---
content_id: WACK-CONTENT-0062
library_id: WACK-CASEFILES-0001
channel: web-long-read
related_concept_ids: [WACK-CONCEPT-0008, WACK-CONCEPT-0015, WACK-CONCEPT-0020]
field_manual_content_id: WACK-CONTENT-0022
publication_status: ready
claim_class: editorial_composite
technical_review: not_required
verified: 2026-09-03
---

# The Vendor AOC That Answered the Wrong Question

> The document was current, authentic, and relevant to the provider. It still could not explain the customer’s half of the service.

_Fictional composite synthesized from common practitioner patterns; it does not describe a client, assessment, or incident. Practitioner education, not PCI SSC terminology or a compliance determination._

The vendor sent the AOC in eleven minutes. The team spent the next eleven weeks trying to make it answer a responsibility question it had never been designed to answer.

## The scene

The service provider was responsive, established, and central to the payment flow. Procurement had the contract. Security had the due-diligence packet. Compliance had a current attestation. The architecture diagram showed a neat cloud around the provider with one arrow entering and another leaving. Whenever responsibility came up, somebody pointed to the cloud and said the vendor handles that.

The sentence compressed several different ideas. The provider operated a service. The customer configured part of that service. An internal team decided which events entered it. Another team reviewed alerts. A separate group retained evidence. The AOC described the provider’s assessed services and conclusions. It did not assign the customer’s configuration, monitoring, escalation, or evidence duties for this particular implementation.

## The request that bounced

A reviewer requested evidence for a monitoring activity. The internal owner sent the provider AOC. The reviewer asked where the customer responsibility was described. Compliance sent the contract. The contract named the service but not the operating control. Procurement sent the security exhibit. The exhibit promised capabilities but did not show who configured or reviewed them.

The request bounced among four teams because every document was real and none was the missing artifact. Each handoff widened Ownership Fog. People could identify who purchased the service, who administered it, who met with the vendor, and who received the bill. Nobody could point to one requirement-level or activity-level map showing the provider side, customer side, shared steps, and evidence source.

## The N/A shortcut

Under deadline pressure, someone proposed marking the activity not applicable internally because the provider performed it. That conclusion felt efficient, but it repeated the original mistake. The question was not whether the provider did something related. The question was which exact activity the implementation required from each party and what facts supported that division.

The team opened the service documentation, contract, AOC, configuration screens, runbook, and alert queue together. The documents stopped competing once each was allowed to answer its own question. The AOC supported what had been assessed about the provider. The configuration showed what the customer enabled. The runbook showed who reviewed events. The queue showed how exceptions moved.

## Turning the cloud into a seam

Instead of drawing one cloud labeled vendor, the team drew a seam. On the left: provider-operated platform activities and provider evidence. On the right: customer configuration, data selection, review, escalation, and retention. In the center: shared activities that failed if either side assumed the other had completed the handoff.

The responsibility map fit on two pages. It was less impressive than the AOC and more useful in the next meeting. Every row named the service activity, provider role, customer role, internal owner, evidence, and trigger for reassessment. The AOC remained important. It simply stopped being forced to impersonate a responsibility matrix.

## What the team finally saw

Wack by TPSP appears when evidence about a provider is treated as proof of the customer’s complete operating model. The provider can be competent, the AOC can be valid, and the responsibility gap can still be wide open. The missing object is usually not another assurance document. It is a map of the specific service as implemented: who configures, who operates, who reviews, who responds, who retains evidence, and where the shared seams can fail.

## The way out

### Find

Collect the statements people use to transfer responsibility: the vendor handles it, it is covered by the AOC, or it is not applicable to us. Pair each statement with the exact service activity being discussed.

### Map

For every activity, record provider responsibility, customer responsibility, shared steps, internal owner, evidence source, and unresolved question. Map the implemented service, not the vendor’s marketing category.

### Explain

Let each document answer its proper question. Separate assessed provider services, contractual promises, technical capabilities, customer configuration, operating procedure, and actual evidence instead of blending them into one proof object.

### Reduce

Eliminate ambiguous shared activities, duplicate reviewers, and undocumented handoffs. Where responsibility must remain shared, specify the event, artifact, or notification that proves the handoff occurred.

### Prove

Keep the current responsibility map with the contract, provider assurance material, configuration evidence, operating records, and review trigger. Update it when the service, implementation, or provider scope changes.

## Field notes

- An AOC is evidence about an assessed provider, not a customer responsibility matrix.
- The phrase vendor handles it should always be followed by which activity and which evidence.
- Shared responsibility needs a visible handoff, not a shared assumption.
- N/A is a conclusion supported by facts, not a deadline-management technique.

## What changed

The evidence request closed after the internal team produced its configuration, review record, and escalation trail alongside the provider material. No heroic new control was invented. The team simply stopped asking one document to prove both sides of a relationship.

At the next vendor review, the first agenda item was no longer please send the latest AOC. It was show us what changed in the service, the responsibility seam, and the evidence path. The cloud on the diagram remained. Now it had edges, owners, and a door.


**The next useful question:** Choose one relied-upon provider service and map the provider, customer, and shared activities to named owners and evidence.
