For vendor risk analysts and assessment teams
No independent report to hand you yet. No authorization. No conformance report. No second-region standby. No estate outside the United States. No deletion from an existing backup image. Each of those closes something, each is written on its own page in detail, and none of them will be discovered in week nine.
An assessment queue does not fail because the questions are hard. It fails because each answer has to be extracted — a form returned incomplete, a follow-up call, a document under an agreement, a clarification about what a word meant, and three weeks of elapsed time for perhaps four hours of actual analysis.
The pattern that wastes the most time is the qualified yes. A supplier answers affirmatively, the answer turns out to depend on a configuration, a tier, a deployment shape or a clause not yet agreed, and the analyst discovers the dependency two rounds later. Nobody lied at any point and the assessment took three times as long as it needed to.
Inconsistency is the other tax. The same supplier answers one question one way to a large organisation, differently to a smaller one, and differently again in a security document, because different people answered from different sources and none of them was authoritative. An analyst comparing two answers cannot tell whether something changed or whether somebody guessed.
And the deepest inefficiency is that the interesting information is what a supplier cannot do, which is precisely what a questionnaire is worst at extracting. Forms are built from affirmative criteria, so a gap appears as a partial answer with a comment, and the comment is where the whole risk lives.
Meanwhile the queue does not stop. Reassessments come round, new requests arrive faster than they close, and the analyst is measured on throughput while being accountable for anything that gets through. Everybody in the function knows which of those two pressures wins when they conflict.
A questionnaire is a discovery exercise only because suppliers answer privately, inconsistently and affirmatively — so the analyst spends their time extracting rather than assessing, and the gaps arrive last.
Everything an assessment asks about is written on a page here, in detail, in public. Not a summary: the mechanism, the timeframe, the definition, and the limit. That turns the questionnaire into a verification exercise — you read, you check, you press on the parts that matter to your organisation — and it makes it impossible for us to answer one reviewer differently from another, because there is one published answer and it is the same one.
The declines are collected here rather than distributed politely across seventeen pages. There is no independent report to hand over — a security attestation is under way and none exists yet. No authorization is held for federal use, and no equivalency is claimed. No accessibility conformance report exists. There is no warm standby in a second region. There is no estate outside the United States. A deletion instruction does not reach inside a backup image already written, and the clause requiring it will not be signed. Each of those closes a category of buyer, each is stated in the hero of its own page, and each is checkable today.
The refusals are separate from the gaps and deserve their own listing, because a gap may close and a refusal will not. Determining eligibility, deciding employment or standing, scoring a person for treatment, and ordering a queue of people by anything resembling desirability are refused as acts. No appliance image is offered. No per-customer release approval exists on the shared service. No global ordering is promised across the integration surface. No availability percentage is quoted, because none has been independently measured.
Where a page says designed rather than attested, that is a deliberate word and your file should carry it as designed. Nearly everything here is designed. A design intent that has never been independently examined is a real position and a weaker one than an attested control, and inflating it would buy one signature at the cost of every later one.
What that leaves you is a shorter and better assessment: read the pages, verify the handful that matter to your organisation with the tests each page suggests, and spend your remaining time on the two or three risks that are specific to how your organisation would use this rather than on establishing facts that were already written down.
Whether a disqualifying gap exists — measured by reading the six published declines against your own requirements before issuing anything.
Whether answers differ by audience — measured by comparing a returned questionnaire answer against the published page on the same subject.
Which claims are attested and which are designed — measured by the basis stated on every claim, entered into your file as stated rather than collapsed.
Whether a claim can be verified without us — measured by running the test each page names, in a trial, with our involvement removed.
Elapsed time from request to decision — measured by comparing this assessment’s elapsed days against your queue’s median.
Where the residual risk actually is — measured by the two or three items specific to your organisation, once the general ones are read rather than extracted.
no independent report of any kind exists to hand over today. No authorization, no conformance report, no second-region standby, no estate outside the United States, and no deletion from an already-written backup image. Nearly every property across these pages is designed rather than independently attested, and your file should say designed. Publishing answers does not make them verified — it makes them consistent and checkable.
Each subject an assessment covers has its own page with the mechanism, the timeframe and the limit: how the system is built and where a compromise stops; how customers are separated and what is genuinely shared; where records sit and where copies sit; how identity works and what happens when somebody leaves; what a processing agreement can and cannot commit to; where models come from and what happens when one changes; who is accountable for an automated act; who else is in the chain and what notice you get.
