451 Research report on Cyber Risk Assurance fueled by continuous control monitoring. Read the report →

Why security questionnaires can’t measure vendor risk

Sravish Sridhar

Sep 2, 2026

paperwork-vs-proof

“Friends don’t send friends security questionnaires. “If you hang around me long enough, you will hear me say it. It gets a laugh, but the point underneath it is serious. Are security questionnaires enough to manage third-party risk? No. A questionnaire tells you what a vendor is willing to claim on a given day. It does not tell you whether the control behind that claim is working. Those are two very different things, and most third-party risk programs are still built on the first one.

When a 400-question PDF is the whole program, you are managing paperwork, not risk. And in a world where vendor ecosystems are enormous, constantly changing, and where a single weak vendor can unravel years of security investment, paperwork is not enough.

Why security questionnaires create false confidence

A completed assessment feels like progress, because the vendor said yes, the box is checked, the workflow is closed. But a vendor saying yes does not mean the control behind it is working, and a closed workflow does not mean the business is protected.

The data bears this out. In a RiskRecon and Cyentia survey of 154 third-party risk professionals, 84 percent use questionnaires and 81 percent say their vendors pass with no exceptions. Yet only 14 percent are highly confident those vendors actually meet the requirements. If questionnaires were working, confidence would climb with every passing score. Instead we get perfect scores and worse outcomes.

Beyond that, the questions are often absurd. CISO Myke Lyons shared in our Strategic CISOs series that his team is still “asked more than ten questions about tape backups, for a modern cloud service provider.”  The form was not built for how his company actually operates, so the answers are not particularly useful. I have talked to CISOs who track a formal KPI for how many of these their people complete by hand every day.

A questionnaire is a snapshot, and vendor risk changes constantly. Vendors change, access changes, subprocessors change, and incidents happen between one assessment and the next. A control that passed last year can stop working, and a static questionnaire will never tell you. This is the same reason point-in-time GRC is obsolete across the board, and vendor risk is where it bites hardest.

Consider how long trouble stays hidden. IBM’s 2025 Cost of a Data Breach Report found that breaches traced to a third-party vendor or supply chain compromise take longer to identify and contain than any other kind, at 267 days, roughly nine months. A questionnaire a vendor answered last year has no way of catching a control that failed last quarter. By the time your next assessment comes due, the exposure has already run its course. As Lamont Atkins, a partner at McKinsey, has observed, a vendor can look fully compliant on paper and still introduce real risk into your business.

What evidence-based vendor risk looks like

The better model is to stop asking vendors what they do and start analyzing proof of what they actually do. In practice that means three things.

  1. Combine outside-in signals, like ratings and threat feeds, with inside-out evidence, like real control and contract artifacts, so you are reading posture rather than promises.
  2. Tier your vendors by blast radius, so the ones touching crown-jewel data and critical operations get genuine scrutiny while the rest are not buried in forms they do not warrant. 
  3. Reassess when something changes, not once a year because the calendar says so.

Automation makes this possible at enterprise scale. AI can complete most of the assessment workflow, so your team stops chasing essays and spends its time on the anomalies, gaps, and escalations that actually matter. Your people keep the judgment and the approvals, and automation takes the volume.

One Global 2000 company that made the move went from assessing 20% of its vendors to nearly all of them, and found four times as many critical gaps in the process. When you can actually see the risk, you can act on it.

Where to start

You do not have to rebuild the program overnight. Start by tiering your vendors and being honest about which ones could genuinely hurt the business if they failed. For those, ask for evidence and signals instead of essays, and set the expectation that you will look again when something changes. If you want a practical path from static questionnaires toward continuous trust, we walk through one in 6 ways to move from security questionnaires to self-serve trust.

The goal is straightforward. When your board, a customer, or a regulator asks whether a critical vendor is a risk, you should be able to answer from evidence, not from a form the vendor filled out months ago. A questionnaire can start that conversation. It was never meant to end it.

See how TrustLens delivers agentic, evidence-based third-party assessments.

Got Trust?®

TrustCloud makes it effortless for companies to share their data security, privacy, and governance posture with auditors, customers, and board of directors.
Trusty