{"id":63,"date":"2026-08-24T01:28:22","date_gmt":"2026-08-24T01:28:22","guid":{"rendered":"https:\/\/bayrisk.com.au\/blog\/?p=63"},"modified":"2026-08-24T01:28:22","modified_gmt":"2026-08-24T01:28:22","slug":"isaca-just-retired-the-questionnaire","status":"publish","type":"post","link":"https:\/\/bayrisk.com.au\/blog\/2026\/08\/24\/isaca-just-retired-the-questionnaire\/","title":{"rendered":"ISACA just retired the questionnaire"},"content":{"rendered":"<body>\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>TL;DR.<\/strong> ISACA, the global professional body for governance, risk and assurance, has published a blueprint for modern third-party risk built on five shifts: a contextual risk model, continuous assurance, materiality by use case, evidence-backed scores, and replacing questionnaires with data-driven insight. Each one is something the questionnaire cannot do. Together they describe a different instrument entirely, and most programs cannot yet deliver them because their tooling is still built around the form.<br><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">For years, arguing that the security questionnaire was the wrong tool got you labelled a contrarian, or a vendor with something to sell. That argument is now over. ISACA, the global professional body for governance, risk and assurance, has published what amounts to a specification for third-party risk, and the questionnaire is nowhere in it. When the profession\u2019s own institution sets out the destination, the useful question stops being whether to move and becomes whether your program can actually get there.<br><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">From one opinion to a professional standard<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">ISACA\u2019s paper, \u201cMoving from Questionnaire Fatigue to Contextual Assurance,\u201d sets out five recommendations. Read individually, each is sensible. Read together, they describe an instrument that has almost nothing in common with the questionnaire that still sits at the centre of most programs. And ISACA is not alone in the direction it points. Gartner now treats annual questionnaires as below the standard for third-party risk, with continuous monitoring as the baseline, and KPMG\u2019s 2026 global survey finds that the organisations pulling ahead are the ones narrowing their attention to the small fraction of vendors that genuinely matter, rather than assessing everyone the same way. What was a fringe view a few years ago is now the consensus of the bodies that set the tone for the profession.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The five shifts, and what each one actually demands<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The value in ISACA\u2019s list is not that the ideas are new. It is that each one, taken seriously, quietly rules out the questionnaire.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>1: <\/strong>A contextual risk model means you stop asking how good a vendor is in the abstract and start asking what this vendor does for you and what that specifically could cost you. Context, in their terms, is data sensitivity, access level, operational dependency and regulatory impact. In practice it means you assess the engagement, not the company, and a generic form has nowhere to hold that.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>2:<\/strong> Continuous assurance means the position is re-derived as the evidence changes, so it is true today rather than merely true at the last review. Most programs mistake a monitoring feed for assurance. The feed is raw signal; assurance is the judgement laid on top of it, and a document signed once a year is neither.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>3:<\/strong> Materiality by use case carries an uncomfortable corollary. If you are meant to prioritise by how materially a vendor affects your operations, then most of your vendor list does not really matter, and assessing everyone equally is precisely how the few that do matter get lost in the noise. KPMG\u2019s finding, that only a small fraction of vendors pose a genuine threat, is the same point from the data side.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>4: <\/strong>Evidence-backed, explainable scores means a number you cannot defend is a liability rather than an asset. Explainable means you can show a board or a regulator the evidence and the reasoning behind a rating, not a figure transcribed from a form the vendor filled in about itself.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>5: <\/strong>And the last, in ISACA\u2019s own words, is to \u201creplace repetitive questionnaires with contextual, data-driven insights.\u201d The burden of the questionnaire is not a side complaint here. It is the tell. When a control costs both sides enormous effort and no one trusts the output, the control has already failed.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>The table below sets all five recommendations against what the questionnaire cannot do about each, and how we deliver it.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"577\" src=\"https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/08\/bayrisk-isaca-tracery-table-1-1024x577.png\" alt=\"\" class=\"wp-image-70\" loading=\"lazy\" srcset=\"https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/08\/bayrisk-isaca-tracery-table-1-1024x577.png 1024w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/08\/bayrisk-isaca-tracery-table-1-300x169.png 300w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/08\/bayrisk-isaca-tracery-table-1-767x432.png 767w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/08\/bayrisk-isaca-tracery-table-1-1536x865.png 1536w, https:\/\/bayrisk.com.au\/blog\/wp-content\/uploads\/2026\/08\/bayrisk-isaca-tracery-table-1-2048x1154.png 2048w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Why most programs cannot deliver this yet<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Here is the catch that the blueprint politely leaves unstated. Every one of the five shifts is hard to deliver with tooling built around the questionnaire, because the questionnaire is the opposite of all five at once. It is generic where you now need context, frozen where you need continuity, uniform where you need materiality, self-reported where you need evidence, and heavy where you need to be light. You cannot bolt context, continuity, materiality, evidence and low burden onto a survey and call it contextual assurance. You need a different instrument.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">That instrument resolves who a counterparty really is from independent evidence rather than its own account, scopes the assessment to what the supplier actually does for you, keeps the position live as the evidence moves, and follows the risk down the chain into the fourth party where a good deal of it now lives. That is what Enterprise Trust Management is, and it is why we built BayRisk around it rather than around a better survey.