At a glance
“Is access managed securely?” sounds reasonable until three teams answer it in three different ways. A useful assessment question tells the participant which process to describe and what evidence would support the answer.
- Ask about one observable outcome at a time.
- Name the application, population and period.
- Make it safe to report uncertainty or a partial process.
Begin with the decision the answer will support
Imagine a fictional company assessing temporary supplier access before expanding a support contract. The owner needs to know whether access ends when the work ends. Asking about all identity governance at once will produce a broad narrative. Asking how end dates are recorded and removal is checked gives the reviewer something specific to examine.
Write down the decision first, then draft the question. If you cannot explain how the answer will affect the assessment, the question may be unnecessary or need a clearer purpose. Long questionnaires can exhaust participants without improving coverage.
Separate requirements from operation
Ask whether a requirement exists, how it is implemented and what happened in selected cases. These are related but different questions. A participant can provide a policy even when the operating process has exceptions. A single yes-or-no response can hide that distinction.
| Instead of | Ask |
|---|---|
| Do you have access controls? | Who authorises supplier access to the finance application? |
| Are accounts removed promptly? | What triggers removal, and which record shows when it occurred? |
| Is the process compliant? | For the selected completed engagements, which records demonstrate the agreed removal requirement? |
Use familiar language before specialist terms. If “joiner, mover and leaver” is necessary, explain that it means people starting, changing roles and leaving. The participant should spend their time describing the process, not decoding the questionnaire.
Request enough evidence to test the answer
Tell participants which period and system matter. Ask for a suitable record or example rather than an unlimited document collection. If evidence cannot be provided, request an explanation and a route to resolve the uncertainty. Do not silently interpret missing evidence as either success or failure.
NIST SP 800-53A recognises examination, interviews and testing. A written response is one input; the appropriate combination depends on what the reviewer needs to establish. NIST SP 800-53A Rev. 5: Assessing Security and Privacy Controls.
For the supplier example, a request ticket may establish approval while an account log establishes removal. Keep those records connected to the same case. If they disagree, the question has uncovered something worth reviewing rather than something to edit away.
Review generated questions as working drafts
AssessX can combine knowledge-base questions with AI-generated questions for the selected campaign scope. Before launch, check whether the generated wording assumes a technology or process the organisation does not use. Remove duplicates and split questions that ask about several controls at once.
Try the draft with someone who understands the process but did not write the questionnaire. Ask them to explain what they think is being requested. If their interpretation differs from yours, improve the wording before sending it to everyone. Keep the corrected version for the next campaign.
References
Primary guidance used for the specific points cited above. The examples, templates and recommended working practices are AIdentX editorial guidance.
Sources reviewed September 2026.
Published by AIdentX Editorial. Illustrative scenarios are fictional and do not represent customer results.
