The most dangerous compliance artifact in security is not always the missing policy. Sometimes it is the completed questionnaire, filed with ceremonial confidence, quietly proving only that everyone involved can survive a long PDF without losing the will to patch. SecurityWeek columnist Matt Honea has a useful antidote to this paperwork séance: stop worshipping bigger frameworks and ask better questions. His argument is not anti compliance, which would be convenient and wrong. It is anti theater, the kind where a control exists because a cell in a spreadsheet says it exists, and production systems nod politely while doing something else entirely. ## Incident Report: SecurityWeek Finds A Checklist Shaped Hole SecurityWeek’s Honea opens with a lesson from outside security: in 2009, Atul Gawande and a team backed by the World Health Organization showed that a 19 item surgical checklist could cut complications and deaths by dramatic margins across eight hospitals worldwide. Honea also points to aviation, where the pre flight checklist fits in a pilot’s hand rather than a binder. The lesson is not that surgery, aviation, or AI governance are simple. It is that high consequence work improves when the critical questions are short enough to use and specific enough to catch failure. That is the compliance version of discovering the smoke alarm should be connected to the ceiling, not laminated in the emergency plan. Frameworks can define territory, but questions determine whether anyone can prove the control is alive. If a team cannot answer where evidence comes from, who uses it, and what engineering decision changes because of it, the control may be decorative. Decorative controls are very popular right up until the incident review starts asking rude questions. ## Blast Radius: SecurityWeek Sees Questionnaires Swelling SecurityWeek’s Honea says security teams are sending AI vendors questionnaires with 300 questions, with many starting by asking vendors to describe their approach and few likely to catch a real failure. This is how compliance turns into a fog machine with procurement branding. The vendor writes confident prose, the buyer stores it, and everyone hopes the model never changes in a way that makes the answer stale before the next review cycle. The practical blast radius is not just wasted time. It is misplaced confidence, which is security debt wearing a blazer. A 300 question questionnaire can still miss the one thing engineering needed to know: whether the claimed control produces observable, repeatable evidence when the system behaves badly. Threat actors do not care how elegant your policy taxonomy is. Neither does an outage, a data leak, or a model behavior nobody thought to test because the spreadsheet was already green. ## Root Cause: SecurityWeek Says Frameworks Are Not The Finish Line SecurityWeek reports that the timing matters because the EU AI Act’s enforcement teeth for general purpose AI arrive this August, high risk obligations are phasing in behind them, ISO/IEC 42001 is appearing by name in third party risk questionnaires, and NIST’s AI Risk Management Framework has become the default North American answer for proving an AI risk program exists. That is a lot of gravity pulling teams toward bigger compliance maps. Maps are useful. Mistaking the map for the road is how organizations end up compliant in theory and surprised in production. The better move is to treat each framework requirement as an engineering design prompt. What question would expose failure? What log, test result, model card, review record, or access decision would answer it? Who sees that evidence before a customer, regulator, or incident commander does? If the answer is a paragraph beginning with governance vibes, congratulations, you have invented a control shaped piñata. ## Mitigation: SecurityWeek’s Lesson For Builders And Buyers SecurityWeek’s core point is that the best programs are built on a short list of questions that can be answered and still hold when models change. For buyers, that means replacing broad vendor poetry with requests for evidence that can be tested. For builders, it means designing controls that generate proof as a byproduct of real work, not as a quarterly archaeological dig through tickets, screenshots, and Slack messages nobody wants admitted into evidence. This is where compliance becomes useful instead of merely survivable. Ask whether the control would have caught a real failure, whether the evidence is fresh enough to matter, and whether an engineer can act on it without decoding a binder. The answer will not make frameworks disappear, and it should not. It will make them less like wall art and more like instrumentation. ## What It Actually Means For You SecurityWeek’s column is a reminder to stop measuring compliance by page count. If you run security, procurement, privacy, or product for AI systems, pressure test your favorite framework with one brutal question: what evidence would prove this control reduced real engineering risk today? If nobody can answer without scheduling a workshop, that is your backlog item. The next phase of AI compliance will reward teams that can connect regulation, vendor review, and engineering reality without drowning in questionnaires. Watch for organizations that move from describe your approach to show the evidence. The former is paperwork. The latter is how we keep the internet from becoming a compliance museum with breach notifications in the gift shop. ## Sources - Timeless Compliance: Why Better Questions Beat Bigger Frameworks

Sources