The score is compared to the prior year's score. If the score has not declined significantly, the review is marked complete. If the score has declined, a remediation plan is requested and filed. The vendor relationship continues unchanged. The data continues to flow. The access continues to exist. The annual review has produced documentation. It has not produced governance.
What the Annual Review Actually Produces
Annual vendor reviews produce a point-in-time snapshot of the vendor's self-reported security posture, compared to the prior year's point-in-time snapshot of the same self-reported posture. The comparison tells the reviewer whether the vendor's responses have changed between the two snapshots. It does not tell the reviewer whether the vendor's actual security posture has changed, whether the vendor's responses accurately reflect their practices, or whether the vendor's access to the organization's environment remains appropriate for the current state of both organizations.
The annual review was designed for an environment where vendor relationships were stable, where the security threat landscape evolved slowly, and where the most significant vendor risk was vendor insolvency or service failure rather than vendor compromise as an attack vector. In the current environment, where vendor compromise is an established attack technique and the security threat landscape evolves continuously, the annual review produces a document that was accurate on the day it was completed and becomes progressively less accurate from that day forward.
The annual review produces a record that the review occurred. Whether the review produced any governance — any change in how the vendor relationship is managed, any adjustment to the vendor's access based on what the review found, any verification that the vendor's assurances are accurate — is the question the review documentation does not answer.
What Changes Nothing
The Review That Confirms the Prior Assessment
Vendor reviews that compare current scores to prior scores and find no significant decline confirm that the vendor's self-reported position has not changed materially. They do not confirm that the vendor's actual security posture has not changed materially. A vendor whose security posture has deteriorated significantly since the prior review — through budget cuts, personnel turnover, or technology changes — may produce questionnaire responses that do not reflect the deterioration, either because the person completing the questionnaire does not know about the deterioration or because the questionnaire does not ask the right questions to surface it.
The Remediation Plan That Is Filed and Not Followed
When a vendor review produces findings that require remediation, the remediation plan is a governance artifact whose value depends entirely on whether the remediation is actually completed. Remediation plans that are filed and not followed up produce documented governance with no operational change. The finding persists. The remediation plan confirms it was acknowledged. The subsequent annual review may find the same finding, with the prior remediation plan attached as evidence that it has been previously identified.
The Review That Does Not Change Access or Terms
The most consequential outcome of a vendor review should be: the relationship is continued under current terms, the relationship is continued under modified terms that address identified risks, or the relationship is restructured to reduce the vendor's access scope. Reviews that consistently produce the first outcome regardless of what the review finds have not been designed to change anything. They are compliance exercises that confirm the relationship continues.
What Would Make the Review Matter
An annual vendor review produces governance when the findings from the review can change the vendor relationship and when the governance program has the organizational authority and practical mechanism to make those changes. The review that can result in access scope reduction, contract renegotiation, or relationship termination is a review that vendors take seriously and that produces actual governance. The review that can only produce a remediation plan that may or may not be followed produces documentation.
Building governance authority into the review process means establishing in advance what findings will produce what responses — and having organizational commitment to those responses. A finding that the vendor's encryption practices do not meet the contract's requirements should produce a specific response: remediate within 90 days or access is suspended. That response must be real — the organization must be willing and able to execute it — for the finding to produce governance rather than documentation.
The practical step is to review the last three annual assessments for the top ten vendors and ask: what changed as a result of these reviews? If the answer is primarily documentation and filed remediation plans, the program is producing records. If the answer includes access modifications, contract changes, and relationship restructurings, the program is producing governance.
Build consequence into the review. The annual review that can change nothing will change nothing.
Review what changed after the last three annual assessments. The changes — or absence of them — tell you whether the annual review is governance or record-keeping.
Enterprise practitioner perspective. Not legal advice. Part of the Deep Trust Governance Series by Verisq. Get the free weekly Breach Digest.