And the operational half: which deployment shapes exist and what each costs your team; what happens during an outage and what has never been rehearsed; how you leave and what an export actually contains; what a service level means once the definitions are fixed; how integrations behave when a call fails; how records reach your own warehouse; where audit evidence lands; how change reaches your change process; and what is and is not true about accessibility.
The one thing worth doing before reading any of them is checking the declines above against your own mandatory requirements. If one of them disqualifies us, that is the correct outcome of an assessment and it should take an hour rather than a quarter.
It proves consistency and it does not prove correctness. A published answer cannot be tailored to an audience, cannot quietly differ between a security document and a sales conversation, and can be held against us by anybody. That is a real property and it is not verification.
Verification is the part that stays yours, which is why nearly every page names a test you can run without our cooperation. Revoke a credential and watch the connection stop. Omit a tenant qualifier and see what returns. Disable a dependency and watch what continues. Delete a record and see whether the warehouse forgets. Run an export and load it somewhere else. Those tests are the assessment; the pages are what stops you spending three weeks getting to them.
On independent assurance the position is the same everywhere here: a SOC 2 Type II attestation is in progress and no report exists yet, so nobody can be handed one. It is an attestation with a defined scope and period rather than a certification, and the two words are not interchangeable. We hold neither a FedRAMP authorization nor a FedRAMP certification and claim no equivalency.
And the standing commitment behind all of it: where something changes, the page changes rather than the answer changing in a conversation. A published claim that turns out to be wrong is corrected in public, which is a worse day for us and a considerably better arrangement for you.
Start with the six gaps rather than with the capabilities. If one of them is mandatory for your organisation, the assessment is finished and it took an hour. That is the highest-value hour available in this whole exercise and almost no process is ordered to spend it first.
Then pick the two or three subjects that genuinely carry your organisation’s risk and run the tests those pages name. Verification of the things that matter beats extraction of everything.
Use the questionnaire to confirm rather than to discover, and treat a returned answer that differs from a published page as a finding in itself. That comparison is a control you get for free here and cannot run against a supplier who answers only in private.
And record designed and attested as different entries in your file. It is the accurate distinction, it is the one an examiner would arrive at anyway, and collapsing it is the most common way a risk register overstates what an organisation actually knows.
One hour reading the published declines against your organisation’s mandatory requirements, before any form is issued or any call is scheduled.
This inverts the usual order deliberately. An assessment that looks for the disqualifier first either closes in an hour or proceeds knowing that the general facts are already settled, and both outcomes are better than discovering a mandatory gap after three weeks of correspondence.
If nothing disqualifies, choose the two or three subjects that carry your organisation’s actual risk and run the tests those pages name in a trial. That is where the analysis belongs and it is where a queue-bound function almost never gets to.
Then issue the questionnaire if your process requires one, and compare its answers against the published pages. A difference is a finding, and it is a control you do not have with a supplier who answers only in private.
Because the alternative costs more. A gap discovered in week nine burns your team’s time and ours and ends the relationship badly; the same gap read in hour one ends it cleanly and leaves the door open for a different requirement later. And publishing removes our ability to answer one reviewer differently from another, which is a discipline rather than a courtesy — there is one answer, it is public, and anybody can hold us to it. That is worth more to you than a favourable private answer would be.
It does not, and this page says so plainly: publishing proves consistency, not correctness. Which is why nearly every page names a test you can run yourself without our cooperation — revoke a credential and watch the connection stop, omit a tenant qualifier and see what returns, disable a dependency and see what continues, run an export and load it elsewhere. Those tests are the assessment. What the pages do is stop you spending three weeks of extraction before you get to them.
Then issue it, and use the published pages to make it a verification exercise rather than a discovery one. There is an additional control in that sequence you do not usually have: compare each returned answer against the published page on the same subject, and treat any difference as a finding. Against a supplier who answers only in private, an inconsistency between what you were told and what somebody else was told is invisible to you. Here it is checkable.
It is, and that should go into your file exactly that way rather than being collapsed. A design intent that no third party has examined is a real position and a materially weaker one than an attested control — the honest entry is the one an examiner would arrive at anyway. A security attestation is in progress and no report exists yet, so nobody can be handed one, and it will be described as an attestation with a scope and a period rather than as a certification when it does exist.
Then the page changes in public, which is a worse day for us and a better arrangement for you than a private correction to whoever happens to ask next. That is the standing commitment behind the whole section: where something changes, the published answer changes rather than the conversation quietly changing. It also gives your reassessment cycle something to compare against — you can diff a page between two assessments, which is not possible with answers that only ever existed in a returned form.