Essay · Published · 16 min read
Trust should be a shared fact
Why security questionnaires shouldn't exist.
Somewhere today, a security engineer is answering the question "Do you encrypt data at rest?" for the two-hundredth time. Not because the answer changed (it has been "yes, AES-256, keys in a managed KMS" for six years) but because a new buyer asked. The answer exists in their SOC 2 report. It exists in the last hundred and ninety-nine spreadsheets. It will be typed again anyway, in this buyer's phrasing, in this buyer's portal, under this buyer's deadline. And when it is submitted, it will be read once, scored, and filed against the day something goes wrong.
Multiply this by every question on the questionnaire, every questionnaire in the pipeline, every vendor in the industry, and you get one of the strangest institutions in modern software: an enormous apparatus for restating facts that everyone involved already agrees are established.
The standard response to this absurdity is to make the restating faster. Ours is that the restating shouldn't happen at all.
01
Facts with no home
A security questionnaire is a bilateral, ephemeral exchange. The buyer asks in their own dialect. The answers land in their portal, or a spreadsheet, and stop mattering until a dispute resurrects them. Vendors, for their part, keep answer libraries (the copy-paste corpus is a decade-old industry), but that accumulation is private and one-sided. It makes the typing cheaper. It does not make the two-hundredth review any shorter, because nothing the vendor accumulates carries weight on the buyer's side of the table. Between the parties, nothing accumulates at all.
Compare this to the other facts businesses exchange. Prices have catalogs. Identity has certificates. Ownership has registries. In each case, somebody eventually noticed that a fact being re-established bilaterally, over and over, was really a missing piece of infrastructure, and built the shared representation that made the re-establishing unnecessary.
Trust facts like we encrypt at rest, we run background checks, and our subprocessors are X, Y, and Z never got that treatment. They have no canonical representation, no address, no protocol. So every buyer builds a private one, and every vendor answers all of them.
Seen this way, the questionnaire is not how buyers evaluate vendors. It is how buyers cope with the absence of anything to evaluate against. It is a protocol failure wearing the costume of diligence.
It's worth being precise about what the questionnaire gets right, because any replacement has to preserve it. A completed questionnaire encodes two legitimate things. First, a point-in-time attestation: you told us this, on this date. Second, accountability: someone signed their name to it. These are real. A vendor's answers get referenced in contracts, disputes, and audits, and the ugly spreadsheet is surprisingly legible to the lawyers who do the referencing. Whatever replaces the questionnaire must be at least as durable as the thing it replaces, not merely more informative.
So the argument here is not against attestation. It is against re-derivation. Those have been bundled together for so long that they look like one activity. They aren't.
02
Reality is smaller than the questionnaire space
Here is the observation the whole argument rests on: strip away the phrasing, and security questionnaires mostly ask the same things. There are a thousand ways to ask whether a vendor encrypts data, rotates keys, enforces MFA, screens employees, or reviews access. The underlying reality being asked about is much smaller.
It is not that every question maps neatly onto some master list. The long tail of buyer-specific questions is real, and it often encodes real, buyer-specific risk. The claim is that most questions can be evaluated as compositions over a much smaller set of underlying facts. A gnarly question like "do administrative sessions originating outside approved jurisdictions require device-bound, phishing-resistant MFA?" doesn't correspond to one fact. It composes four or five. Questions proliferate combinatorially; reality stays compact.
Anyone who has worked with a database will recognize this shape. There are infinitely many queries you can run against a finite schema, and no sane system responds by materializing every query result and maintaining each one by hand. You store the state, and you compute the answers.
The security questionnaire industry does the opposite. A questionnaire is a query. The vendor's actual posture is the state. And current practice is to materialize every query result, every buyer's phrasing of every question, as its own hand-maintained artifact, stored in someone else's portal, going stale at its own rate.
There is a second compression hiding underneath. Many trust facts aren't solely about the vendor at all. "Do you encrypt data at rest?" asked of a company running on a major cloud provider is substantially a question about that provider. Not entirely, though, and the difference is exactly where the vendor's real responsibility lives. The provider supplies the capability; the vendor determines whether it's enabled, who controls the keys, and what the exceptions are. The honest structure is composition: a platform fact (this database service supports AES-256 encryption at rest via managed keys) plus a vendor declaration (our production instances have it enabled, under keys we control) yields a derived vendor fact (our production data is encrypted at rest). The vendor's marginal contribution is the declaration: small, specific, and ownable, not a re-derivation of the entire answer.
