---
title: "A Wrong Answer About One 800-171 Practice Ends Up in the System Security Plan You Drafted. Citations Catch It."
description: "Wrong control narratives cost failed assessments and rework. How answers restricted to an approved document shelf, with citations, change a GRC analyst's week."
canonical: https://callsphere.ai/blog/a-wrong-answer-about-one-800-171-practice-ends-up-in-the-system-securi
category: "IT & SaaS Support"
tags: ["cmmc", "nist 800-171", "grc consulting", "security questionnaires", "vciso", "grounded answers"]
author: "CallSphere Team"
published: 2026-06-18T14:37:43.000Z
updated: 2026-07-25T23:18:26.482Z
---

# A Wrong Answer About One 800-171 Practice Ends Up in the System Security Plan You Drafted. Citations Catch It.

> Wrong control narratives cost failed assessments and rework. How answers restricted to an approved document shelf, with citations, change a GRC analyst's week.

One hundred and ten practices. One score submitted to a government system, on a scale starting at 110 that can run down past minus two hundred. One system security plan, sometimes ninety pages, drafted by your GRC analyst and stood behind by your firm. That is what a CMMC Level 2 readiness engagement produces, and every sentence in it asserts something about what a client actually does.

Now count the sentences your team wrote last year across system security plans, plans of action, SIG Lite responses, CAIQ workbooks, HECVAT sheets for the university client, and the 300-row Excel questionnaire the health system sends every February. Somewhere in the low thousands — every one a place where a fluent wrong answer can be typed and never caught.

## The specific way a wrong answer costs money here

In most trades a wrong answer from an assistant produces an awkward email. In compliance consulting it produces one of four outcomes, all with a price.

The first: a control narrative in a client's system security plan describes something they do not actually do. The third-party assessor asks to see it, the evidence does not exist, and a clean assessment becomes a finding — and for a defense subcontractor whose award depends on it, a delayed contract. The second: a self-assessment score computed on a mistaken reading of what counts as met, and submitted. That is not a paperwork error; misrepresenting security compliance to the government is exactly what the Department of Justice's civil cyber-fraud work pursues, and the contractor's signature is on it even though your firm drafted the words.

The third is quieter: a questionnaire answer claims a capability the client's environment does not have, their customer relies on it, and eighteen months later somebody pulls that questionnaire during an incident. The fourth is rework — the auditor kicks back a batch of answers and your GRC analyst spends two days rewriting what was plausible rather than sourced.

**Grounding means the assistant may only answer from documents you have approved — the assessment guide, the client's signed policies, the evidence already accepted by an auditor — and it shows you which document and which paragraph each sentence came from.**

## Why 2026 is different from the version you tried

The 2024 experiment in most firms went like this: someone pasted a control requirement into a chat window and got back four paragraphs of confident, generically-correct-sounding narrative. It read beautifully. It also invented control numbers, blended one standard's language into another's, and described a quarterly access review the client had never performed. Useless to an assessor, and correctly abandoned.

What shipped since is grounding with citation: the assistant is restricted to a defined body of your own approved material, and every claim comes with its source next to it. The consequence for a compliance practice is not more eloquent answers. It is that a wrong answer becomes catchable in seconds instead of plausible for eighteen months. A sentence with no citation is a sentence somebody made up, and your reviewer can see that without knowing the standard by heart.

```mermaid
flowchart TD
  A["Questionnaire row or control narrative to answer"] --> B["Search the approved library only"]
  B --> C{"Found a source: policy, evidence, or assessment objective?"}
  C -->|"No"| D["Mark as gap, route to the vCISO"]
  D --> E["Client interview or new evidence collected"]
  E --> B
  C -->|"Yes"| F["Draft answer with the document and paragraph shown"]
  F --> G{"GRC analyst agrees the source says that?"}
  G -->|"No"| D
  G -->|"Yes"| H["Answer locked, source recorded in the audit trail"]
```

## What goes in the approved library, and what stays out

The whole value here depends on being strict about the shelf. For a firm doing CMMC and SOC 2 work it holds: the CMMC assessment guide for the level you are working at; the assessment objectives in NIST SP 800-171A, which are the sentences an assessor checks against; the client's signed and dated policies as they sit in Vanta, Drata or Hyperproof; their current system security plan and plan of action; screenshots and configuration exports already accepted in a prior audit; and your own bank of questionnaire responses that survived review.

What stays out matters more. Blog posts. Vendor whitepapers. A different client's system security plan — a tempting shortcut that eventually puts one client's environment description inside another client's document. Unsigned draft policies. And anything from a standard the client is not being assessed against, because mixing one standard's language into another's narrative is the most common way these documents get flagged.

Set the shelf up per client, not per firm — the manufacturing client's enclave boundary and the software client's cloud environment are different worlds, and a shared shelf is how a sentence about one ends up in the other. Date every document and remove superseded versions as they change.

