Somewhere in your organisation this morning, a spreadsheet is on its way to a supplier who will spend the better part of a week answering three hundred questions about controls no one on your side will ever verify, and who will send back a document you will file and never open, describing a security posture that was true, if it was ever true, only on the single morning it was signed. This is the ritual at the centre of third-party risk management, and the quiet thing the whole industry has agreed not to say out loud is that almost nobody, on either side of the exchange, believes it works. The security questionnaire is dead. We have simply not stopped sending it.
It was always the wrong instrument
Strip away the volume and the platforms and the maturity scores, and a questionnaire is only ever one thing, which is a record of what a supplier is willing to say about itself, on a day of its own choosing, in an exercise everyone in the room understands to be a performance. It is self-attestation wearing the costume of assurance. We would never accept a vendor’s own word that their product works, we insist on testing it, and yet at the most consequential layer of all, whether we can trust the organisation holding our data or building on our site, we have been content to accept that same organisation’s own report card. Nobody fails their own interview, and a questionnaire is an interview that the candidate is left to mark
A photograph of a moving target
Even taken at its very best, a completed questionnaire captures a single moment, and risk does not hold still for the photograph. Ownership changes, key people leave, a control quietly lapses, a subcontractor is brought on without ceremony, and none of it announces itself back to the form sitting in your register. By the time the assessment is reviewed, signed and filed, it already describes a company that no longer exists in quite the same shape, and you then carry that stale picture forward for a year, or until the next annual cycle comes round to take a fresh one that will be out of date every bit as fast.
It assesses the whole supplier, not the part that can hurt you
The questionnaire also insists on treating every supplier as one undifferentiated thing, so you find yourself scoring a consultancy’s public website and its mail configuration when the actual engagement is two advisers with laptops who will never touch your environment, and you spend the same effort, and ask the same three hundred questions, of the vendor that runs a critical piece of your operation as the one that changes the plants in reception. What determines how much a supplier can actually hurt you is context, the specific job they do for you and the part of their business you are exposed to through it, and that is exactly what a one-size questionnaire has no way to capture. So the signal that matters gets buried under the noise of everything that does not, and the assessment manages to grow longer and less useful at the same time.
The risk was never at the third party, it sits four parties deep
Here is the part the document cannot reach at all. Your supplier is not a single entity, it is the visible front of a chain, and the failure that reaches you rarely comes from the name on your contract. It comes from the company that name subcontracted to, and the company that one subcontracted to in turn. A construction project makes this vivid, because you engage a firm that mostly project-manages, it brings on four trades, one of those trades hands part of the work to a fourth party you have never heard of, and it is that fourth party, whose basic mail security was never in place, that quietly gives an attacker the way in. You assessed the network of the vendor you could see, while the exposure was living three companies deeper, inside a business that never filled in one of your forms and never would. A questionnaire has no line of sight past the first signature, and the risk moved past it long ago. This is why the numbers keep getting worse rather than better, and why Verizon’s 2025 Data Breach Investigations Report found that third-party involvement in breaches doubled in a single year, to thirty percent of all breaches. A document that stops at the first party was never going to hold that line.
You assessed the vendor you could see. The exposure was living three companies deeper, inside a business that never filled in one of your forms and never would.
Both sides are exhausted by a document neither side trusts
None of this comes free. Your team spends its weeks chasing forms, extracting them, chasing them again, and then reading answers it has no way to check, while on the other side the supplier’s team fills in hundreds of near-identical questionnaires a year, each one worded slightly differently, none of them believed, all of them a tax on people who were already stretched thin. It is an enormous, industry-wide expenditure of effort that produces almost no assurance, and everyone involved knows it, which is perhaps the strangest feature of the whole arrangement, a ritual carried on long after its participants stopped believing in it, kept alive only because nobody had put anything better in its place.
And now the standard has quietly changed
For a long time you could keep sending the forms because sending the forms was the expectation, and that is the part that has now moved underneath everyone. In financial services, APRA’s CPS 230 does not ask whether you assessed your material service providers, it asks whether you can keep operating when one of them fails, and that is a question a filed questionnaire simply cannot answer. In critical infrastructure, and in the construction and property firms that build and run so much of it, the enhanced obligations under the Security of Critical Infrastructure Act look straight through the front supplier to the supply-chain and personnel hazards sitting behind it, to who really owns and controls a counterparty, and to the people actually on site, all the more so where defence and government work is involved. Across both worlds the bar has shifted from did you assess to can you prove, from a form returned to evidence produced on demand, and the questionnaire has nothing to offer the second question. It answers a test that is no longer being set.
What comes after the form
If the questionnaire is dead, the thing that replaces it is not a better questionnaire, it is a different instrument altogether. It starts from independent evidence rather than the supplier’s own account, so what you hold has been verified rather than volunteered. It is scoped to what a given supplier actually does for you, so a low-stakes relationship is not assessed as though it were a critical one, and the critical one finally gets the depth it deserves. It is continuous rather than annual, a live position that is re-derived as the evidence changes rather than a snapshot that was stale on arrival. And it follows the risk down the chain, into the fourth party and the fifth, because that is where the risk has been living the whole time. This is the discipline now emerging to replace third-party risk management, and the reason it is emerging is not fashion, it is that the old instrument stopped measuring the thing that matters and the world stopped accepting the pretence that it did.
The questionnaire is not dying because it is old
It is worth being clear about why the questionnaire is finished, because it is not simply that it has dated. It is that it never really worked, and the cost of pretending otherwise has finally come due, in the regulation, in a supply chain that grew deeper and more global than any form could ever follow, and in the losses that keep arriving through a back door while the front-door paperwork sits neatly filed. The organisations that will be trusted from here are the ones that can prove they are trustworthy, on demand, from evidence, across the whole chain and not merely the first name on it. Everyone else will still be sending spreadsheets, and quietly hoping that the company three links down the chain, the one they have never assessed and never will, has its mail security in order. At BayRisk we would rather help you prove your position than help you file another form, which is the whole reason we operate the way we do, and it is why the questionnaire, as far as we are concerned, can now rest in peace.
Sources
- Verizon, 2025 Data Breach Investigations Report (third-party involvement in breaches doubled year on year, to 30% of all breaches, up from about 15%), https://www.verizon.com/business/resources/reports/dbir/
- APRA, Prudential Standard CPS 230 Operational Risk Management (management of material service providers and operational resilience; commenced 1 July 2025, with material service provider obligations and targeted amendments taking full effect 1 July 2026), https://www.apra.gov.au
- Department of Home Affairs, Cyber and Infrastructure Security Centre, Security of Critical Infrastructure Act and the enhanced Critical Infrastructure Risk Management Program Rules (supply-chain and personnel hazards, and foreign ownership, control and influence, 2026), https://www.cisc.gov.au