What is it?
Supplier evidence is any document a supplier produces or publishes that lets you verify a claim about their controls, practices or performance. In vendor due diligence, evidence is what separates "the supplier says so" from "the supplier has shown so".
Not all evidence is equal. Understanding what makes evidence strong — and what makes it weak — is one of the highest-leverage skills in due diligence.
Why does it matter?
Assessments built on strong evidence are defensible. When a regulator, auditor or internal reviewer asks why you approved a supplier, you can point to specific documents mapped to specific requirements. Assessments built on weak evidence — questionnaire answers, marketing pages, verbal assurances — collapse under scrutiny.
Common challenges
- Marketing collateral treated as evidence ("we take security seriously").
- Certifications accepted without checking scope, dates or exclusions.
- Questionnaire responses recorded as fact without corroboration.
- Attestation letters treated as equivalent to audit reports.
- Evidence collected once at onboarding and never refreshed.
Best practice
Evidence strength can be judged along five dimensions:
- Independence — was it produced by a qualified third party (auditor, assessor, tester) or self-declared?
- Scope — does it cover the specific product, environment and controls you rely on?
- Recency — is it current, or has the environment changed since it was produced?
- Specificity — does it describe controls in enough detail to verify, or only in general terms?
- Traceability — can each claim you rely on be pointed back to a specific paragraph or section?
A SOC 2 Type II report with in-scope services, no material exceptions and a current audit period is strong evidence. A vendor's own security whitepaper for the same claim is weaker. A questionnaire answer is weaker still. The point is not to reject weaker evidence categorically — it is to know what you have and to assess accordingly.
How Governly supports this area
Governly's methodology, Requirements-to-Evidence Mapping, is built on this distinction. Every requirement in an assessment is linked to the specific evidence that supports it. Where evidence is missing or weak, the assessment says so — the goal is a traceable decision, not a green checkmark.