None of this means facts are simple. A fact carries its scope, and scope is where careful reviewers earn their pay: "we encrypt at rest" is not a fact until it says which systems. Production only? Backups? Laptops? The logging pipeline? Scope expands the state space. It does not change its character: scopes are finite, enumerable, and stable in a way that buyer phrasings are not.
Follow the decomposition to the end and trust facts sort into three kinds. Some are inherited: facts about your platforms, composed with a declaration of how you use them. Some are evidenced: facts already established by an attestation you hold, like a SOC 2 audit. And some are asserted: genuinely specific to your company, with no source but a person willing to own the claim.
The asserted residue, the only part that ever deserved a human's attention, is small. It is also the part that gets the least attention today, because the humans are busy re-answering the derivable majority.
03
The trap of "faster"
The obvious response to all this is AI. If the answers are derivable, have a model derive them. Parse the SOC 2, embed the policies, match the questions, fill the spreadsheet. This is where the industry is currently sprinting.
We build this. It works. And as an endgame, it is a trap.
Consider the equilibrium. Questionnaires are cheap to send and expensive to answer; that asymmetry is the main thing restraining their volume. Make them cheap to answer and the volume adjusts. Buyers send longer questionnaires, more often, to more vendors. Why not? Vendors auto-answer. Buyers, drowning in auto-answers, deploy AI to evaluate them. The terminal state is language models exchanging spreadsheets with language models, burning tokens to move zero new information, while the humans on both sides supervise a transaction that informs neither of them. Everyone is faster. Nobody knows anything they didn't know before.
There is a second casualty. The cost of answering used to carry information of its own: a vendor producing prompt, competent, internally consistent answers was demonstrating a real security program, and experienced reviewers read sloppy questionnaires as the diagnostic they were. Generated fluency is free now. Whatever signal survives will not be polish. It will be substance: how much evidence a vendor can attach, and how little of their story has to be taken on faith.
The tell that speed was never the real problem: answering was already mostly copy-paste before AI arrived. The waste isn't in the typing. The waste is a protocol that demands the same fact be re-serialized, one buyer dialect at a time, forever. Automation that merely accelerates the re-serialization doesn't fix that protocol. It entrenches it.
Which raises a fair question: if a shared representation is the fix, why didn't someone build it ten years ago?
Because until recently, it was economically impossible to bootstrap. A canonical layer is only useful if arbitrary buyer language can be mapped onto it, and for decades that mapping had to be built by hand, buyer by buyer, form by form. There is an entire crosswalk subindustry that grinds at exactly this. Hand-built semantic normalization doesn't scale, which is why the industry's best attempt at the problem was standardizing the questions instead. More on that failure below.
That is the thing large language models actually changed. Mapping "describe cryptographic protections applied to persisted customer information" onto a canonical encryption-at-rest fact is now cheap, reliable enough to propose, and, crucially, cheap to do with provenance attached and a human in the approval loop. AI makes the shared layer bootstrappable.
That is a different claim than "AI is the layer." The model is the migration technology: the thing that gets the world's existing questionnaire traffic translated into and out of a canonical representation. The goal was never to answer questions faster. The goal is to make asking unnecessary, the way a browser doesn't interview a website about its identity before connecting. A shared system settles it before the page loads.
04
What a shared fact is
"Shared fact" invites an immediate and correct suspicion: says who? So, concretely: four properties, each of which exists because someone will object.
A shared fact is canonical: one representation per fact, rather than one per buyer dialect. Buyer formats don't disappear; they become projections, views computed over the canonical state. The old world keeps working while the new one takes root.
A shared fact is a claim, not a decree. No system gets to declare "this vendor encrypts customer backups" as ambient truth, and nothing here tries. What the representation holds is the claim plus everything you'd need to decide whether to believe it: the evidence behind it, the named person who approved it, when it was observed, which version you're looking at, and when it expires. A shared fact is a portable, inspectable claim, which makes it more auditable than a questionnaire answer, not less. A spreadsheet cell says "yes." A fact says "yes, and here is why you should believe me, signed."
A shared fact is governed: it has an owner, an approval trail, and a version history. This is where the questionnaire's legitimate cargo, attestation and accountability, survives the transition. And because compositions are themselves claims (every input true, the combination still false, is exactly how misrepresentation prefers to travel), the governance extends to them: the rule that composes four facts into an answer must be versioned, inspectable, and governed too.
