Sample output

What a finding actually looks like

The claim is that we cross-check what a vendor attests against what is actually exposed. This is that, in the format you would receive it. The vendor is invented, the structure is not.

This is a sample. "Northwind Analytics" is not a real company and the observations below are illustrative. No client data and no real third party appears on this page. The layout, the fields and the control mapping are exactly what a real finding carries.

Vendor

Northwind Analytics

High severity Open

Attestation expired while the contract continued

What the vendor claimed
In the security questionnaire returned on 14 March 2026, question 4.2 was answered: "We hold a current SOC 2 Type II report covering security and availability." A report cover page was attached.
What we observed
The attached report covers the period 1 January 2024 to 31 December 2024. No report has been provided for any period after that. The attestation was 6 months out of date on the day it was submitted, and is now 19 months out of date.
The delta
The answer says "current". The evidence says the coverage window closed 19 months ago. Nothing here suggests the vendor is insecure. It says that nobody, on either side, checked the date on the document being relied upon.
Framework control
ISO 27001:2022 Annex A 5.22, monitoring, review and change management of supplier services. Also SOC 2 CC9.2 (vendor risk assessment) and DORA Article 28(1) if the vendor supports a critical or important function.
Business impact
Northwind holds customer records under the current contract. If asked by a regulator or an insurer to evidence supplier assurance, the most recent independent evidence available is from a period that ended 19 months ago. That is the exposure, not a technical vulnerability.
Recommended action
Request the current SOC 2 Type II report and the bridge letter covering the gap. If neither exists, record a dated exception with an owner and a review date rather than leaving the questionnaire answer standing. Add an automatic check on the report period end date so this is caught on the day it lapses rather than at the next annual review.
How this was found
Automatically. The attestation period end date is extracted from the uploaded document and compared against today on a schedule. No human re-read the questionnaire.
Finding ID PS-SAMPLE-0001 First seen 26 July 2026 Source: vendor document + scheduled re-check

Why this shape

Every field exists because a buyer asked for it. "What did they claim" and "what did we observe" are separated so the finding cannot be waved away as opinion. The control mapping is there so it can be dropped into an audit pack without translation. The recommended action names the exception route as well as the fix, because sometimes accepting a risk is the right call and it still needs recording.

The point about timing

This finding is dull. That is deliberate. The failure it describes is not a breach or a clever attack, it is a date nobody looked at. Point-in-time assessment cannot catch it, because on the day of the assessment the questionnaire said "current" and the box was ticked. Only re-checking on a schedule catches the day the answer stops being true.

See the full report format

The sample report shows how findings like this are assembled into something you can hand to a board or an auditor.

View the sample report