Failure modes
Six ways a questionnaire goes wrong, in the order they appear
These failures are structural rather than moral. A clinical-stage company with thirty people and a real product almost always has adequate controls and almost never has the artefacts that let someone else verify it. The gap between having controls and being able to evidence them is the entire problem, and it widens quietly until the first serious buyer asks.
The first failure is the absence of a control narrative. The company encrypts data at rest, reviews access quarterly and runs change management through pull requests, but no document says so. Every questionnaire is therefore an act of original composition. The second failure follows immediately: evidence is scattered. Policies live in Notion, screenshots in a Slack thread, the penetration test PDF in somebody’s inbox, the data processing agreement in a signed-contract folder nobody can search. The cost of assembling the evidence dominates the cost of writing the answer, which is why a questionnaire that looks like a two-hour job consumes a week.
The third failure is that nobody owns it. In a twenty-person biotech the questionnaire lands on the CTO, who is also the constraint on shipping. Vanta, drawing on its own analysis of the burden, puts the effort at five to fifteen hours per questionnaire; in a small company those hours come directly out of engineering capacity at the exact moment the deal needs the product to keep moving.
The fourth failure is inconsistency across instruments. The Standardized Information Gathering questionnaire, the Consensus Assessments Initiative Questionnaire and a customer’s bespoke Word document ask the same underlying question in three vocabularies. Without a canonical answer bank the company contradicts itself, and a buyer who receives two questionnaires six months apart notices. Contradiction reads as incompetence or concealment, and neither impression is recoverable inside a deal cycle.
The fifth failure is timing. Diligence is discovered at the point of maximum leverage loss: after the internal champion has sold the project, before signature. What should have been a project becomes a schedule risk, and the pressure to give a fast confident answer is precisely the pressure that produces the sixth and most damaging failure, which is overclaiming. Saying SOC 2 compliant when there is no report. Saying ISO certified when a consultant performed a gap assessment. Saying HIPAA compliant, which is a category error because HIPAA has no certification and nobody can issue one. A reviewer who catches a single overclaim discounts every other answer on the form, including the true ones.
There is a strategic point buried in the burden data that is worth stating directly. In the same analysis, Vanta cites RiskRecon research finding that only 34 percent of third-party risk management professionals believe questionnaire responses are accurate. The instrument is distrusted by the people who send it. That is not a reason to answer it badly; it is the reason that verifiable evidence beats additional prose. A current penetration test with a remediation record, a published self-assessment, and a policy set with real approval dates move a reviewer further than another thousand words of assertion.
No control narrative
Controls exist, but nothing written says what they are, so every questionnaire is composed from scratch.
Evidence scattered
Policies, screenshots, test reports and contracts live in five systems. Assembly cost dominates answer cost.
No owner
The form lands on the person who is already the shipping bottleneck, and the hours come out of engineering.
Inconsistent answers
Three instruments, three vocabularies, no canonical answer bank, and a buyer who compares two submissions.
Arrives mid-deal
Diligence surfaces after the champion has sold internally, converting a project into a schedule risk.
Overclaiming
One caught overstatement discounts every other answer, including the accurate ones.
The instrument is already distrusted. Verifiable evidence persuades where additional prose does not.
Related evidence and next steps
- Vanta: why security questionnaires are ineffective— Five to fifteen hours per questionnaire, and the 34 percent accuracy finding.
- AI access exposure review— The companion engagement that establishes what a connected assistant can currently reach.




