They describe the vendor's security practices, data handling standards, and compliance posture in terms that satisfy the assessment process and create no verifiable obligation. Evidence is different: it is a record of what the vendor actually did, produced by a mechanism that the vendor does not control. The gap between vendor assurances and vendor evidence is the gap between vendor accountability as described in the governance program and vendor accountability as it actually operates.
The Assurance Economy
The vendor assessment process in most organizations is designed to receive and evaluate assurances. Questionnaires ask vendors to describe their practices. Vendors respond with descriptions of their practices. Reviewers evaluate the descriptions against defined criteria. High scores produce approvals. The process is efficient, scalable, and produces documentation. It does not produce evidence that the practices described actually operate as described.
Vendors operating in this environment optimize for high questionnaire scores rather than for strong security practices. Questionnaire responses that describe security programs in detail produce high scores regardless of whether the programs described are actually implemented. A vendor with a documented incident response plan, documented encryption standards, and documented access review processes scores well whether or not those processes produce their intended outcomes.
The questionnaire-based assessment economy rewards vendors for describing security programs well. It does not reward vendors for implementing security programs effectively. Organizations that rely exclusively on questionnaire-based assessment are measuring the quality of vendor self-description, not the quality of vendor security.
What Evidence Looks Like in Practice
Evidence From Third-Party Assessments
SOC 2 Type II reports, ISO 27001 certification reports, and penetration test results produced by independent assessors provide evidence that is not vendor-generated. The assessor conducted testing and produced findings based on what they observed rather than on what the vendor reported. The evidence is stronger than self-reported questionnaire responses because it reflects independent observation. Its limitations: the evidence covers only the scope of the assessment, reflects the state of the environment at the time of the assessment, and may not address the specific controls most relevant to the organization's vendor relationship.
Evidence From the Vendor's Operational Records
Vendors who have implemented the security controls they claim to have implemented produce operational records: access review completion records that show actual access changes made, vulnerability management records that show patch deployment timelines, incident response records that show how past incidents were handled. Requesting these records and reviewing them against the vendor's questionnaire responses provides a comparison between what the vendor claims and what their operational records show. The comparison is more revealing than the questionnaire alone.
Evidence From Exercising Audit Rights
DPAs and security addenda that include audit rights enable the organization to conduct or commission independent verification of the vendor's practices. Organizations that exercise audit rights — through direct audit, through agreed-upon procedures with an independent assessor, or through review of the vendor's internal audit findings — produce evidence that neither the vendor nor the independent certification body has produced for the organization's specific requirements. Audit right exercise is the most direct form of evidence. It is also the least commonly exercised.
Making Evidence Part of the Assessment Process
The practical transition from assurance-based to evidence-based vendor governance requires deciding which vendors and which controls are important enough to warrant evidence rather than assurance. Not every vendor requires the same level of evidence. The vendor with broad access to sensitive customer data warrants more evidence than the vendor providing a productivity tool used by a small team. The resource investment in evidence-based assessment must be allocated based on the risk profile of the vendor relationship.
For the highest-risk vendors, the evidence requirements should be specific and recurring: SOC 2 Type II reports reviewed annually, vulnerability management SLA performance data provided quarterly, access review records provided at each quarterly review, incident notification records maintained for the duration of the relationship. These are evidence requirements that can be built into the contract as ongoing delivery obligations rather than assessed at periodic points.
For lower-risk vendors, a hybrid approach — questionnaire assessment supplemented by specific evidence requests for the most important controls — provides more assurance than questionnaire alone without the full investment that the highest-risk tier warrants.
Define the evidence requirements for each vendor tier. Request evidence, not assurances, for the controls that matter most. Exercise audit rights for the vendors where the relationship warrants it.
Ask for the operational records. Review the SOC 2 against what the questionnaire claimed. Exercise an audit right for your top-five vendors this year. Evidence changes the accountability dynamic that assurances alone cannot change.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
