Vendor Control Drift
Assessed Two Years Ago. Sixty Percent Security Turnover Since. Drifting.
6 min read · 19 June 2026 · Compliance
A logistics technology company's assessment of a data analytics vendor two years prior had found a satisfactory security programme , a CISO with fifteen years of experience, a security team of twelve, a recently completed SOC 2 Type II audit, and a security governance structure that included monthly steering committee reviews. The annual questionnaire sent eight months after the assessment had confirmed no material changes to the security programme. The questionnaire sent sixteen months after had also confirmed no material changes. What the questionnaires had not captured: the founding CISO had departed thirteen months prior, replaced by an interim security director from a different industry who was still building relationships with the engineering team. Seven of the twelve security team members had left over the same period, with five positions currently unfilled. The security tooling budget had been reduced as part of a company-wide cost reduction initiative, resulting in the decommission of two security monitoring tools. The monthly security steering committee had met twice in the last six months , the remaining meetings had been cancelled due to competing priorities. The SOC 2 audit was due in four months and the security team was concerned about readiness. The vendor's questionnaire responses had consistently confirmed 'no material changes to the security programme.' The security programme that existed today was materially different from the security programme that had been assessed two years prior.
What is Vendor Control Drift, Really?
Control drift is the gradual degradation of a vendor's security programme between formal assessment events , the progressive erosion of security posture through personnel turnover, budget reduction, governance attrition, and tool decommission that individually may not meet the threshold for 'material programme change' but collectively represent a significantly weaker security posture than the one that was assessed. Control drift is the opposite of intentional change , it is the passive deterioration that occurs when the active maintenance required to sustain a security programme at its assessed quality is reduced without a deliberate decision to do so.
Security programme maintenance is a continuous investment, not a one-time achievement. A strong security programme at assessment reflects the personnel, tools, governance processes, and organisational attention that were invested in it at that time. Maintaining that strength requires continuous investment , retaining experienced security staff, maintaining security tool subscriptions, sustaining governance cadences, and allocating budget to security improvements. When any of these maintenance investments is reduced , through staff departures not replaced, budget cuts, or governance schedule attrition , the security programme begins to drift from the assessed posture.
The below-threshold accumulation problem makes control drift particularly difficult to detect through questionnaire-based assessment. Annual questionnaires that ask about material programme changes capture single-event degradations , the CISO who left with no replacement, the major security tool that was decommissioned, the security governance function that was formally eliminated. They are less effective at detecting the accumulation of smaller, individually-below-threshold changes that together constitute significant drift , the pattern of gradual erosion that the hook scenario describes.
- Staff turnover not triggering assessment , key security staff departures not flagged as material programme changes
- Budget reduction not surfaced , security budget cuts not disclosed in questionnaire responses
- Governance attrition , security governance meetings not occurring as described in programme documentation
- Tool decommission below detection threshold , individual tool decommissions not meeting material change criteria
- Cumulative drift invisible to questionnaires , individually below-threshold changes accumulating to significant degradation
Why this matters
Control drift matters for TPRM because the security programme quality that justified a vendor's risk rating may no longer accurately describe the vendor's current posture two years into the relationship. A vendor rated satisfactory based on an assessment of a specific security team, specific tools, and specific governance processes presents a different risk when two-thirds of the security team has departed, the tools have been reduced, and the governance processes have become irregular. The rating reflects the assessed posture. The current risk is in the drifted posture.
The security incident timing problem is the most direct operational consequence of undetected drift. Many security incidents at vendors occur in the context of degraded security postures , the understaffed security team that could not keep up with vulnerability patching, the decommissioned monitoring tool that would have detected the anomalous access, the cancelled governance meeting where the access review would have been reviewed. Control drift creates the conditions under which security incidents are more likely. Detecting drift before it produces an incident is the governance objective that continuous monitoring and signal-based reassessment attempt to achieve.
Where most teams get this wrong
The most consistent failure is designing questionnaire change questions that capture single material events rather than the accumulation of smaller changes that together represent drift. Questionnaires that ask 'have there been any material changes to your security programme' will miss control drift consistently , because individually below-threshold changes do not produce 'yes' answers to that question.
