Third-party identity and screening vendors deliver confident PDFs: match rates, logos, timestamps. Auditors under time pressure attach them and move on. The firm still owns the residual risk those packets never claimed to cover.
Read the boundary, not the cover
Ask what data sources the vendor used, how fuzzy matches are scored, and what the attestation excludes. Contract schedules often hide the answers — which is why our Audit Lab vendor module is thinner if legal will not share schedules. That limitation is real; pretending otherwise helps nobody.
Annotate residual ownership
On the packet itself, mark where vendor responsibility ends. Did your firm decide to override a hit? Who approved? Where is the rule version? Without those notes, a future reviewer only sees a green badge.
Sample the overrides
If overrides cluster in a corridor or VIP path, pull those files deliberately. Vendor KPIs rarely highlight your internal shortcuts.
Teach skepticism without theatrics
The goal is not to attack vendors. It is to keep customer verification audits honest about what evidence actually proves. Autodataops cohorts practice that annotation skill until it becomes a habit.