I once picked up an assessment where the historical record painted a fairly clear picture of what the third party was expected to do.

The earlier scope described a planned implementation. The service was supposed to be introduced into the environment, with access to information that would’ve mattered from a risk perspective.

If I’d treated that historical scope as the current state, the assessment would’ve been straightforward and wrong.

While revalidating the scope with the relationship owner, I asked what services were actually in use because I wanted the assessment to reflect the relationship as it existed now.

I learned that the planned implementation had never happened.

The software had never been installed, and the planned work hadn’t progressed into an operational proof of concept. The third party hadn’t accessed the systems, environments, or data described in the earlier scope. Access material created for the proposed work had already been removed.

There was no active implementation left to assess.

The original documentation wasn’t necessarily inaccurate.

It was historical.

Third-party records accumulate over time. Intake forms, business descriptions, proposed architecture, contracts, implementation plans, security reviews, and prior assessments may all describe the same relationship at different points in its lifecycle.

The trouble starts when the timing disappears.

Something that originally meant, “This is what we plan to implement,” can gradually be read as, “This is what we implemented.” A proposed data flow becomes an assumed data flow, and expected access starts looking like established access.

In this case, I needed to separate what had been proposed, what had actually become operational, and what was still true now.

Instead of carrying forward previously documented data use, system access, and deployment as established facts, I traced them forward. I checked whether the software had ever been installed, whether implementation had actually begun, whether the anticipated access had ever been granted, whether any data had moved, and whether anything remained active.

By the time I finished that review, my understanding of the relationship had changed before I evaluated a single control.

The historical record still mattered. It showed what had been contemplated at the time. But it couldn’t tell me what was true now without current validation.

That’s what can get lost when old scope is carried from one assessment into the next. Once the original date and context fade into the background, a plan can start looking like an operational fact.

A proposed implementation can also sit in a third-party inventory for years if nothing triggers someone to confirm what happened after the original plan. Eventually, another assessor has to reconstruct the relationship manually.

The assessment process should be able to preserve more than what was once proposed. It should also make clear whether the proposal became operational, changed, or never happened at all.

Otherwise, uncertainty gets carried forward until someone notices that the record and the real relationship no longer match.

What in today’s scope have you actually re-established, and what are you still carrying forward because it was documented before?

Reply

Avatar

or to participate