- Questionnaire change questions not detecting cumulative drift
- No drift-specific signals , personnel, budget, and governance attrition not monitored
- Security staff turnover not tracked as a risk signal
- No continuous monitoring to detect governance and tool attrition
- Annual questionnaire cadence too slow to detect drift in progress
What good looks like
Mature control drift detection programmes combine annual questionnaires with continuous signals that specifically detect drift indicators , security staff turnover rates, security budget changes, governance meeting cadence, and external security rating trends , and trigger reassessment when drift signals reach defined thresholds.
- Drift-specific questionnaire questions , staff turnover rate, vacant security positions, budget changes, governance meeting frequency
- Continuous external rating monitoring , rating decline as a proxy for programme degradation
- Security staff turnover signal , key security leadership departure triggering targeted assessment
- Governance attrition monitoring , vendor security governance meeting cadence as a drift indicator
- Triggered reassessment for drift signals , defined signal thresholds initiating targeted assessment before the next scheduled review
Tooling
Continuous Security Ratings , BitSight, SecurityScorecard
Security rating platforms provide a continuous proxy for programme health , rating declines reflect the observable consequences of control drift (increased vulnerabilities, slower patching, configuration degradation) even when the underlying causes are not directly observable. For TPRM practitioners, monitoring continuous security ratings for drift-indicative decline patterns provides an external signal that questionnaires cannot generate.
Vendor Intelligence , Interos, LinkedIn monitoring
Vendor intelligence platforms that monitor leadership and key staff changes provide the personnel drift signal that external security ratings do not capture. CISO and senior security team departures are publicly observable events that signal potential programme disruption. For TPRM practitioners, monitoring key security leadership changes as a drift trigger provides an early warning before the consequences are visible in external rating data.
Governance challenges
The governance challenge with control drift is the indirectness of available signals. The most important drift indicators , security budget reductions, governance attrition, and tool decommissions , are internal vendor information that is not observable externally. External signals , security rating changes, key staff departures , are observable but are lagging indicators that reflect drift consequences rather than drift causes. The governance resolution is combining available external signals with drift-specific questionnaire questions that ask directly about the indicators rather than about material programme changes.
- Add drift-specific questions to annual questionnaire , staff vacancy rate, security governance meeting frequency, budget changes
- Monitor key security leadership departures as a drift signal
- Use continuous security ratings as a programme health proxy
- Define drift signal thresholds that trigger targeted assessment
- Ask specifically about SOC 2 or ISO 27001 audit readiness , readiness concern is a drift indicator
If you are a small team
Add four questions to your next annual questionnaire that specifically ask about drift indicators rather than material programme changes. First: what is the current security team headcount compared to twelve months ago, and how many positions are currently vacant? Second: has the security budget changed relative to last year? Third: how frequently has the security governance committee or equivalent body met in the last six months? Fourth: is the organisation on track for its next SOC 2 or ISO 27001 certification? Those four questions will surface the drift that the material change question misses.
- Add security headcount and vacancy question to annual questionnaire
- Add security budget change question
- Add security governance meeting frequency question
- Add audit readiness question as drift indicator
What to require
Ask directly:
"Since our last assessment, what is the current security team headcount compared to that time, how many security positions are currently vacant, and have there been any changes to the security budget or governance structure that have affected the programme's operational capacity?"
Expect as evidence
- Security team headcount comparison to last assessment
- Current vacancy count
- Security budget change disclosure
- Governance meeting frequency in the last six months
A vendor who confirms no material programme changes should be asked the four drift-specific questions. The individual answers may each be below the material change threshold. The combined picture may describe significant drift.
How to evidence it
- Drift-specific questionnaire question records
- Security staff turnover monitoring
- Continuous rating drift signal monitoring
- Triggered reassessment records for drift signals
Key Takeaway
Control drift is the gradual erosion that the annual questionnaire does not see. The CISO departure, the seven staff departures, the budget reduction, the tool decommissions, the governance meeting cancellations , each individually below the material change threshold, collectively representing a programme that is significantly weaker than the one that was assessed two years ago. Security programmes degrade when the investment required to maintain them is reduced. The investment reduction happens gradually. The degradation accumulates below the detection threshold of questions that ask about material changes. Ask about the drift indicators directly , headcount, vacancies, budget, governance frequency, audit readiness. The accumulation that those questions reveal is the drift that the material change question cannot surface.
Speak to It™
The term you nodded along to, explained in ninety seconds, so you can speak to it professionally. It is how most readers find these articles.
Join the Association