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"has-medium-font-size wp-block-paragraph\">You cannot bolt context, continuity, materiality, evidence and low burden onto a survey and call it contextual assurance. You need a different instrument.<\/p>\n<\/blockquote>\n\n\n\n<h2 class=\"wp-block-heading\">The regulators are pointing the same way<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">None of this is happening in isolation from the rules. APRA\u2019s CPS 230 asks whether a bank can keep operating when a material service provider fails, which is a question a filed questionnaire cannot answer. The Security of Critical Infrastructure obligations look straight through the front supplier to the supply-chain and personnel hazards behind it. And Australia\u2019s Tranche 2 anti-money-laundering reforms tell professional-services firms, for the first time, that they must be able to show they know who their clients and counterparties really are. The profession and the regulator have arrived at the same standard from different directions, and that standard is provable, contextual, continuous trust.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The blueprint is the easy part<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">The real service ISACA has done is to end the argument about direction. There is now a professional consensus, echoed by the analysts and reinforced by the regulators, on what good third-party risk looks like. The hard part was always going to be delivery, and delivery is where programs will separate. The ones that can show a board the five, on demand and from evidence, will be the ones that are trusted. The ones still administering forms will be busy, and quietly exposed.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">I argued recently that the questionnaire itself was finished. This is the constructive other half of that case: not just what is ending, but what the profession has now agreed should take its place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Q&amp;A<\/h2>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>What are ISACA\u2019s recommendations for modern third-party risk management?<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">In its 2026 paper \u201cMoving from Questionnaire Fatigue to Contextual Assurance,\u201d ISACA recommends five shifts: a contextual risk model weighted by data sensitivity, access, operational dependency and regulatory impact; continuous assurance rather than point-in-time review; prioritising vendors by how materially they are used rather than by size or certification; evidence-backed, explainable risk scores; and replacing repetitive questionnaires with contextual, data-driven insight.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>What is contextual assurance in third-party risk?<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Contextual assurance means assessing a supplier on what it actually does for you, its data access, operational dependency and regulatory impact, and continuously verifying that from independent evidence, rather than sending a generic questionnaire and trusting the answers. It replaces a one-size, point-in-time form with a live, evidence-led view scoped to the engagement.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>Why are security questionnaires being replaced?<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Because they capture self-reported answers at a single point in time, treat every vendor alike, and stop at the first supplier, missing materiality, change over time, and the fourth parties where much of the risk now sits. Bodies including ISACA and Gartner now regard annual questionnaires as below standard, with continuous, contextual assurance as the baseline.<\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\"><strong>How does this connect to CPS 230 and Tranche 2?<\/strong><\/p>\n\n\n\n<p class=\"has-medium-font-size wp-block-paragraph\">Both push in the same direction as ISACA. APRA\u2019s CPS 230 asks whether you can keep operating when a material service provider fails, which a filed questionnaire cannot answer, and Australia\u2019s Tranche 2 reforms require professional-services firms to know who their clients and counterparties really are. The common standard is provable, contextual, continuous trust.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Sources<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">ISACA, \u201cEnhancing Third-Party Risk Management: Moving from Questionnaire Fatigue to Contextual Assurance,\u201d Gaudam Suriyakala Thiyagarajan and Nivathan Athiganoor Somasundharam, 4 May 2026, <a href=\"https:\/\/www.isaca.org\/resources\/news-and-trends\/industry-news\/2026\/enhancing-third-party-risk-management-moving-from-questionnaire-fatigue-to-contextual-assurance\">https:\/\/www.isaca.org\/resources\/news-and-trends\/industry-news\/2026\/enhancing-third-party-risk-management-moving-from-questionnaire-fatigue-to-contextual-assurance<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Gartner, commentary on third-party and supply-chain risk as a leading cybersecurity trend for 2026, with continuous monitoring superseding annual questionnaires, <a href=\"https:\/\/www.gartner.com\">https:\/\/www.gartner.com<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">KPMG, Third Party Risk Management Outlook 2026 (shift to a focused, risk-based model concentrating on the vendors that genuinely matter), <a href=\"https:\/\/kpmg.com\">https:\/\/kpmg.com<\/a> <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">APRA, Prudential Standard CPS 230 Operational Risk Management, <a href=\"https:\/\/www.apra.gov.au\">https:\/\/www.apra.gov.au<\/a> Department of Home Affairs, Cyber and Infrastructure Security Centre, Security of Critical Infrastructure Act, <a href=\"https:\/\/www.cisc.gov.au\">https:\/\/www.cisc.gov.au<\/a><\/p>\n<\/body>","protected":false},"excerpt":{"rendered":"<p>TL;DR. ISACA, the global professional body for governance, risk and assurance, has published a blueprint for modern third-party risk built on five shifts: a contextual risk&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[14,1],"tags":[35,24,34,28,33],"class_list":["post-63","post","type-post","status-publish","format-standard","hentry","category-supply-chain-risk","category-uncategorized","tag-contextual-assurance","tag-cps-230","tag-isaca","tag-third-party-risk","tag-tprm"],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/63","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/comments?post=63"}],"version-history":[{"count":5,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/63\/revisions"}],"predecessor-version":[{"id":74,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/posts\/63\/revisions\/74"}],"wp:attachment":[{"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/media?parent=63"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/categories?post=63"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/bayrisk.com.au\/blog\/wp-json\/wp\/v2\/tags?post=63"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}