Two buyers. Same question. Two answers.
Pull two returned questionnaires and read the same row side by side. Thirty seconds, and it is the cheapest audit in the building.
Open two files.
A security questionnaire your team returned in February. Another returned in April. Different buyer, different logo in the header, same question two-thirds of the way down: Where is customer data stored, and is any of it processed or accessed outside the United States?
Read the February answer. Read the April answer. Then read them side by side.
I’ve built and audited more than 5,000 of these responses, and I can tell you what you’ll usually find. They don’t say the same thing.
Nobody did anything wrong. Two people, two deadlines, two sources. One copied the last completed questionnaire out of a shared drive. One pulled from the security page, which engineering had revised in the meantime. Both went to a buyer. Both are on the record. Neither was flagged.
That’s the whole idea. Thirty seconds to test, and almost nobody runs it on purpose.
The answer isn’t a document. It’s a commitment.
A sales deck is marketing. A security questionnaire answer is a statement of fact about your company, made in writing, to a buyer who is going to file it.
And it doesn’t stay in the deal. It goes into their vendor-risk record. It gets read by the person who renews you. It comes back out when their auditor asks how they diligenced you.
So two versions of the same fact sent to two buyers in one quarter isn’t a copy error. It’s two commitments that can’t both be true, with a written record of each sitting in a different company’s file.
Not a legal question, incidentally. I don’t touch contracts or redlines — that lands long after this does. This is sitting in the pile of answers your team ships every week that nobody reviews against each other.
The side-by-side
I have no client stories and I’m not inventing one. Picture two deals in the same quarter. I made these up to show the shape. The shape is the real part.
Question, both questionnaires: Where is customer data stored, and is any of it processed or accessed outside the United States?
“All customer data is stored in US-based data centers. Customer data is not processed or accessed outside the United States.“
“Primary storage is US-based. Certain support and engineering functions are performed by personnel located in the EU and India, under contractual data-protection terms.”
It is rarely just the one, and contradiction is only half of it. The version I have seen most often is multiple variants of the same answer, each written for a different audience, with nothing telling anyone which to pull when. Not wrong. Just unlabelled — and a rep on a deadline picks by instinct.
My estimate is that roughly a fifth of a typical library is effectively unusable at any given moment — outdated, superseded, or an orphaned variant nobody can place. That is a read from building and auditing this content, not a measured figure, but it is the number I would plan against.
It is rarely just the one. Run the same check on retention and you’ll find thirty days after termination, then permanent deletion sitting next to ninety days by default, with extended retention available on request. Run it on subprocessors. On breach-notification windows. On certifications held versus in progress. Then run it on the newest category — how your product uses AI, what it trains on, whether a buyer’s data ever reaches a third-party model. That question didn’t exist in most answer libraries two years ago. Nobody owns it yet, and it’s where divergence is worst right now.
Nobody catches it because nobody reads both
People assume the fix is caring more, hiring a better writer, or buying software. It isn’t. The failure is structural, and once you see the structure you can’t unsee it.
Every review in your process is vertical. The rep reviews their own questionnaire. Security signs off on the technical accuracy of the answer in front of them. The deal desk checks pricing on that one deal. Every review is competent. Every review is scoped to a single response.
The contradiction doesn’t live inside a response. It lives in the space between two of them.
There is no reviewer whose job includes reading the last one. No gate the second answer passes through where the first one is present. Try to name the person at your company who is supposed to catch this. There isn’t one. They aren’t failing at the job — the job doesn’t exist.
Your tools are built the same way. Response software is organized by project, because projects are how the work arrives. Search is built for retrieval: it answers what did we say about encryption and hands you the top result. It is not built to answer did we say two different things about encryption. That’s a conflict query, and a conflict query is nobody’s product feature. A team with a well-maintained library and a real tool still has this problem, because the tool is doing exactly what it was designed to do.
AI widened the gap rather than closing it. Point a model at a folder and it returns a fluent, confident, well-formatted answer in seconds. Point it at a different folder next month and it returns a different fluent, confident, well-formatted answer, and neither looks wrong. The old friction — a person rewriting an answer slowly enough to think wait, didn’t we say something else last time — was doing quiet quality work nobody had budgeted for. Speed removed the pause.
Running the check
Not a product. A pass, and you can run the first one yourself this week.
Pick the answers that carry real exposure
Not all four hundred. In my experience three come up over and over and cause the most trouble: data location — always, with any global customer — encryption and key management, and retention. After those: subprocessors, breach notification, certifications held versus in progress, uptime commitments, and how your product uses AI. Oversight proportionate to exposure — you don’t audit the company-overview paragraph at the intensity of the data-residency answer.
Pull what you sent, not what’s in the library
Skipping this defeats the exercise. Your library is what you meant to say. The returned questionnaires are what you actually said, and only one of those is sitting in a buyer’s file. One quarter is plenty.
Sort by question, not by deal
That’s the trick. Everything in your world is organized by deal — folders, CRM records, project workspaces, your own memory. Contradictions are invisible under that sort and obvious under this one.
Resolve each divergence out loud
Which one is true. Which are superseded. Who owns that domain going forward, by name. How long an answer in that domain stays valid before someone re-confirms it.
The practical route is the function leader. Take the divergence to whoever owns that domain and let them state the current position — not as a correction to be litigated, but as the latest stance. Then the hard one: does a buyer need to be told. When the answer is yes, frame it constructively and forward-looking. A vendor who proactively clarifies its own position reads as governed. A vendor who is caught reads as careless, and it is the same fact either way.
Step four is why this isn’t a software problem. AI can compare thousands of answers faster and more thoroughly than any human, and it should. What it can’t do is decide which sentence your company stands behind, or whether you go back to a buyer you’re mid-renewal with. AI does the volume. A person who ran the motion owns the judgment.
The cheapest audit in the building
In B2B SaaS and life sciences since 2011, running Deal Desk and Sales Operations since 2018, I’ve never seen a team run this check as routine. I’ve seen plenty discover a contradiction the expensive way — from a buyer, in a follow-up question sharper than the first one.
It costs an afternoon. It needs no budget, no tool, and nobody’s permission.
And unlike most process work, it produces evidence from your own artifacts on day one rather than a recommendation you have to take on faith.
Two files. Same question, two deals, one quarter. What did you actually send?
Related: on why the commercial side never got the discipline the regulated side did — Same discipline. Different room.