Evidence gaps

How to Handle Unknown or Unsupported Security Questionnaire Answers

Say what the approved evidence proves, state what remains unconfirmed, and route the decision to a named owner. Do not answer “yes” because the control sounds likely or because the deal is urgent.

An unknown is a workflow state, not a failure. Record the gap, choose an owner, set a due date, and use qualified wording only when it gives the buyer a truthful partial answer.

Choose the right state

StateUse it whenNext action
SupportedCurrent, in-scope evidence proves the whole answerCite and send for approval
Needs reviewEvidence is partial, conflicting, stale, or requires owner judgmentRoute to the control owner
UnknownNo approved source answers the questionState the gap and assign discovery

Handle the gap in four steps

  1. Check for partial support

    Separate the part you can prove from the part you cannot. Do not let a true clause carry an unsupported one.

  2. Write plain, qualified wording

    Use “The current approved evidence confirms…” and “The evidence does not confirm…” instead of vague promises.

  3. Assign the right owner

    Route technical controls to engineering or security, contract terms to legal, privacy to the privacy owner, and roadmap claims to product leadership.

  4. Record the decision

    Save the question, evidence checked, owner, deadline, and final approved wording. If the answer stays unknown, keep it unknown.

Safe wording patterns

Unknown“The current approved evidence does not confirm this capability.”
Partial“The control applies to production databases; backup coverage is under review.”
Planned“This is not currently supported. Do not state a future date without approved commitment.”

A safe synthetic example

Fictional compliance question

Question: Do you hold FedRAMP Moderate authorization?

Evidence checked: Trust page, audit reports, security policy, and approved certifications list. No FedRAMP authorization appears.

Unknown / unsupported Answer: “The approved evidence does not confirm a FedRAMP authorization. No authorization should be claimed.”

Common mistakes

  • Turning “we use a compliant provider” into “we are certified.”
  • Calling a planned control current.
  • Using “N/A” when the question applies but the answer is unknown.
  • Asking the same owner repeatedly without recording the decision.
  • Removing unknown rows before final approval.

How SaneCite handles this

When approved evidence does not support an answer, SaneCite leaves the question visible for review instead of inventing a response. The reviewer can add the missing evidence or approve honest qualified wording.

Questions people ask

Will unknown answers hurt the deal?
A clear gap can prompt a useful discussion. An unsupported claim creates larger trust, contract, and security-review risk.
When is “not applicable” correct?
Use it only when the question truly falls outside the product, data, environment, or service scope, and state that reason.
Can I leave the field blank?
A stated unknown with an owner is usually clearer. Follow the buyer's format and approval process.

Primary sources

Published July 26, 2026. No material revisions yet.

Flag the gap. Never guess.

Draft from approved evidence and keep unsupported questions in review.

Try it free

Related guides