A vendor questionnaire is a photograph. It captures the vendor's stated security posture on the day it was completed, signed, and filed. The problem is that vendors do not stop changing once they hand you back a completed form.
This is not a criticism of questionnaires as a concept. For a lot of security decisions, a structured evidence request is exactly the right tool. But there is a category of vendor risk that questionnaires are architecturally incapable of capturing, and that gap is where real incidents tend to start.
What a Questionnaire Actually Measures
When you send a vendor a SOC 2 attestation request or an information security questionnaire, you are asking them to self-report their posture at a point in time. Some vendors answer in good faith with current information. Others reference documentation that is six months old. Some have a dedicated vendor management team that tracks these requests; others assign it to whoever has bandwidth this week.
Even in the best case, you are getting a reflection of the vendor's state on the day they filled out the form. If you run annual assessments, you might be acting on information that is 11 months stale by the time the next review cycle starts.
For vendors that do not change much, this works reasonably well. A vendor with stable ownership, consistent operational practices, and no major regulatory activity looks roughly the same from one year to the next. The questionnaire gap is acceptable because the risk gap is small.
But vendors do change. And the changes that matter most tend not to show up in next year's questionnaire.
The Categories Questionnaires Consistently Miss
Security advisories and unpatched vulnerabilities
When a major CVE is published against software a vendor runs, the vendor may not update their self-assessment for months. The advisory is public. The vendor's patch status may be visible through external scanning signals. But none of that appears in the questionnaire you completed last March.
Leadership and ownership changes
Acquisitions, private equity buyouts, and executive turnover affect how vendors treat security investment decisions. A vendor that operated with one security culture under previous ownership may behave differently after a change of control. Annual questionnaires ask about current controls; they rarely ask who owned this organization 90 days ago and why that changed.
Regulatory actions and enforcement
When a regulator publishes an enforcement action, a consent order, or a public reprimand against a vendor, that information is publicly available in regulatory databases. It typically does not appear in that vendor's next self-assessment. We have seen this pattern repeatedly: a vendor receives a formal regulatory notice, then completes a vendor questionnaire three months later with no mention of it.
Financial and operational stress
The relationship between financial distress and security investment is well-documented in risk management literature. Companies cutting expenses in response to cash flow pressure often reduce security headcount and defer infrastructure maintenance. Earnings calls, credit rating changes, and layoff announcements are all visible signals. Annual questionnaires do not ask about balance sheets.
Operational incidents in the public record
Outages, data exposure events, and infrastructure failures affecting a vendor's customers often appear in the public record before any formal breach notification. Customer posts in community forums, status page entries, news coverage, and regulatory filings can all surface an operational problem. By the time your questionnaire asks about this, the event may be a year old and partially resolved.
Why Continuous Monitoring Reads Different Signals
The signal types that matter most are largely external and public. Security advisory databases, regulatory enforcement databases, news sources covering the vendor's sector, financial press, and structured data about company events are all accessible without asking the vendor anything.
Continuous monitoring means checking these sources on a recurring basis, not once a year. When a high-severity CVE is published against infrastructure software a vendor uses, a monitoring system can flag it the same week. When a public regulatory action is filed against a vendor, it can surface within days. When a vendor's leadership team turns over in a three-month window, that pattern becomes visible.
This does not replace the vendor's own reporting. If your compliance framework requires a SOC 2 attestation or a completed HECVAT, you still need that. The point is that continuous monitoring answers different questions than questionnaires answer.
A questionnaire tells you: here is what the vendor says about their controls as of the date they signed this document.
Continuous monitoring tells you: here is what the external evidence says about this vendor's risk trajectory over time.
Both are useful. Only one of them updates between cycles.
A Scenario That Illustrates the Gap
Consider a SaaS workflow tool used by a regional insurance firm's operations team. The vendor had passed the firm's annual assessment. SOC 2 Type II report, completed security questionnaire, satisfactory responses on data handling.
Seven months into the assessment cycle, the vendor went through an acquisition by a private equity firm focused on operational cost reduction. Two months after that, a high-severity vulnerability was disclosed in the platform's authentication layer. The vendor issued a patch, but a subset of customers running on-premise deployments took longer to apply it.
None of this appeared in next year's questionnaire. The vendor completed it accurately: the vulnerability had been patched, the PE acquisition was disclosed. The firm's security team, doing its annual review, saw a vendor that had passed the prior year and had current documentation in hand.
A monitoring system watching public signals would have flagged the acquisition when it closed, flagged the CVE publication when it was disclosed, and potentially flagged the deployment lag if customer reports surfaced publicly. The security team would have had three separate prompts to look more closely at this vendor, at the time each event occurred rather than 11 months later.
This is not a hypothetical architecture. These signals are available in public data sources. The gap is in whether anyone is watching them continuously.
The Limit of What This Solves
We should be direct about what continuous monitoring does not do. It does not give you insight into the internal state of a vendor's security program that is not visible externally. It does not replace the assessment process for high-criticality vendors where you need evidence of specific controls. And it is not a substitute for contractual security requirements and right-to-audit provisions.
What it addresses is the time gap between assessments. Annual questionnaires are point-in-time by design, and that is appropriate for certain use cases. The issue is when organizations use them as their only signal about a vendor's current state, and then act surprised when an incident emerges from something that changed eight months ago.
What This Means for Your Program
If you are running an annual questionnaire cycle as your primary vendor monitoring mechanism, the question is not whether it is useful. It is. The question is whether you have any mechanism to catch what changes between cycles.
For most security teams, the honest answer is: not systematically. There might be a news alert set up for a major vendor's name, or a colleague who noticed a relevant story. But there is no structured process checking external signals for every vendor in the program on a regular schedule.
Adding that layer does not mean abandoning annual questionnaires. It means treating them as what they are: a point-in-time evidence collection mechanism, supplemented by continuous monitoring of the external signals that tell you how a vendor's risk profile is evolving right now.
The incident that happens in month seven of an annual cycle is not a failure of the questionnaire. It is a failure of the assumption that the questionnaire is enough on its own.