Back to blogCompliance

Why Your Compliance Program Doesn't Detect Real Risks

Aranis· Plataforma de inteligência de risco
June 28, 20268 min read

One of the world's largest security software vendors, with ISO 27001, SOC 2 Type II certification, and a presence in Gartner's Magic Quadrant, was compromised by a supply chain attack that affected more than 18,000 organizations. The vendor was compliant with everything. The risk had been active for months.

Compliance measures adherence to requirements at a point in time. Risk management measures exposure to adverse events on an ongoing basis. The two disciplines complement each other, but are fundamentally different — and confusing them has serious consequences.

What a certification actually guarantees

ISO 27001 guarantees that, at the time of the audit, the organization had a documented and implemented Information Security Management System, with traceable controls and formalized continuous improvement processes. It does not guarantee the absence of vulnerabilities, it does not guarantee that the controls are sufficient for your specific threat context, and it does not guarantee that nothing has changed since the last audit.

This is not a criticism of ISO 27001 — it is a precise description of what it is. The problem occurs when certifications are used as substitutes for risk analysis, rather than as inputs to it.

Compliance as a floor, not a ceiling

The most useful distinction for security and compliance managers is to treat regulatory frameworks as a minimum floor — not as a destination. A vendor with ISO 27001 passes the basic qualification filter. But the real risk analysis starts after: what is this vendor's attack surface exposure? What critical vulnerabilities are open in their systems? Are their credentials circulating in underground markets?

These questions are not on the certification checklist. They are in the domain of threat intelligence applied to the specific context of each vendor — and require monitoring capabilities that go beyond what annual audits can cover.

The paradox of apparent conformance

There is a silent paradox in many TPRM programs: the more the process is checklist-driven, the less it detects real risk. Sophisticated vendors learn to answer questionnaires in ways that maximize their score — and they do so honestly, because the questionnaires ask about processes that exist on paper, not about the real effectiveness of controls.

The solution is not to abandon questionnaires — it is to complement them with verifiable technical evidence (pentest results, vulnerability scan reports, auditable access logs) and passive external signals that do not depend on vendor self-declaration.

Integrating compliance and risk management in practice

The most robust model combines three layers: declared conformance (questionnaires, certifications), verified technical evidence (scans, third-party reports, shared logs), and continuous external intelligence (threat intel, attack surface monitoring, dark web monitoring). The weight of each layer varies according to vendor criticality — but all three need to be present for vendors with access to critical assets.

With this structure, compliance stops being the destination of the TPRM program and becomes what it should be: the starting point for a genuine risk analysis.

complianceISO 27001NISTriskauditCISO