Compliance Interview Techniques
Compliance interviews are where weak SSPs get exposed and strong programs get validated. Here is how to interview operators and capture what they actually do.
What Interviews Reveal
Compliance interviews surface what the SSP and policies cannot: the actual day-to-day operation of controls. Documents say what the organization wants the controls to be. Interviews reveal what they actually are.
What interviews verify:
- Control awareness: Do operators know the control exists?
- Control operation: How is the control actually executed in practice?
- Exception handling: What happens when normal process fails?
- Cross-team handoffs: Are interfaces between teams smooth or broken?
- Tool effectiveness: Do the deployed tools support the documented process?
- Workforce understanding: Are people trained on the controls they operate?
Strong interviews find gaps that document review missed. Weak interviews accept rehearsed answers without probing. The interviewer's quality determines the outcome.
Use the assessment learning module for interview question banks aligned to control families.
Interview Preparation
Strong interviews start with preparation:
- Review the SSP narrative: Read what the document says about the controls relevant to this interviewee. Identify specific implementation claims to test.
- Map controls to interviewee role: Which controls does this person operate? Which can they speak to authoritatively?
- Prepare specific questions: Tied to controls and assessment objectives. Open-ended where possible.
- Prepare follow-up paths: If the answer is X, what do you ask next? If the answer is Y, what changes?
- Identify evidence to test: "Show me the dashboard that shows MFA enforcement" rather than "Do you have MFA enforced?"
An hour of preparation saves an hour of interview time and produces better results. Underprepared interviews ask generic questions and accept generic answers.
Question Design
Question types and when to use each:
- Open-ended: "Walk me through how you handle a new vulnerability finding from your scanner." Surfaces the real process.
- Specific scenario: "What happens when an admin leaves the company on a Friday afternoon?" Tests whether the off-boarding control works under realistic conditions.
- Probing follow-up: "What if that ticket is open more than 30 days?" Tests exception handling.
- Evidence request: "Can you show me the most recent example of this happening?" Verifies the control actually operates.
- Counter-example: "When was the last time this control failed?" Tests whether they monitor and recognize failures.
Avoid leading questions. "Do you have a strong incident response process?" gets a yes; "Tell me about the last incident you handled" gets the truth.
Avoid yes/no questions for substantive controls. They invite rehearsed answers. Open-ended questions invite descriptions that reveal real implementation.
Listening Techniques
What you listen for matters as much as what you ask:
- Specifics vs generalities: "We do quarterly access reviews" is general. "Our last access review on April 15 covered 47 production accounts and identified 3 dormant accounts that we deactivated" is specific. Specifics indicate real operation.
- Confidence vs hedging: "I think we do that" or "Someone in the security team handles that" indicates the interviewee may not be the right person to ask. Find the actual operator.
- Pattern matching: Multiple interviewees describing the same control should produce consistent stories. Inconsistencies indicate process gaps or training gaps.
- Defensive responses: Long answers that pivot from the question, blame other teams, or invoke authority figures suggest something is being avoided. Probe deeper.
- What is not said: If someone describes a process without mentioning specific steps you expected, the steps may not happen.
Take detailed notes during interviews. Direct quotes capture exactly what was said and prevent later misinterpretation.
Documenting Interview Results
Interview documentation patterns:
- Capture during the interview: Don't try to remember after. Notes during, written up immediately after.
- Quote when significant: Direct quotes capture nuance. Especially for findings that contradict the SSP.
- Map answers to control objectives: For each control objective, which interview answers support or contradict it?
- Identify follow-ups: What evidence requests came out of the interview? What additional people need to be interviewed?
- Distinguish facts from impressions: "Operator stated MFA is enforced for production access" is a fact. "Operator seemed unfamiliar with the control" is an impression. Both can be documented but should be labeled.
Interview notes become evidence in the assessment. Assessors review notes alongside SSP narratives and other evidence to triangulate findings. Good notes hold up under cross-examination during finding disputes.
Frequently Asked Questions
Related Articles
Compliance Assessment Workflow
A systematic compliance assessment workflow takes you from initial client intake through final report. Here is the process that produces consistent, defensible assessments.
Audit Readiness Checklist
Audit readiness is more than controls. Documentation, evidence, personnel, and logistics all need preparation. Here is a comprehensive checklist that applies across frameworks.
System Security Plan Writing Guide
The System Security Plan is the central document for CMMC, FedRAMP, and NIST 800-53 assessments. Here is how to write one that holds up under assessor scrutiny.