Every enterprise compliance programme includes some variation of the same ritual: once a year, a vendor is asked to complete a security questionnaire. They fill it out — sometimes carefully, sometimes not — and the answers are filed away. A checkbox is ticked. The vendor is considered "reviewed." Everyone moves on until the calendar rolls around again.
This process feels rigorous. It has documentation. It has sign-offs. It has audit trails. And it is, in almost every meaningful sense, a fiction.
The annual vendor review cycle was not designed for malice or negligence. It emerged from a reasonable constraint: gathering information about vendors was expensive, slow, and labour-intensive. If you could only afford to look once a year, once a year was better than never. That logic made sense in 1995. It does not make sense today.
The statistics above — drawn from IBM's 2024 Cost of a Data Breach Report and the Ponemon Institute's Third-Party Risk Management Study — expose an uncomfortable truth: the average enterprise discovers a supply-chain breach more than six months after it began. An annual review conducted six months ago offers no protection against what is happening right now.
The problem with point-in-time assessment
A vendor questionnaire captures a snapshot. It records what a company says about its controls, certifications, and practices on the day the questionnaire was completed. It cannot capture what happens the next day, or the week after, or in the nine months between now and the next review cycle.
Consider what can change in a year for a mid-sized software vendor:
- A key security engineer leaves and the team contracts by 30%
- The company takes on new investment and undergoes a platform migration
- A SOC 2 Type II certification lapses without renewal
- A critical CVE is published in a library the vendor has in production
- A regulatory action is opened in a jurisdiction the vendor operates in
- The company's financial health deteriorates, reducing capacity for security investment
None of these events would appear in last year's questionnaire. All of them are material to the risk you carry by continuing to work with that vendor. And all of them can happen — and often do — in the gaps between annual reviews.
"A questionnaire answered in January tells you nothing about what is true in September. But the breach in September will still be your problem."
Why the cycle persists despite its flaws
If annual reviews are so ineffective, why do they remain the dominant practice? The answer involves a mix of institutional inertia, audit requirements, and the genuine difficulty of the alternative.
First, annual reviews satisfy auditors. Most compliance frameworks — including SOC 2, ISO 27001, and various GDPR-derived requirements — specify that vendor assessments must be conducted periodically. Annual is accepted as periodic. The frameworks were written when continuous assessment was not operationally feasible, and the language has not kept pace with what is now technically possible.
Second, most risk teams are understaffed relative to their vendor portfolios. A mid-sized enterprise may have 200 to 1,000 significant third-party relationships. With a team of five analysts, reviewing each vendor more than once a year is simply not achievable through manual effort.
Third, the vendors themselves are adapted to the cycle. Security questionnaire fatigue is real. Vendors receive identical or near-identical questionnaires from dozens of customers annually, and they have learned to complete them efficiently — which often means with less rigour than their customers assume.
The annual review cycle was not designed to be effective. It was designed to be defensible. There is a meaningful difference between a process that reduces risk and one that produces documentation proving that a process was followed. The latter dominates enterprise practice today.
Replacing a snapshot with a living document
The fix is not to run the same questionnaire more often. A more frequent point-in-time check is still a point-in-time check — it just exhausts the review team faster without closing the gap that matters. The fix is to stop treating vendor trust as something you measure once and start treating it as something a vendor maintains, continuously, in a form you can verify.
This is the premise behind a Dossier: not a completed form filed away after a review cycle, but a living trust document that a vendor keeps current because doing so is in their own commercial interest — and that you can check against signals you didn't have to ask for.
This only works if the underlying score is built to resist exactly the failure mode questionnaires have. A score built mostly from things a company can simply acquire — a certificate, a policy document, a checked box — measures the same thing an annual questionnaire measures, just with a faster refresh rate. We built SignalScore™ around a different governing rule: score what a company cannot buy from an auditor.
Practically, that means every signal feeding the score is sorted by how hard it would be to fake. Credentials and attestations — the things any company can acquire or write — are real, but they are the floor, not the ceiling. What we weight more heavily is behavioral evidence: how quickly a company actually closes findings from its own pentests, how candidly it discloses incidents, whether its evidence is current or quietly stale. And above that sits what a company never gets to author at all — what an external scan of their actual public posture shows, independent of anything they submitted.
"Zero findings disclosed is not the same as zero findings. A company that shows what broke and how fast they fixed it should outscore one that simply says nothing."
Why disclosure has to be the rewarded path
This is the part that breaks most cleanly from the annual-review mentality. Under a questionnaire model, the rational move for a vendor is to disclose as little as possible — every admitted finding is a risk to the relationship, with no offsetting upside. Under a model where remediation speed and candor are scored components, the incentive flips: a vendor that discloses findings and closes them quickly scores higher than one that shows a clean sheet with no evidence behind it. Concealment is structurally capped — it can earn partial credit for coverage, never the credit for speed or honesty.
The same logic extends to third-party events outside a vendor's direct control — a breach at one of their own subprocessors, say. A vendor that acknowledges the event and discloses how they assessed and handled it sees a penalty that shrinks toward neutral. A vendor that says nothing carries the full, decaying penalty until it ages out. The score moves on what a company actually does in response to a real event, not on whether the event happened to occur during a review window.
The business case is not just risk reduction
A continuously maintained trust posture is usually framed as a defensive investment — a cost incurred to reduce the odds of a costly incident. That framing undersells it. A vendor who can hand a prospective enterprise customer a live, auditable Dossier — rather than a stale SOC 2 letter and a freshly completed questionnaire — changes the shape of the sales conversation. Procurement is reviewing evidence instead of waiting on answers. That shortens cycles on both sides of the table.
The cost of a third-party breach averages $4.76 million according to IBM's 2024 data. The cost of maintaining a living, verifiable trust posture is a fraction of that — and unlike an annual questionnaire, it pays back on the sales side as well as the risk side.
The annual vendor review will not disappear overnight. It is too deeply embedded in compliance frameworks, procurement processes, and institutional muscle memory. But the enterprises — and vendors — that move first, replacing point-in-time snapshots with a living document scored on what's actually verifiable, will carry materially less risk and spend less time on assessments that mostly produce false confidence.
The questionnaire as the primary instrument of third-party risk management had a good run. Its time is up.