Create an answer record
For each customer question, identify the scope and locate the person able to approve an accurate response.
- Question and the service or entity it concerns.
- Proposed answer and the actual evidence supporting it.
- Evidence owner, version, date and coverage limitations.
- Approval, permitted sharing and unresolved follow-up.
Use precise status language
A policy drafted for approval is not an operating control. A scheduled review is not completed evidence. A supplier assertion is not an independently checked finding. Describe the current state and planned action separately.
Example: access reviews
If one team has completed a review but other systems are pending, say which systems and period are covered. Record the remaining owners and actions instead of answering an unqualified “yes”.
Share a proportionate pack
Use approved summaries or suitably redacted records. Avoid attaching employee data, secrets, unnecessary system detail or another customer’s information. Confirm who can receive any restricted assurance report.
Common questions
Can a proposed future control answer a current “yes/no” question?
Describe it as planned, with its scope and status. Do not represent a commitment as already implemented.
Should every customer get the same evidence?
Start with a maintained core pack, then check relevance, confidentiality and sharing restrictions for that request.
Discuss the work you need
Agree the service, deliverables, responsibilities and fees before committing to an engagement.
Related reading
This page explains topics to scope and discuss. It does not establish applicability, certify compliance or confirm a paid engagement.
← Practical guides