I was reviewing a questionnaire response about insider threat controls.
The question asked whether the third party had a specific policy and related controls in place. They answered “Yes” and added comments describing several technical measures.
On the surface, it looked like a solid response.
But when I moved into validation, I couldn’t find evidence supporting the claim itself. I couldn’t establish that the policy existed, and I couldn’t connect the controls described in the comments to evidence showing that the broader requirement was actually in place.
So I went back to the third party and explained why I was asking for more. The assessment required evidence-based validation. Their answer told me what they said was true, but I still needed support before I could treat it as validated.
A questionnaire captures the third party’s representation of its own environment. That representation has value. The respondent may know the control well, their explanation may be completely accurate, and in some assessment models self-attestation may be an acceptable level of assurance.
But when evidence-based validation is required, the answer is still the starting point.
A “Yes” can easily take on more certainty as it moves through an assessment. The third party answers the question, adds some context, and the questionnaire is completed. Later, someone reviewing the record may simply see that the control is marked as implemented without knowing what actually supported that status.
In the insider threat response I was reviewing, the technical measures described in the comments gave me useful context about the third party’s security environment. I just didn’t have enough to turn the broader claim into something I was prepared to validate.
The accurate record at that point was that the third party said the policy and controls were in place.
I wasn’t saying they were wrong.
I simply hadn’t established that they were right.
The source of a conclusion matters, especially once an assessment starts being reused.
If I come back to the same record later, I want to know whether a control status came from the third party’s answer, independent assurance, technical evidence, a clarification during the assessment, internal confirmation, or some combination of those things.
Otherwise, all of that history can eventually get reduced to the same Yes.
Once the original context disappears, the next assessor may inherit a conclusion without knowing how much confidence was actually behind it. A risk owner may rely on it. An auditor may see it. What began as “the third party told us this” can gradually start reading like “we established this.”
The questionnaire wasn’t the problem here. It did what it was supposed to do: capture the third party’s response.
The validation step had a different purpose. I had to decide how much of that response I could actually stand behind based on the information available.
I want that source and validation history to remain visible after the assessment is complete, especially when someone else may rely on the conclusion later.
If the questionnaire disappeared tomorrow, what would still support the conclusions in your assessment?

