← Back to blog

Vendor trust without the email chase

Most vendor due diligence still lives in inboxes. Shared compliance passports and structured questionnaires cut the back-and-forth without lowering the bar.

July 15, 2026 · Nisium team · Product

If you have ever owned vendor risk for more than a quarter, you know the pattern. Someone needs a new SaaS tool. Procurement asks for “security docs.” You forward a questionnaire. The vendor replies with a PDF from 2023, a SOC 2 report that expires next month, and three follow-up emails asking what “evidence of access reviews” means in practice.

Two weeks later you still do not have a clean answer—and the business has already started using the tool.

Why email fails as a control

Email is fine for conversation. It is a poor system of record for compliance.

Threads fork. Attachments get outdated. Nobody knows which version is authoritative. When an auditor asks how you assessed a critical supplier last year, you are digging through folders named `vendor-security-final-v3-REALLY-FINAL`.

The deeper problem is repetition. Every customer asks roughly the same questions. Every vendor answers them from scratch for each request. That is wasted effort on both sides, and it does not produce better risk decisions—it produces slower ones.

What “good enough” looks like in practice

You do not need a fifty-page security novel from every vendor. You need a consistent picture:

  • Who they are and what services they provide to you
  • Which controls matter for *your* use of them (data processing, availability, incident notification)
  • Fresh enough evidence that you can defend the decision later
  • A way for the vendor to update answers without starting another email chain

That is where structured questionnaires and shared compliance artefacts help. A compliance passport—anonymized, verifiable metadata about a vendor’s posture—lets a customer confirm status without opening yet another ZIP of screenshots. Questionnaires still matter for specifics, but they should not be reinvented in Outlook every time.

Reduce chase, keep judgment

Automation should not replace judgment. A green badge does not mean “approve forever.” It means “we are not guessing from a stale PDF.”

Practical habits that work:

  1. Standardize the ask. Use one questionnaire shape for similar risk tiers. Custom questions are for exceptions, not the default.
  2. Prefer reusable artefacts. Ask for evidence that the vendor can maintain once and share many times—policy excerpts, control attestations, passport verification links.
  3. Set a refresh cadence. Annual for low risk, tighter for processors of personal data or services in your critical path.
  4. Record the decision. Who approved, on what basis, and when it expires. If that only lives in email, it will disappear when someone leaves.

For Bulgarian and EU operators

Under NIS2-style expectations, supply-chain and third-party risk is not optional theatre. Essential and important entities need to show they understand who they depend on. That does not mean treating every SaaS signup like a nuclear procurement—but it does mean being able to explain your process without reconstructing it from memory.

If your current process is “forward the last questionnaire and hope,” you are not alone. The fix is usually not more emails. It is a shared place for answers, evidence, and verification that both sides can reuse.

Less chase. Same bar. Better sleep before the next audit.