What is evidence decay?
Evidence decay is the concept that the assurance value of a piece of evidence decreases over time at a rate that depends on the evidence type. Evidence that is harder to obtain (a SOC 2 Type II requires months of auditing) decays slowly. Evidence that is easy to update (a status page) decays quickly. The decay model is exponential: value = initial_value * e^(-lambda * days), where lambda is the decay constant specific to the evidence type.
What are the half-lives of common evidence types?
In TrustVendor’s model, approximate half-lives are: SOC 2 Type II report — 365 days; ISO 27001 certificate — 540 days (valid 3 years, annual surveillance); HIPAA BAA — 730 days (until terminated); subprocessor list — 90 days (changes frequently); status page — 7 days; penetration test report — 180 days; security questionnaire response — 180 days. These half-lives reflect both how often evidence legitimately changes and how easy it is to detect changes.
How does evidence decay affect scoring?
TrustVendor’s assurance score is the evidence-freshness-weighted sum of control coverage. A vendor with a SOC 2 Type II from last month scores higher on assurance than an identical vendor whose SOC 2 is from fourteen months ago — even if the underlying control coverage is identical. The score reflects how much you can actually trust the evidence, not just whether the evidence exists.
How should you use evidence decay in vendor reviews?
Rather than scheduling vendor reviews by calendar, use evidence decay as the trigger. When a vendor’s assurance score drops below a threshold because their key evidence has aged, that is the signal to request an updated report or take other action. This approach concentrates review effort on vendors where evidence is genuinely aging out, rather than distributing it uniformly across a portfolio regardless of evidence freshness.