Finally, a shared fact is living, without forgetting. Facts carry staleness and expiry: when a fact is corrected, or the evidence beneath it changes, everything derived from it is known-stale instantly, and a claim nobody has re-affirmed by its review date degrades visibly instead of silently. A ledger can still be wrong (no representation fixes an unreported change), but it can never be silently old, which is the spreadsheet's permanent condition. And buyers don't only need current state. They also need history: what did you represent to us on the day we signed? So the representation has two temporal modes: the living, governed current claim, and the immutable snapshot frozen at transaction time, approved and contract-referenceable. Today's spreadsheet gives you only the second, badly. A versioned fact with snapshots gives you both.
Put those properties together and the endgame names itself. Once trust facts are shared, provenanced, and governed, asking again is revealed as what it always was: a cache miss. Some cache misses are legitimate: a genuinely novel question deserves a genuinely fresh answer. The rest are protocol overhead. The goal is to drive the trust-review cache-hit rate toward one hundred percent, a measurable number, not a manifesto.
05
Why hasn't this happened already?
The industry has tried to fix questionnaires before, and the attempts are instructive.
SIG, CAIQ, and their relatives standardized the question sets, and the effort taught a lesson worth taking seriously: they standardized the syntax and left the state untouched. A standard way of asking, with no shared answer layer underneath, is just one more questionnaire in the pile. Empirically, buyers who adopt the standard forms still append their custom tabs. Questionnaires are messages. Trust facts are records. A standard message format is still a message.
SOC 2 got closer, and its lesson is sharper. SOC 2 solved the attestation problem far better than it solved the information-reuse problem. A real auditor really examines real controls, and real accountability attaches to the result. Then the whole thing ships as prose in a PDF: facts you can read but cannot reference, query, or compose. This is much of why buyers who hold your SOC 2 report still send a questionnaire about its contents. Not all of it (scoping games, carve-outs, and the trailing audit window do their share), but the structural part: buyers hold trustworthy information in a form they cannot compute over, so they ask you to re-interpret it into their schema, by hand, again.
Look further and the pieces of the alternative have each been built somewhere. NIST's OSCAL is a genuinely canonical, machine-readable representation of controls and assessments: a state format, waiting for traffic. FedRAMP is a working assess-once-reuse-many trust layer at government scale: agencies share the assessment and still issue their own authorizations. It also shows the price of arriving by committee: a decade of grind and six-figure onboarding. HITRUST has shipped control inheritance from cloud providers for years: inherited facts, in production. And the current generation of vendor trust centers puts polished security profiles in front of buyers, who glance and send the questionnaire anyway, not because the pages are empty (many gate real audit reports and live control checks) but because they are exhibits: nothing in them is addressable, composable, or referenceable from a contract. You can look. You cannot build on what you saw.
Each solved a piece. None became the place trust lives. The missing ingredient was never the format, and it was never the will. It was a way to get the world's existing questionnaire traffic flowing through a canonical layer without first asking anyone's permission, which the economics of semantic mapping only recently made possible.
06
How it arrives
Not by committee, then. No buyer consortium, no standards body, no flag day. Proposals shaped like "everyone agree on the new thing first" die in exactly the procurement departments they need to convince. It arrives in three stages, and the first one is invisible.
Vendors adopt a canonical profile for selfish reasons: it answers today's questionnaires with less effort, in whatever format each buyer demands. The buyer receives the spreadsheet they asked for and changes nothing. Every questionnaire answered this way enriches the profile that answered it.
In the second stage, the profile starts leaking through the projection: as evidence. Answers arrive carrying durable references: this answer derives from this fact, in this snapshot, approved by this person on this date. This, not answering speed, is the step today's answering tools skip: their answers arrive stripped of references, so the leak into the buyer's workflow never starts. Nothing about the buyer's process changes, and no discretion is asked of anyone, which matters, because the person processing the response is often not a senior reviewer with latitude but an analyst executing a playbook in a GRC platform. References don't ask the playbook to bend. They make it cheaper to run: answers that arrive holding their own evidence clear checks faster and spawn fewer follow-up cycles. Demand builds on the buyer side one processed questionnaire at a time, without a single policy decision being made.
In the third stage, some buyer says the quiet part: just send the snapshot. This one, finally, is a real adoption decision: a policy revision, a tooling integration, in regulated industries perhaps a conversation with an examiner. A meaningful share of questionnaire volume is regulator-compelled diligence, and examiners move at examiner speed. But notice what kind of decision it is: a ratification of value already demonstrated, made last. Not a leap of faith demanded first.
One thing never happens in this sequence: nobody asks the buyer to think in the canonical schema. A buyer with 311 internal controls keeps their 311 controls; the layer's job is to show, with evidence attached, that 287 are satisfied, 17 need review, and 7 lack evidence. The buyer keeps their ontology. They only have to trust the projection. Abstraction layers that win tend to win exactly this way: nobody adopts them, everybody just stops working around their absence.
