Compliance · Vendor risk

The answer was true in March. The questionnaire went out in September.

Answer libraries make the second security questionnaire cost a fraction of the first. They also quietly keep asserting controls that stopped working — and a questionnaire answer is not marketing copy, it is a representation your customer will hold you to.

SemperWise Research Desk 8 min read Compliance
ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit

Every company past its first enterprise deal knows the ritual. A customer’s procurement team sends a spreadsheet — 120 rows, sometimes 400 — and the deal stops moving until somebody fills it in. It is a CAIQ, or a SIG Lite, or a VSA, or a questionnaire the customer’s legal team wrote themselves in 2019 and has extended every year since. The questions are 80% the same as the last one. The phrasing is entirely different.

So you build an answer library. You answer "do you encrypt customer data at rest?" once, store it, and the next time a version of that question arrives it fills itself in. This is genuinely good engineering and it saves real weeks. Every compliance platform on the market ships it, and if you do not have one you should.

The problem is not the library. The problem is what happens to it in month fourteen.

A security answer is a claim with a shelf life

Consider four ordinary answers, all of them true on the day they were written:

  • "We perform user access reviews quarterly." True in March, when the review ran. The Q2 review slipped, then Q3 was skipped during a reorganisation. The sentence has not changed.
  • "All production applications are penetration tested annually by an independent third party." True when the report was dated. That was fourteen months ago; this year’s test was deferred pending budget.
  • "Data at rest is encrypted using AES-256 with keys managed in a dedicated KMS." True for the original platform. The analytics workload added in June writes to a bucket that nobody enabled encryption on.
  • "We maintain a documented disaster recovery plan, tested annually." The document exists. The test has never happened. It was true enough when written that nobody questioned it.

Not one of those sentences is a lie anybody told. Each one is a sentence that stopped being true while sitting in a database, and there was no moment at which anyone was asked to reconsider it. That is the failure mode, and it is structural: the answer is text, and text does not expire.

What the automation vendors actually automate

The current generation of questionnaire automation does three things well and one thing not at all.

  1. It matches.

    A new question is compared against what you have answered before, so a reworded version of a question you have already handled fills itself in. Fast, effective, and the source of most of the time saved.

  2. It drafts.

    For questions the library has never seen, a language model writes something plausible from whatever context it was given. Useful when the context is your real control state; actively dangerous when it is not.

  3. It tracks completion.

    How many rows are done, how many remain, who is blocking. Ordinary project mechanics, and welcome.

  4. It does not expire anything.

    This is the gap. Nothing in a standard answer library knows that the evidence behind an answer has lapsed, because the answer was never connected to any evidence in the first place.

The result is a system that gets faster every quarter and less accurate at the same rate. The library grows, the match rate climbs, the completion time drops — and the proportion of answers that no longer reflect reality rises silently, because nothing in the design is capable of noticing.

Bind the answer to the artefact

The fix is not a review reminder. Calendar reminders to "review the answer library" are ignored for the same reason annual policy reviews are ignored: they arrive undifferentiated, covering hundreds of entries of which a handful have actually changed, so the rational response is to skim and approve everything.

The fix is structural. When an answer is approved, record what makes it true — the control it rests on, and the specific dated artefact that evidences that control. The access review answer points at the access review. The penetration testing answer points at the report. The encryption answer points at the key policy export. Then let the artefact’s own expiry date govern the answer.

Evidence already has a date

Any compliance programme worth the name records when an artefact was collected and when it stops counting. That expiry is exactly the signal an answer library needs, and in most organisations it already exists — it is just not connected to anything.

Expiry should disable, not delete

A stale answer should stay visible and stay in the history. What it loses is the right to speak for you unattended: it stops auto-filling new questionnaires and comes back to a human with the reason attached.

The stale list is a control report

Once answers expire with their evidence, "which answers went stale this quarter" is the same list as "which controls stopped being evidenced". That is a genuinely useful compliance artefact that nobody had to compile.

Citations travel to the recipient

If the export names the clause and the dated artefact behind each answer, the recipient can verify rather than trust. That changes the character of the document — and it is a competitive advantage in a procurement process, not just an internal hygiene measure.

Four rules for a questionnaire programme that stays honest

  1. Never let a machine send an answer.

    Drafting is automation; approving is a representation. Keep a person and a name between the two, and record which one it was. If a bulk-approve button exists, restrict it to answers a human already approved once against cited evidence — never to fresh model output that nobody has read.

  2. Ground the drafting pass in your real control state.

    A model told only the question will write the answer the question is fishing for. A model told which of your controls are verified, which are merely implemented and which are absent will write "partial" and "no" where those are the truth — which is what you need, because an overstated answer is the expensive kind.

  3. Make the count honest.

    A single "92% automated" figure invites trust it has not earned. Break it apart: how many answers came from your own approved library, how many were drafted by a model, how many were held back because their evidence expired, how many nobody can answer honestly. The last two numbers are the ones worth reading.

  4. Treat "we cannot answer this yet" as a legitimate output.

    The pressure in a questionnaire is always toward a "yes". A system that cannot return "no" or "not applicable, and here is why" is not a compliance tool; it is a plausibility generator with a deal attached.

The awkward test

Here is a question worth asking your current process, whatever tooling sits behind it: pick the last questionnaire you sent back, choose any three answers, and produce the artefact that made each one true on the day you sent it.

If that takes more than a few minutes, the answers were assertions rather than evidence — and the gap between those two words is where the risk in this whole exercise actually lives. Most organisations find at least one answer they can no longer support. That is not a scandal. It is simply what happens when claims and proof are kept in different systems, and it is fixable the moment they are kept in the same one.

SemperWise Research Desk

Compliance & Regulatory Research

Tracks primary sources — regulator notifications, standards bodies and audit guidance — and turns them into practical checklists our delivery teams use on live engagements. Every figure is checked against its original source before publication.

Next step

Talk to us about your next assessment.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.