An auditor's control questionnaire covers a document store you run on a managed service; why is "the provider is certified" not an answer?
answer
- the report is scoped to the provider's layers
- evidence about the past, not a control you run
- every row splits three ways
- platform-owned, tenant-owned, genuinely shared
- a shared row needs both halves evidenced
basics
~20 sAn independent audit report evidences the provider's side of a control only. Every row still needs the tenant's half answered and evidenced separately, because managed means the provider operates the layer, not that the control is satisfied for your workload.
solid answer
~40 sA provider's audit report is evidence about the provider's layers: the facility, the hardware, the virtualization, and the operation of the service itself. It says nothing about how **you** configured that service, who you granted access to, or what data you put in — so it cannot close a row that has a tenant half. The working method is to split each control into three: rows the platform owns outright, where the provider's report is your evidence; rows you own outright, where you must produce your own records; and rows that are genuinely **shared**, where each side performs a different part and both parts need evidencing. "It is managed" answers the question of who operates the layer. The questionnaire is asking who satisfies the control, which is a different question.
code
pseudocode · 22 linesfor each control in questionnaire:
if control is about the facility, the hardware,
or the virtualization layer:
control.ownerSide = "platform"
control.evidence = provider independent audit report
control.tenantAction = none
else if control is about the data, the identities,
or the configuration exposed to us:
control.ownerSide = "tenant"
control.evidence = our own dated records
control.tenantAction = perform and record the control
else:
control.ownerSide = "shared"
control.evidence = provider report AND our own records
control.tenantAction = perform our half, cite both
if control.evidence is missing:
flag control as unevidenced
// an assumed owner is not an answergo deeper
Remember that a provider's audit report covers the provider's layers only. A managed service still leaves the data, the access and the configuration to be answered by whoever runs the workload.
Explain the three row shapes — platform-owned, tenant-owned and shared — and why a shared row needs both halves evidenced rather than a single answer from either side.
Show you have done this: read the service's own responsibility documentation and the report's scope section, produced dated evidence for tenant rows, and caught a row about access answered as "provider responsibility".
Own the posture: which services are permitted where the report's scope is thin, who signs off residual tenant controls across teams, and how that evidence is kept current between audits rather than assembled under deadline.
## What a provider's audit report actually asserts A large provider is assessed by an independent auditor and publishes the result. That report is genuine evidence, and it is evidence about a specific scope: the provider's facilities and their physical access controls, its hardware and the virtualization layer, and the way it operates the services in scope. Two properties of it matter for your questionnaire: - It is scoped to the provider's own layers and the services listed in it, not to your workload. - It is **detective evidence about the past** — an assessment that controls operated over a period. It is not a control that you operate, and describing it as though it prevented anything in your environment is a category error. So "the provider is certified" is a true statement that answers a question the auditor did not ask. The auditor is asking, per row, who satisfies this control for **this** document store, and what proves it. ## Turning the responsibility model into answers The method is mechanical once you accept that every row is really three possible shapes: 1. **Platform-owned rows.** Physical access to the facility, media disposal, hardware maintenance, isolation between tenants at the virtualization layer. Your answer names the provider as the operator and cites its report as the evidence. You do not claim to have performed the control. 2. **Tenant-owned rows.** Data classification and retention, which principals hold access, whether the store is reachable from outside, whether the configuration was reviewed, what the audit record of changes shows. Your answer names your own team and cites your own records. The provider's report is irrelevant here and citing it is the mistake the question is about. 3. **Shared rows.** The interesting ones. A control like "vulnerabilities are remediated in a timely manner" is performed on both sides of the line: the provider patches the layers it owns, and you patch what you shipped and choose when an offered upgrade lands. A shared row is not a row where either party may answer; it is a row where **each side does a different part and each part needs its own evidence**. ## The claim that fails the audit The failure mode has a specific shape. Someone reads a row, recognises that the underlying service is managed, and writes "provider responsibility, see attestation". Later, the row turns out to have been about who could read the documents, or how long deleted documents remained recoverable, or whether the store was reachable from outside the private network. None of those is in the provider's scope, none of them appears in its report, and the exposure — when it happens — is on a service that was, accurately, fully managed and fully patched the whole time. This is the concrete meaning of "managed is not secured". The tier removes operational work below the line. The controls that cause breaches on a managed service cluster above it, because that is where configuration, access and data live. ## What to do before answering - **Read the provider's own responsibility documentation for the specific service.** The line differs by service on the same platform, so the general picture is not enough for a row-by-row answer. - **Read the report's scope section, not its conclusion.** A service you use may simply not be in scope, which turns an assumed platform-owned row into an unevidenced one. - **Name evidence, not intent, for every tenant row.** A configuration review with a date and an owner is evidence; "we follow least privilege" is not. - **Mark shared rows explicitly as shared,** and attach both halves. A shared row silently answered as platform-owned is the same defect as the one above, just harder to spot. ## Where the boundary of this question sits Two neighbouring things are deliberately not the answer here. What the provider commits to in writing about availability, and what remedy you get when it misses, is a contractual question of its own. So is who holds the encryption key and what revoking it makes unreadable. Both come up in the same conversation, and both are separate subjects; this question is only about who performs each control and who can prove it. ## How to answer it in an interview Say what the report evidences and what it is scoped to, then give the three row shapes, then give the failure: a row about access or retention answered as "provider responsibility" on a service that really was managed and really was patched. That last sentence is the one that shows you have filled in one of these questionnaires rather than read about them.
- Which rows on a document store's questionnaire are most often mis-assigned to the provider?The ones about who may read the documents, how long deleted documents stay recoverable, and whether the store is reachable from outside your private network. All three are configuration and access decisions above the line, and none appears in the provider's report — yet all three sit on a service that is genuinely managed.
- What does marking a control "shared" commit you to?Performing your half and evidencing it separately from the provider's. Shared does not mean either side may answer; it means the control is split, typically with the provider covering the layers it operates and you covering what you shipped, configured or scheduled. Both halves must be citable.
- Why check the report's scope section rather than its conclusion?Because the service you actually use may not be in scope. A clean conclusion over a scope that excludes your service evidences nothing about it, and a row you marked platform-owned on that basis is unevidenced. Scope is where an attestation stops being general reassurance and becomes usable evidence.
saying these in an interview costs you the question
- Treats a provider's audit report as covering the tenant's configuration
- Says "it is managed, so the control is satisfied"
- Describes an audit report as a control that prevents something
- Assumes every service on a platform is inside the report's scope
- Answers a shared row entirely as the provider's responsibility
- Cites intent rather than dated evidence for tenant-owned rows