The questionnaire, in other words, is the distribution channel for the thing that replaces it.
07
Objections
"Provenance isn't verification." Correct, and the model doesn't pretend otherwise. A self-attested claim with an owner, a timestamp, and a version is still a self-attested claim; no amount of metadata upgrades say-so into audit. What the representation changes is that you can finally see which kind of claim you are holding. An inherited fact resolves against a platform's own attestations. An evidenced fact carries the auditor's work with it. An asserted fact is exactly what a questionnaire answer always was: someone's word, minus the disguise. Today all three arrive flattened into the same spreadsheet cell, indistinguishable. And once claims are addressable, assurance can attach to them piecemeal: a third party can verify the facts that matter most, fact by fact, instead of prose report by prose report. The layer doesn't make claims true. It makes the trust calculus legible.
"This is the fifteenth competing standard." In one sense, guilty: a canonical representation is a new format, and this space is a graveyard of new formats. But that failure has a specific mechanism, and it is worth being precise about it. Standards die this way when they are useless until everyone agrees to use them, so each new entrant only lengthens the menu. This layer is useful to a single vendor on day one, answering the questionnaires that already exist, in the formats buyers already demand. No buyer is asked to read it, no consortium is asked to bless it, and the existing dialects are translated rather than replaced. A standard that needs collective adoption before it produces value is asking the industry for an act of faith it has rightly stopped extending. A representation that pays for itself unilaterally is not entered in that contest. It accumulates underneath the formats we already have until it either earns the name infrastructure or fails quietly, without having asked anyone for anything.
"You're just building another silo." The failure mode is real: a trust profile readable only through one vendor's tooling is a portal, not a protocol, and the industry has enough portals. The answer has to be built in rather than promised: complete export, stable identifiers, documented structure, machine-readable provenance: trust facts that remain portable and addressable outside the system that created them. A layer that takes data hostage has reproduced the original problem one level down.
"You're trying to standardize everyone's risk appetite." No. Two reasonable buyers can read identical facts and reach different conclusions; one considers a control satisfied, the other calls it partial. That is not an inconsistency to engineer away. Questionnaires conflate two questions: what is true about this vendor? and is that good enough for our policy? The first should be reusable state. The second is legitimately buyer-specific judgment, and it stays that way. The facts can be shared even when the risk judgment isn't. What ends is not disagreement; what ends is every buyer independently re-deriving the reality before applying their own appetite to it.
"Security review is partly theater, and the theater has a function." It does. The questionnaire also exists so a security team can show their work: to auditors, to executives, to regulators. A signed, versioned, evidenced profile gives them better work to show. The theater survives; the props improve.
"The questionnaire is really a liability instrument." It is. A completed questionnaire is a representation the vendor can be held to, in the buyer's own words, and legal departments will keep the spreadsheet for that reason alone unless the replacement holds up in the same court. Two things have to be true. The artifact must be at least as durable. That is the immutable snapshot, and a snapshot with named approvers, attached evidence, and tamper-evident history is a stronger instrument to hold someone to than a spreadsheet. And someone must stand behind the projection, because "we attested to the fact; your rendering mistranslated it" is a defense no buyer will accept twice. So the projection is what gets signed: the vendor approves the answers as rendered, in the buyer's format and phrasing, exactly as they approve a spreadsheet today. The platform composes; the vendor represents. And because the platform composes, the portability commitments above apply to it doubly, since a composer you cannot leave is a silo with extra steps. The liability chain isn't dissolved. It's upgraded.
08
The world after
What does diligence look like when trust is a shared fact? A buyer opens a vendor's profile and sees not a spreadsheet but a ledger: each fact with its source, its evidence, its owner, its history. The derivable majority arrives already assembled, each answer holding the reasons to believe it, and the reviewer's work begins at judgment instead of archaeology. Attention goes where it always should have gone: the handful of facts genuinely specific to this vendor, this deal, this data. Review collapses from weeks of correspondence to minutes of exceptions.
The security questionnaire won't be abolished. It will linger the way fax machines linger: a compatibility surface for the last holdouts, generated automatically, resented by no one, because no human writes it anymore; a signature is all that remains of the labor. Trust, meanwhile, gets what prices, identity, and ownership got long ago: a shared representation, so that establishing it once means never re-deriving it again.
The questionnaire doesn't have to die for any of this. It just has to stop being where trust lives.