An unknown is a workflow state, not a failure. Record the gap, choose an owner, set a due date, and use qualified wording only when it gives the buyer a truthful partial answer.
Choose the right state
| State | Use it when | Next action |
|---|---|---|
| Supported | Current, in-scope evidence proves the whole answer | Cite and send for approval |
| Needs review | Evidence is partial, conflicting, stale, or requires owner judgment | Route to the control owner |
| Unknown | No approved source answers the question | State the gap and assign discovery |
Handle the gap in four steps
Check for partial support
Separate the part you can prove from the part you cannot. Do not let a true clause carry an unsupported one.
Write plain, qualified wording
Use “The current approved evidence confirms…” and “The evidence does not confirm…” instead of vague promises.
Assign the right owner
Route technical controls to engineering or security, contract terms to legal, privacy to the privacy owner, and roadmap claims to product leadership.
Record the decision
Save the question, evidence checked, owner, deadline, and final approved wording. If the answer stays unknown, keep it unknown.
Safe wording patterns
A safe synthetic example
Fictional compliance question
Question: Do you hold FedRAMP Moderate authorization?
Evidence checked: Trust page, audit reports, security policy, and approved certifications list. No FedRAMP authorization appears.
Unknown / unsupported Answer: “The approved evidence does not confirm a FedRAMP authorization. No authorization should be claimed.”
Common mistakes
- Turning “we use a compliant provider” into “we are certified.”
- Calling a planned control current.
- Using “N/A” when the question applies but the answer is unknown.
- Asking the same owner repeatedly without recording the decision.
- Removing unknown rows before final approval.
How SaneCite handles this
When approved evidence does not support an answer, SaneCite leaves the question visible for review instead of inventing a response. The reviewer can add the missing evidence or approve honest qualified wording.
Questions people ask
- Will unknown answers hurt the deal?
- A clear gap can prompt a useful discussion. An unsupported claim creates larger trust, contract, and security-review risk.
- When is “not applicable” correct?
- Use it only when the question truly falls outside the product, data, environment, or service scope, and state that reason.
- Can I leave the field blank?
- A stated unknown with an owner is usually clearer. Follow the buyer's format and approval process.
Primary sources
- NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls (accessed July 26, 2026).
- NIST Cybersecurity Framework 2.0 (accessed July 26, 2026).
- Shared Assessments, Standardized Information Gathering questionnaire FAQ (accessed July 26, 2026).
Published July 26, 2026. No material revisions yet.
Flag the gap. Never guess.
Draft from approved evidence and keep unsupported questions in review.