Guide

Evidence Decay: Why Freshness Is a First-Class Risk Concept

Every piece of vendor risk evidence has a freshness date and a decay rate. A SOC 2 Type II report from three months ago is strong evidence. The same report from eighteen months ago is weak evidence — not because it was wrong then, but because the vendor's controls may have changed since. Most risk management tools treat all evidence as equally valid regardless of age. TrustVendor treats evidence freshness as a first-class concept with an explicit mathematical model.

What is evidence decay?

Evidence decay is the concept that the assurance value of a piece of evidence decreases over time at a rate that depends on the evidence type. Evidence that is harder to obtain (a SOC 2 Type II requires months of auditing) decays slowly. Evidence that is easy to update (a status page) decays quickly. The decay model is exponential: value = initial_value * e^(-lambda * days), where lambda is the decay constant specific to the evidence type.

What are the half-lives of common evidence types?

In TrustVendor’s model, approximate half-lives are: SOC 2 Type II report — 365 days; ISO 27001 certificate — 540 days (valid 3 years, annual surveillance); HIPAA BAA — 730 days (until terminated); subprocessor list — 90 days (changes frequently); status page — 7 days; penetration test report — 180 days; security questionnaire response — 180 days. These half-lives reflect both how often evidence legitimately changes and how easy it is to detect changes.

How does evidence decay affect scoring?

TrustVendor’s assurance score is the evidence-freshness-weighted sum of control coverage. A vendor with a SOC 2 Type II from last month scores higher on assurance than an identical vendor whose SOC 2 is from fourteen months ago — even if the underlying control coverage is identical. The score reflects how much you can actually trust the evidence, not just whether the evidence exists.

How should you use evidence decay in vendor reviews?

Rather than scheduling vendor reviews by calendar, use evidence decay as the trigger. When a vendor’s assurance score drops below a threshold because their key evidence has aged, that is the signal to request an updated report or take other action. This approach concentrates review effort on vendors where evidence is genuinely aging out, rather than distributing it uniformly across a portfolio regardless of evidence freshness.

Common questions

Does evidence decay mean I need to recollect evidence annually?
For slow-decaying evidence like SOC 2 reports, annual recollection aligns with the audit cycle. For fast-decaying evidence like subprocessor pages, TrustVendor monitors continuously so you do not need to manually check. The goal is continuous assurance, not annual snapshots.
How is evidence decay different from expiry?
Expiry is binary: a certificate is either valid or it is not. Decay is a gradient: assurance decreases continuously as evidence ages, reaching zero at the conceptual expiry point. This gradient model is more honest — a SOC 2 from eleven months ago is not as good as one from one month ago, even if both are "valid".
Can I override the evidence decay model for specific vendors?
In TrustVendor, you can adjust decay parameters for specific vendor tiers or individual vendors. A vendor with a contractual obligation to provide monthly attestations might warrant a faster decay model; a vendor with five consecutive clean SOC 2 Type II reports might warrant slower decay to reflect the track record.

Related guides

Residual Risk in Third-Party Risk ManagementSOC 2 Reports Explained: What Compliance Teams Need to KnowBitemporal Claims: How TrustVendor Models What Vendors Promised and When

Put evidence behind every vendor claim.

TrustVendor automates the evidence collection this guide describes.

Book a demo