I was reviewing an assessment where the third party answered “Yes” to a question about removing access when someone leaves the organization.
Their policy supported the answer.
On its own, that could have looked straightforward. The questionnaire said the control was in place, and the policy said access should be removed following termination.
Then I reviewed the SOC 2.
There was an exception involving access that had not been removed as expected after someone left the organization.
That immediately changed how much weight I could put on the policy and questionnaire response.
Elsewhere in the questionnaire, the third party had disclosed a security incident. We asked for the incident and remediation documentation, and the details showed that an account belonging to someone who had already left the organization remained active and was later used to send phishing emails.
Now I had several pieces of evidence telling me something about the same control from different directions.
At that point, I couldn’t reasonably validate the control by pointing back to the policy.
The policy was still useful. It told me what was supposed to happen.
It just didn’t tell me whether that was what was happening now.
So we had to ask for more.
I wanted to understand what had actually changed after the issue was identified. What remediation had been completed? Was there a corrective action being tracked? Had the termination process changed? Had any part of access removal been automated? And were the people or accounts involved connected to the service I was assessing?
I wasn’t trying to prove that the third party never followed its policy.
A SOC 2 exception doesn’t establish that.
An incident doesn’t establish that either.
But together, they gave me enough reason not to treat the written policy as proof that the control was currently working the way the questionnaire said it was.
This is where evidence review gets more interesting than simply collecting documents.
A policy, questionnaire response, audit report, incident record, and remediation evidence can all be legitimate evidence while telling me different things.
The important question is what each one actually tells me.
The policy tells me what should happen.
The independent testing tells me something about what happened during the period reviewed.
The incident gives me context about a real failure.
And the remediation evidence can tell me what changed afterward.
None of them automatically replaces the others.
What I needed was enough current evidence to be comfortable with the conclusion I was putting into the assessment.
Because if the same type of issue happened again later, I wanted to be able to explain why I had considered the control validated based on what I knew at the time.
That is a very different standard from simply showing that a policy existed.
When your policy says the control works one way, but other evidence shows an exception, what do you need to see before you’re comfortable validating the current state?