## A February afternoon in the GRC seat

The health system's vendor risk team sends the annual questionnaire on a Tuesday: 312 rows, ten business days, for a client on a monthly vCISO retainer. Historically your analyst blocks out three days, works from last year's file, guesses at the eleven rows whose wording changed, and emails the IT manager four questions that come back on day nine.

The 2026 version: the analyst points the assistant at that client's shelf and asks for the 312 rows. It comes back in three groups. Answers citing a signed policy or accepted evidence — most of the file, drafted in an hour, each with its source named. Answers whose only source is last year's response with no evidence behind it, flagged as such. And rows where nothing on the shelf supports an answer at all, which is the pile that matters: those go to the vCISO as a gap list, and they are the client conversation you should have been having anyway.

The analyst's day stops being typing and becomes checking: open each cited paragraph, confirm it says what the draft claims, reject the ones that stretch. The gap list reaches the client's IT manager on day one instead of day nine.

## What the rework actually costs, before and after

Illustrative assumptions: your practice produces roughly 4,600 written control answers a year across questionnaires, plan narratives and auditor evidence responses. About 22% come back for rework today — from your senior reviewer, the client, or the auditor — at roughly 25 minutes of analyst time plus 10 of vCISO time, blended at $85 an hour. With citation review made mandatory, assume rework falls to 6%.

| Line | Today | With grounded answers |
| --- | --- | --- |
| Answers written per year | 4,600 | 4,600 |
| Rework rate | 22% = 1,012 | 6% = 276 |
| Rework time at 35 min each | 590 hours | 161 hours |
| Cost of rework at $85/hour | $50,150 | $13,685 |
| Tooling, illustrative |  | $9,000 |
| Net annual difference |  | **$27,465 recovered** |

That is the boring half. The other half has no reliable frequency: one assessment that fails on a control narrative nobody could evidence costs the re-assessment fee, months of delay for a client whose award depends on the certificate, and a relationship you probably do not keep. Price that at $45,000 plus the retainer, and one avoided occurrence in three years beats all the rework savings combined.

## The judgment grounding does not replace — and where to begin

A citation proves a sentence came from a document. It does not prove the document is true. If a client's signed access control policy says quarterly reviews happen and nobody has run one since March, a grounded answer will cheerfully cite the policy — exactly the assertion that collapses in an assessment. Grounding fixes invention, not a paper program, and telling those apart is what your vCISO is for.

Scoping stays human, and scoping is where the money is decided. Which systems fall inside a controlled unclassified information enclave, whether a shared service is in or out, how remote workers are handled — those are arguments with an assessor, informed by knowing the client's business. No document search settles them.

Interpretation stays human too. The gap between what a requirement says and what a particular assessor accepts as meeting it is trade knowledge held by people who have sat through assessments. And the final read stays human: somebody with a name signs off. Make that explicit, because "the assistant cited a document" is not a defense anyone will accept.

So start narrow. Pick one client and one document type — questionnaire responses, not the system security plan. Build that client's shelf: signed policies, the evidence file the last auditor accepted, last year's approved answers. Run the next questionnaire through it with your analyst checking every citation, and count two things: how many rows came back with a real source, and how often the analyst disagreed with the cited paragraph. That disagreement count is your quality measure from then on — review it monthly, and widen to plan narratives only once it is low and stable.

## Frequently asked questions

### Can we use this for our own SOC 2 and our own answers, not just client work?

Yes, and it is the sensible place to start, because you are the client who will forgive you. Your firm gets sent the same vendor questionnaires your clients get, and your own auditor asks for the same evidence. Run your own shelf first, find where it produces nonsense, then take it to a paying engagement.

### Is it safe to put a client's policies and evidence into one of these tools?

It is a contract and boundary question. Check what your master services agreement says about processing their material, whether the service appears on your own supplier list, and for defense clients whether it sits inside the boundary described in your own system security plan. If a client holds controlled unclassified information, keep their shelf out of any service you cannot evidence as acceptable to their assessor.

### Will an assessor accept answers written this way?

Assessors do not assess your writing method; they assess whether the practice is met and whether evidence supports it. Work drafted this way tends to hold up better under questioning, because every sentence traces to a policy paragraph or evidence file — which is exactly what gets asked for next. Be ready to say plainly how the document was produced and who reviewed it, and that answer should be a person's name.

## A note from CallSphere

Compliance season produces phone calls: the client whose questionnaire is due Friday, the prospect who just failed a customer's vendor review, the IT manager chasing an evidence request while your GRC team is heads-down. [CallSphere](https://callsphere.ai) builds AI voice and chat agents that answer the phone line and website chat around the clock, handle routine questions about your services, book the scoping call and pass the details into your systems — so the February rush reaches a person instead of a voicemail greeting.

---

Source: https://callsphere.ai/blog/a-wrong-answer-about-one-800-171-practice-ends-up-in-the-system-securi
