The starting point
A questionnaire the vendor filled in is not an assessment
The standard procurement artefact is a spreadsheet the vendor completed about itself, returned to a buyer who has no practical way to test any individual answer. That is a useful structured disclosure. It is not diligence, and the market already knows it: research cited by Vanta reports that only 34% of third-party risk management professionals believe questionnaire responses are accurate, and that a single questionnaire takes somewhere between five and fifteen hours to complete.
Two things follow from that number, and they point in the same direction. The first is that adding more questions does not add more assurance. If the instrument is distrusted, a longer instrument is distrusted at greater cost to both sides. The second is that verifiable evidence beats volume of answers by a wide margin. A vendor that names its model provider and cites the specific contractual clause governing training on customer data has told you more in one line than a two-hundred-question spreadsheet of yes and no.
The failure mode is rarely dishonesty. It is that the person completing the questionnaire is answering in good faith about a general product while you are buying a specific deployment, and the general answer and the specific answer diverge in exactly the places that matter. Data residency is the clearest example: a company can be headquartered in the EU, hosted in the EU, and still process your prompts in whatever geography its chosen deployment type routes to. The questionnaire has no field for that distinction, so it is answered "yes" and nobody has lied.
An assessment is therefore not a longer questionnaire. It is a short list of high-consequence claims, each of which is checked against a primary source: a contract clause, a configuration state the vendor can demonstrate, a scope statement on a certificate, a report section, a published sub-processor list. Everything else can be taken on disclosure. This is what makes the work finishable in days rather than becoming an open-ended audit that nobody completes before the purchase order is signed.
It also means that the output has to record what could not be verified. An assessment that presents only what was confirmed is a sales document. The useful deliverable states plainly which claims were checked against evidence, which were accepted on the vendor's word, and which the vendor declined or was unable to answer. The third category is usually the most informative part of the file.
Check
Claims where a wrong answer changes the buy decision or creates a regulatory exposure. Verify these against primary sources.
Accept
Claims that are low consequence or independently unverifiable. Record them as disclosure, not as verified fact.
Escalate
Refusals, non-answers and contradictions between documents. These are findings in their own right.
Re-ask
Anything version-dependent. A model, a deployment type or a sub-processor list is a moving target, not a settled fact.
The point of an assessment is not to collect more answers. It is to decide which few answers you are going to insist on being able to prove.
Related evidence and next steps
- Vanta: why security questionnaires are ineffective— Five to fifteen hours per questionnaire; only 34% of TPRM professionals trust the answers.
- Security questionnaire readiness (the other side of this problem)— What to do when the questionnaire is being sent to you rather than by you.
- The AI security service line— How vendor assessment, access review, classification and testing fit together.




