Scrutineer · By framework
HECVAT questionnaire software for HECVAT 4, Lite and Full
The HECVAT Lite and Full choice that most published guides still describe was retired. HECVAT 4 replaced all three workbooks with one conditional questionnaire, and it now asks about AI and accessibility as well.
Scrutineer holds your controls and evidence once, then drafts HECVAT answers from them, so a university request becomes a review pass instead of two weeks of retyping.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with HECVAT
The HECVAT Lite and Full choice no longer exists
This is the single most common mistake in HECVAT guidance being republished right now. HECVAT 4 consolidated the Full, Lite and On-Premise workbooks into one instrument in February 2025, and EDUCAUSE lists 4.1.6 as current as of July 22, 2026. Instead of picking a version, you complete a core set of questions and a Start Here tab routes you through the rest based on solution type, deployment model and the data you touch. A vendor who downloads a HECVAT Lite template today is filling in a retired form, and an institution that asks for one is usually asking out of habit rather than policy. The practical effect is good news: the conditional routing means a low risk product answers far less than the roughly 321 questions the full workbook contains.
HECVAT 4 now asks what your AI does, and most vendors have no artifact for it
Artificial Intelligence is a dedicated section in HECVAT 4, alongside Organization, Product, Infrastructure, IT Accessibility, Case-Specific and Privacy. If your product ships any AI feature, higher education procurement now expects an inventory of it, a documented purpose and its limitations, something credible about training data provenance, evidence of human oversight, and the controls an institution can use to opt out. This is where 2026 HECVATs stall, because AI features shipped fast and the governance artifacts behind them usually do not exist yet. Scrutineer runs that inventory and oversight evidence from the same control set as the rest of your program, so the AI section is answered rather than negotiated.
The accessibility section does not discharge the VPAT request
HECVAT 4 includes an IT Accessibility section covering WCAG conformance and assistive technology support, and a lot of vendors read that as replacing the accessibility paperwork. It does not. Institutions routinely require both a HECVAT and a VPAT or Accessibility Conformance Report for each product, on new purchases and on renewals, because the two answer different questions: HECVAT screens, the ACR documents conformance in detail. If you answer the HECVAT accessibility questions and then push back on the VPAT request, you stall your own deal. Plan for both and keep them current together.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Drafts HECVAT 4 answers from your existing control library, so the work shifts from writing to reviewing and approving
- Follows the HECVAT 4 conditional routing, so you answer the sections your product actually triggers instead of the whole workbook
- Keeps an inventory of AI systems and features with documented purpose, limitations and human oversight, which the Artificial Intelligence section now requires
- Maps one control to every framework that asks for it, including HECVAT, SIG, SIG Lite, CAIQ, SOC 2 and ISO 27001
- Tracks the twelve month freshness window institutions expect, and flags answers that have gone stale before a buyer does
- Holds subprocessor lists, retention and deletion behavior and breach notification timelines as evidence rather than as claims
- Separates the education specific commitments institutions require from your general privacy policy language
- Keeps a reusable response history, so the fourth HECVAT costs a fraction of the first
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
HECVAT 4 section reference
What each HECVAT 4 section asks for, and the evidence that actually answers it
Nearly every HECVAT comparison table published today is organized around Lite versus Full versus On-Premise, a split that HECVAT 4 retired in February 2025. That axis tells a vendor nothing useful. The axis that decides whether you finish the workbook this week is section by section: what is being asked, which artifact answers it, and where vendors reliably stall. The Artificial Intelligence row is the newest and the most common hard stop in 2026.
| HECVAT 4 section | What it asks you to show | Evidence that answers it | Where vendors stall |
|---|---|---|---|
| Organization | Company level security program: policies, ownership, staff training, incident response, insurance | Approved policy set with review dates, security awareness training records, incident response plan and test results | Policies exist, but nobody can show they were reviewed this year or that staff actually completed training |
| Product | How the product handles institutional data: authentication, SSO, roles, logging, retention and deletion | SSO and MFA configuration, role definitions, audit log samples, documented retention and deletion behavior | Retention and deletion get answered from intent rather than from what the product does today |
| Infrastructure | Hosting, network controls, encryption, vulnerability management, backup and recovery | Architecture description, encryption standards in transit and at rest, scan and patch cadence, restore test evidence | Hosting and subprocessor detail stays vague, and a restore has never actually been tested end to end |
| IT Accessibility | WCAG conformance, assistive technology support, accessibility testing and remediation practice | Accessibility conformance report, documented testing method, remediation backlog with timelines | Teams answer this section and assume it replaces the VPAT request. Institutions still ask for both. |
| Case-Specific | Extra blocks triggered by what you handle: payment data, PHI, research data, minors, on-premise deployment | The framework evidence you already hold for PCI, HIPAA or FERPA scope, plus deployment documentation | Vendors answer every case-specific block instead of letting the Start Here routing decide which ones apply |
| Artificial Intelligence | Whether the product uses AI, what it does, training data, human oversight and the controls an institution gets | AI system inventory, documented purpose and limitations, training data provenance, human oversight records, opt-out controls | New in HECVAT 4 and the most common hard stop. AI features shipped long before anyone built an inventory or oversight record to point at. |
| Privacy | Data collected, sharing, subprocessors, student data protections, breach notification | Records of processing, subprocessor list, DPA terms, education specific commitments, notification timelines | Student data commitments get answered from the general privacy policy rather than the education specific terms institutions require |
Section names and the seven section structure reflect HECVAT 4, current version 4.1.6 as listed by EDUCAUSE on July 22, 2026. Question counts vary by the routing your product triggers, so the roughly 321 questions in the full workbook is a ceiling rather than what most vendors answer.
Good questions
Questions about HECVAT
Keep reading
Guides that go deeper on this framework
Best HECVAT software for higher ed vendors
The four categories of tooling that claim to answer a HECVAT, what each one actually does, and where every category stops.
Read the guideBest security questionnaire automation software
How the questionnaire response tools compare on format coverage, portal support and answer accuracy, with reported pricing.
Read the guideAutomating security questionnaires
How SIG, CAIQ and bespoke questionnaires get answered from an evidence-backed control library instead of from scratch.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification