TL;DR. ISACA has effectively called time on the supplier security questionnaire, and Australia’s regulators have moved the same way. Under CPS 230, CPS 234, the SOCI Act and now Tranche 2, a critical supplier’s signature on a self-assessment is no longer accepted as proof. The rule is clear. What puzzles me is that in my own client conversations the behaviour has barely shifted. The questionnaires still go out and the attestations still come back. So I want to put a genuine question to you, and I have made it a two-tap poll. Is the inertia because people do not know what to do instead, or because nobody else has moved yet?
For a couple of years now the conversation about third-party risk has been changing, and lately it has changed decisively. ISACA, the professional body that trains and certifies a large share of the world’s auditors, has effectively called time on the security questionnaire as a source of assurance. The regulators here have arrived at the same place from their own directions. APRA’s CPS 234 requires you to assess the information security capability of any third party that handles your data. CPS 230, fully in force since the middle of 2026, requires you to understand and manage the risk of your material service providers and to be able to demonstrate that resilience on a day the regulator chooses, not one you choose. The Security of Critical Infrastructure Act treats your supply chain as a hazard you must actively address in your risk management program. And AUSTRAC’s Tranche 2 reforms now push supply-chain and customer due diligence into a whole population of professional-services firms for the first time.
Read together, they say one thing. A critical supplier telling you they are fine is no longer proof that they are. Self-attestation, the questionnaire you send and the signed response you file, is no longer enough.
I think that is clear. Which is why the next part puzzles me.
In the conversations I have with the people who carry this risk, I am not seeing the behaviour change. The questionnaires still go out on the same cadence. The attestations still come back and get filed. The annual ritual runs as it always has, and the spreadsheet that records it is treated as the control. Everyone I speak to can tell me the rules have moved. Very few of them are doing anything differently because of it.
That gap is what I want to understand, and I have a couple of theories.
The first is that people do not actually know what to do instead. The regulators have been clear about what is no longer acceptable, and much quieter about what should replace it. If you strip out the questionnaire, the obvious question is “what do i replace it with?”, and the honest answer, assess your critical suppliers from real evidence rather than their own say-so, can sound like boiling the ocean. Faced with a vague and enormous-sounding task, it is very human to accept the status quo
The second is that nobody else has moved. Risk teams look sideways at least as much as they look up. If every peer organisation is still running questionnaires, then continuing to run questionnaires feels defensible, and being the one who does something different feels exposed. So everyone waits, quite rationally, for a first mover or a first enforcement action to make the change safe. The herd does not turn until something turns it.
There are other candidates. Perhaps the deadline still feels distant, or there has been no enforcement yet to concentrate minds, or the person who would own the change does not exist on a stretched team. But my two main suspects are those first two, and they point to very different fixes, which is exactly why I want to know which one it really is.
Because here is the part that does not depend on the reason. When the incident happens, or the audit lands, the reason you did not change will not help you. “Our supplier told us they were fine” is not a defence, and “everyone else was still doing it too” is not a control. The question you will be asked is what you knew, and could prove, about the supplier you chose to rely on. And the timing of that question is not set by your peers. It is set by the incident, or the regulator.
We don’t know what “good” looks like now
We’re waiting — nobody else has moved
It’s too hard — we don’t have the capacity
We’ve already changed
None of this means you have to boil the ocean. You do not need to assess every supplier from the outside overnight. You need to start with the handful whose failure would genuinely hurt, move from asking them to attest to seeing them from the outside on evidence, and turn it into a small, repeatable operation rather than a once-a-year ritual. That is a manageable first step, not a transformation program, and it is a great deal more defensible than another signed form.
So I will end where I started, with a genuine question rather than a lecture. I do not think the regulation is the confusing part any more. The behaviour is. If you carry this risk, tell me which it is for you, the not-knowing or the waiting, because the honest answer changes what actually helps. I have put it to a vote, and I would value yours.
References
- ISACA, guidance on third-party and vendor risk assessment, isaca.org
- APRA, Prudential Standard CPS 230 Operational Risk Management, and CPS 234 Information Security, apra.gov.au
- Cyber and Infrastructure Security Centre, Security of Critical Infrastructure Act and the CIRMP supply-chain hazard, cisc.gov.au
- AUSTRAC, AML/CTF reforms (Tranche 2), austrac.gov.au