Use a guide to clarify the question
A framework name can make a project sound more defined than it is. A customer may ask about SOC 2, a colleague may mention ISO 27001 and a vendor questionnaire may ask about privacy controls. Before choosing a preparation path, establish which decision you need to support and what the other party is actually requesting.
RiskSensai’s readiness directory contains curated framework-and-industry guides. These are educational entry points with considerations and questions appropriate to their stated context. They are not a claim that every framework is available as a fully implemented operational control catalog.1
Use the guide to ask better questions. If you need a formal examination, certification or a contractual statement, identify the appropriate professional process separately. The platform’s readiness information does not confer that outcome.2
Select an existing combination
Open the readiness directory and choose a published guide matching the framework and industry you want to explore. The current directory uses a defined set of combinations rather than accepting every possible framework label. For example, the published SOC 2 and technology guide is an existing route; typing arbitrary combinations into the address bar does not create supported guidance.
Read the guide heading and scope before continuing. A similar-sounding guide may still address a different context. If none fits, use the general assessment entry or seek clarification rather than forcing your organization into the closest label.
This is also a useful point to confirm language with colleagues. Are you preparing for a customer discussion, deciding whether to seek a formal engagement, or gathering internal evidence? Those purposes may share records, but they are not the same task.
Read for considerations, not conclusions
The guide can help you identify areas to investigate and questions to discuss. Turn its context into a small preparation note:
| Preparation item | What to write |
|---|---|
| Business purpose | Why this framework came up |
| Organization scope | Which business or service the discussion concerns |
| Requested outcome | Information, preparation or a separately scoped professional engagement |
| Known records | Existing policies, exports or review notes relevant to that purpose |
| Unanswered questions | Information you still need from the owner or requesting party |
Do not complete the note by copying favorable language from a guide. The organization-specific statements must come from your own current facts. A list of common considerations is not evidence that those considerations have been addressed.
Follow the existing assessment action
When the guide’s assessment action fits your purpose, follow it through the existing entry workflow. Sign in when required and explicitly choose the organization. The guide context can accompany the entry, but the current interface explains that context does not change the question bank or establish compliance.
RiskSensai’s assessment remains a self-reported readiness questionnaire across its defined domains. Choosing a framework guide does not silently replace those questions with every requirement of the named framework. The result retains its informational character.3
If you belong to multiple organizations, verify the selected organization before continuing. A correct framework label does not correct a wrong tenant selection. Both the subject of the work and the access context need to be right.
Answer from practice rather than target state
Framework preparation often reveals that people know what a good process should look like but are less certain about what currently happens. Keep that difference visible while answering. A policy under development is not an approved policy. A planned access review is not a completed review.
Ask the relevant owner when the evidence is unclear. You can record a separate working note explaining which answer needs confirmation and which record would resolve it. Do not invent a favorable response to keep the assessment moving.
The current modes have different questionnaire scope. A Quick check is a shorter starting point; the full assessment is broader. Neither mode should be described as an independent examination of every control merely because you entered through a framework guide.
Worked example: a customer’s SOC 2 question
Suppose a technology customer asks whether you have a SOC 2 report. Your organization does not have one, but wants to understand what preparation might involve. The technology readiness guide can help frame the discussion, and the assessment can help identify self-reported gaps.
A useful response to the customer remains honest: you are exploring readiness and have not obtained the requested report. Internally, you might use the guide to ask which service is in scope, who owns relevant processes and what records already exist. You can then decide whether to discuss a professional engagement.
What you cannot reasonably say is that completing the RiskSensai questionnaire supplies a SOC 2 report or establishes equivalent assurance. The guide, the assessment and a formal report have different purposes and different evidentiary weight.2
Keep catalog limitations visible
The current Evidence & Controls interface uses manual control organization and identifies further framework-aware catalog work as a later capability. Do not convert a guide title into a claim that native framework mappings, automated evidence collection or full coverage verification are enabled.
If a colleague links a record to a manually created control, explain the intended relationship. A single policy may help discuss several questions, but that does not mean the application has validated every mapping or eliminated framework-specific interpretation.
The same caution applies to proposed paid scope. A marketing description or plan name is not evidence that an unfinished capability has been activated for the account you are using.
End with a scoped next step
After the assessment, review the saved result and select a few concrete follow-ups. Keep the chosen guide, the organization and the reason for selecting it in your working discussion. That context helps another person understand why the answers were collected.
If you need professional help, prepare a brief describing the desired outcome and the records you already have. Availability and written scope still need confirmation. The guide should make that conversation clearer, rather than imply that a certification, review appointment or audit opinion has already been arranged.
The useful outcome is a better-defined preparation task: a specific organization, a real purpose, current answers and visible uncertainty. That is a strong starting point even when the next decision is to gather more information before proceeding.
Sources and references
-
RiskSensai. Framework Readiness Guides. Provides curated framework and industry entry points. ↩
-
RiskSensai. RiskSensai Trust Center. States readiness and formal-assurance boundaries. ↩ ↩2
-
RiskSensai. Free Digital Trust Assessment. Explains self-reported scope and authenticated assessment entry. ↩

