Start with exposure, not a generic questionnaire.
What the vendor handles, what it can reach and what depends on it set the tier. The tier sets which controls matter, and which questions this vendor is actually asked.

KnightGrid scopes the controls, matches the evidence and routes only what needs judgment to your team. Proven work is confirmed at sign-off, not re-read.
22 controls scopedControls backed by verified evidence clear without a line-by-line read. Your team’s time goes where judgement is needed.
What the vendor handles, what it can reach and what depends on it set the tier. The tier sets which controls matter, and which questions this vendor is actually asked.
A document is mapped once and reused for every control it proves. Evidence that is current and from the right legal entity moves settled work out of your way.
Work arrives sorted: pre-verified, light review, contradictions and escalations. No searching across files and answers.
A failed gate stays visible. If the business proceeds, a named senior manager owns a time-bound override, with conditions and an expiry date.
What security accepted, what it flagged and what it escalated arrive in the decision record as one attributable set. The approver signs against it; nothing is re-explained by email.
IndependentIndependentConfigurationTestedAttestation never silently becomes proof.
| Lane | Control | Reason |
|---|---|---|
| Escalation | Independent assurance | No certification; alternative evidence incomplete |
| Contradiction | Incident response | Plan date mismatch |
| Light review | Penetration testing | Confirm scope |
| Pre-verified | MFA enforcement | Confirmed at sign-off |