NDPA modules · Document requests
Two people asked for the same document on the same day.
The statement of applicability lists every control you hold and precisely where you are weakest. One of these asks should be granted within the hour. The other should never be answered at all — and the difference is not in the document.
Amara Nwachukwu
DR-2026-011Kuda Microfinance Bank · asked 25 July
“We are in procurement with LagosPay and our risk team needs the statement of applicability before we can sign.”
- ✓A named person
- ✓At a company you can verify
- ✓In an active procurement with you
- ✓Asking for what that purpose needs
research@datatrends.example
DR-2026-010Organisation not stated · asked 23 July
“Collecting security documentation from Nigerian fintechs for a market report.”
- ✕No named person
- ✕No organisation given
- ✕Not a vendor review
- ✕Asking for your weakest page
Four requests this month
Every decision recorded with its reason, including the refusals
Because a year later somebody will ask why one competitor got the report and another did not — and the answer needs to be a rule you applied consistently rather than a mood on the day.
2 waiting on you
| Who asked, and for what | State | Decision and reason | Age |
|---|---|---|---|
| Amara NwachukwuKuda Microfinance Bank · Prospective customer · vendor reviewISO 27001 statement of applicability | Waiting on you | Not yet decided. Everything needed to decide it is on the request. | 2 daysunanswered |
| research@datatrends.exampleNot stated · Capacity not statedISO 27001 statement of applicability | Waiting on you | Not yet decided. Declining costs nothing and takes one line. | 4 daysunanswered |
| Segun BelloSterling Bank · Prospective customer · vendor reviewISO 27001 statement of applicability | Granted | Named counterparty in an active procurement. NDA signed both ways before release. Expires 10 August. | 2 daysto decide |
| Ifeoma AdelekeRenmoney · Prospective customerPenetration test, full report | Declined | The full report names unpatched hosts. The remediation summary was sent instead, which answers the question without handing over a map. | 1 dayto decide |
DR-2026-009 · granted for thirty days
The link stops working, and he has to ask again
Which sounds like friction until you notice what he is holding: a document that names your excluded controls, as they were in July. By September it describes a company that has moved. Making him ask again is how you avoid a stale copy of your weakest page circulating indefinitely.
An emailed PDF has no expiry, no record of who forwarded it, and no way back.
Segun Bello · Sterling Bank
ISO 27001 statement of applicability
- Decided by
- Tunde Adeyemi
- Decided in
- 2 days
- NDA
- Countersigned first
- Access expires
- 10 August 2026
- After that
- He asks again
Five questions, asked in order
Declining is not rudeness. It is the answer to a question they did not earn.
And the best refusals come with something else instead. Renmoney asked for the full penetration test; they got the remediation summary, which answered their real question without handing over a map of unpatched hosts. She accepted it and the deal proceeded.
A bare no would not have produced that outcome.
Is there a named person?
A shared mailbox is not a requester. You cannot record a decision about somebody who has not identified themselves.
Can you verify the organisation?
A corporate domain and a company you can look up. Not a proxy for good faith, but the absence of both is a signal.
Does the stated purpose need this document?
A vendor review needs the statement of applicability. A market report does not need anything of yours.
What does the document expose?
Your weakest controls, named. Ask what an unfriendly reader would do with it, not what this reader says they will.
Is there a lesser thing that answers it?
A summary, a scoped extract, a call. The best refusals are substitutions, and they close deals that a bare no would lose.