I was working through an assessment when the third party asked to postpone the whole thing.

Their reason was understandable.

They were already going through ISO 27001 and SOC 2 work, and our assessment was evidence-based too. From their side, another questionnaire asking them to provide evidence for their controls probably felt like one more audit arriving at exactly the wrong time.

The customer still needed a current assessment, so pushing the whole thing out wasn’t really an option.

I started thinking about what I actually needed from the third party.

Did I need them to complete another questionnaire before I could begin assessing them?

Or did I need enough evidence to understand and validate their control environment?

I told them to send me the assurance material they already had. I could work through the questionnaire on my side, use the evidence to start validating the responses, and go back to them only for what the material didn’t answer.

They sent the evidence.

That kept the assessment moving and cut down on some of the duplicate work I was asking them to do.

But the work hadn’t disappeared.

I was now reading the documents, finding what was relevant, connecting it back to individual requirements, documenting the responses, deciding what the evidence actually supported, and figuring out what was still missing.

We reduced some of the vendor’s manual work by moving more of it to the assessor.

That was the part I kept thinking about.

There are already better ways to reuse evidence. Vendors can maintain current SOC reports, certifications, policies, testing material, and other documents in trust centers or similar repositories instead of sending the same files over and over again.

AI can help find and map some of that information too.

But having the evidence and knowing what conclusion it supports are still two different things.

Someone still has to decide whether the evidence answers the requirement, whether it covers the right service and scope, what is missing, and whether anything needs to be clarified.

An ISO certification doesn’t tell me everything about a service. A SOC report may cover something different from what I’m assessing. A policy may tell me what should happen without showing me that it actually does.

Those are judgment calls I still want an assessor making.

What feels increasingly unnecessary is all the manual work required just to get information that already exists into another questionnaire before that judgment can even begin.

The extension request initially looked like a timing problem.

Once I worked through it, timing was only part of it.

The vendor already had much of the evidence I needed. What they were really trying to avoid was repeating a lot of work just to present the same information in another assessment format.

I could reduce that burden without lowering what I still needed to validate.

The tradeoff was that more of the work moved to my side.

That made me look at extension requests differently.

Sometimes the vendor genuinely needs more time.

Other times, the request is telling me something about how much repetitive work the assessment itself is creating.

When a vendor asks for more time, how do you tell whether they actually need a later deadline or just a less repetitive way to give you what you need?

Reply

Avatar

or to participate