessment record.
When that happens, the assessment can still look satisfactory while actual exposure has already expanded. A stale answer set is especially misleading when the vendor’s access is tied to production data, privileged workflows, or downstream systems that were not part of the original scope.
Why the assessment cycle lags the exposure cycle
The main failure is timing. Assessment cadence is usually measured in months, while access changes can occur in days or hours through new integrations, emergency support, temporary elevation, or hidden reuse of credentials. The result is a control that validates history instead of current reality.
This is why access governance has to be treated as a lifecycle problem, not just a review task. The useful question is not only whether the vendor was approved, but whether its current permissions, credential use, and data reach still match the approved intent.
Tools and process boundaries also create blind spots. A questionnaire may focus on policy ownership, but miss how the vendor actually authenticates, which systems it can reach, and whether its access is direct, inherited, or brokered through another service. For third-party access, Third-Party, B2B and Contractor Access Guide is useful because it frames sponsorship, least privilege, time limits, and reviews as living controls rather than one-time onboarding steps.
What practitioners should measure instead of trusting the questionnaire alone
Periodic assessment still has value, but it should be paired with evidence that access has not drifted. The most important signals are active entitlements, token age, privilege scope, unused accounts, and whether vendor access can be tied to an owner and an expiry date. If those cannot be produced quickly, the assessment is not giving you operational assurance.
Practitioners also need to separate vendor compliance from access assurance. A vendor may be “in good standing” on paper while a stale OAuth token, forgotten support account, or overbroad connector continues to expose data. For that reason, IAM and IGA Basics is a useful companion reference because it explains why provisioning, entitlement review, and access certification must be continuous to stay meaningful.
Where third-party access is mediated through tokens or integrations, the risk rises further because those controls can outlive the review cycle and quietly accumulate privilege. Salesloft OAuth token breach shows how a stale trust relationship can turn into broad downstream access when token governance lags operational change.
Risk and Threat Considerations
Third-party access risk is missed when organisations assume the vendor relationship is static. In reality, attackers and negligent operators both benefit from stale approvals, because outdated access records often hide broader reach, dormant tokens, and support paths that were never revalidated.
Failure mechanism: Access expands after the last review through new integrations, inherited permissions, reused credentials, or untracked support access, while the assessment record remains unchanged.
Impact: The organisation continues to treat the vendor as low risk even though the vendor can now reach more systems or data, which increases the blast radius of compromise and delays revocation when something goes wrong.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, while ISO/IEC 27001:2022 and SOC 2 (AICPA) define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-2 — Account Management | Vendor access drift is an account lifecycle problem requiring current entitlement control. |
| AC-6 — Least Privilege | Third-party access risk grows when vendors retain more access than they need. | |
| IA-5 — Authenticator Management | Stale tokens and credentials can preserve third-party access beyond the review cycle. | |
| Recommendation — Review and revoke vendor accounts when business need or scope changes. Constrain vendor permissions to the minimum access needed for the current task. Rotate and retire vendor authenticators on a defined lifecycle. | ||
| ISO/IEC 27001:2022 | A.5.19 — Information security in supplier relationships | Supplier relationships need ongoing security oversight, not only onboarding checks. |
| A.5.20 — Addressing information security within supplier agreements | Contracts must define access limits, review expectations, and change handling. | |
| Recommendation — Embed continuous security obligations into supplier oversight and review. Set explicit supplier access and review obligations in contracts. | ||
| CIS Controls v8 | CIS-6 — Access Control Management | Third-party access should be continuously managed as permissions change. |
| CIS-5 — Account Management | Accounts and tokens can outlive the assessment cycle and increase exposure. | |
| Recommendation — Continuously review and reduce vendor access rights. Inventory and retire vendor accounts, tokens, and support access promptly. | ||
| SOC 2 (AICPA) | CC6.1 — Logical Access Security Software | Vendor access must be restricted and monitored as part of logical access control. |
| CC6.6 — Role and Responsibility Assignment | Third-party access needs accountable ownership and review responsibility. | |
| Recommendation — Restrict vendor access paths and monitor them for drift. Assign clear owners for vendor access approvals and periodic reviews. | ||
Practitioner Guidance
What to verify: Verify the vendor’s current entitlements, token inventory, and privileged paths against the last approved assessment. If you cannot tie each active access path to an owner, expiry, and business justification, treat the assessment as incomplete.
What good looks like: Good third-party governance shows a short, current list of live access paths, not just a completed questionnaire. The access decision should be revisited when integrations, scopes, support arrangements, or data boundaries change, not only on the annual review date.
Decision rule: If the vendor can still authenticate or reach production after the original approval context has changed, prioritise access reduction or revalidation before you rely on the next scheduled assessment.
Practitioner takeaway: Periodic vendor assessment is a governance checkpoint, but it is not an access-control mechanism; the real control is whether the organisation can continuously see, bound, and retire third-party access as it changes.
Related resources from NHI Mgmt Group
- How should organisations govern third-party access in a vendor risk policy?
- How should organisations expand third-party risk management beyond periodic vendor reviews in complex ecosystems?
- Why do third-party access and vendor connections increase compliance risk in regulated financial environments?
- Which matters more for third-party risk, vendor approval or access scope?
Deepen Your Knowledge
Free weekly newsletter
Subscribe to the NHI & AI Identity Journal
The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.
Bonus 33% off our NHI Course when you subscribe.
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org