Scrutineer.ai

Scrutineer · By framework

HECVAT questionnaire software for HECVAT 4, Lite and Full

The HECVAT Lite and Full choice that most published guides still describe was retired. HECVAT 4 replaced all three workbooks with one conditional questionnaire, and it now asks about AI and accessibility as well.

Scrutineer holds your controls and evidence once, then drafts HECVAT answers from them, so a university request becomes a review pass instead of two weeks of retyping.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with HECVAT

The HECVAT Lite and Full choice no longer exists

This is the single most common mistake in HECVAT guidance being republished right now. HECVAT 4 consolidated the Full, Lite and On-Premise workbooks into one instrument in February 2025, and EDUCAUSE lists 4.1.6 as current as of July 22, 2026. Instead of picking a version, you complete a core set of questions and a Start Here tab routes you through the rest based on solution type, deployment model and the data you touch. A vendor who downloads a HECVAT Lite template today is filling in a retired form, and an institution that asks for one is usually asking out of habit rather than policy. The practical effect is good news: the conditional routing means a low risk product answers far less than the roughly 321 questions the full workbook contains.

HECVAT 4 now asks what your AI does, and most vendors have no artifact for it

Artificial Intelligence is a dedicated section in HECVAT 4, alongside Organization, Product, Infrastructure, IT Accessibility, Case-Specific and Privacy. If your product ships any AI feature, higher education procurement now expects an inventory of it, a documented purpose and its limitations, something credible about training data provenance, evidence of human oversight, and the controls an institution can use to opt out. This is where 2026 HECVATs stall, because AI features shipped fast and the governance artifacts behind them usually do not exist yet. Scrutineer runs that inventory and oversight evidence from the same control set as the rest of your program, so the AI section is answered rather than negotiated.

The accessibility section does not discharge the VPAT request

HECVAT 4 includes an IT Accessibility section covering WCAG conformance and assistive technology support, and a lot of vendors read that as replacing the accessibility paperwork. It does not. Institutions routinely require both a HECVAT and a VPAT or Accessibility Conformance Report for each product, on new purchases and on renewals, because the two answer different questions: HECVAT screens, the ACR documents conformance in detail. If you answer the HECVAT accessibility questions and then push back on the VPAT request, you stall your own deal. Plan for both and keep them current together.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Drafts HECVAT 4 answers from your existing control library, so the work shifts from writing to reviewing and approving
  • Follows the HECVAT 4 conditional routing, so you answer the sections your product actually triggers instead of the whole workbook
  • Keeps an inventory of AI systems and features with documented purpose, limitations and human oversight, which the Artificial Intelligence section now requires
  • Maps one control to every framework that asks for it, including HECVAT, SIG, SIG Lite, CAIQ, SOC 2 and ISO 27001
  • Tracks the twelve month freshness window institutions expect, and flags answers that have gone stale before a buyer does
  • Holds subprocessor lists, retention and deletion behavior and breach notification timelines as evidence rather than as claims
  • Separates the education specific commitments institutions require from your general privacy policy language
  • Keeps a reusable response history, so the fourth HECVAT costs a fraction of the first
HECVAT readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

HECVAT 4 section reference

What each HECVAT 4 section asks for, and the evidence that actually answers it

Nearly every HECVAT comparison table published today is organized around Lite versus Full versus On-Premise, a split that HECVAT 4 retired in February 2025. That axis tells a vendor nothing useful. The axis that decides whether you finish the workbook this week is section by section: what is being asked, which artifact answers it, and where vendors reliably stall. The Artificial Intelligence row is the newest and the most common hard stop in 2026.

HECVAT 4 section What it asks you to show Evidence that answers it Where vendors stall
Organization Company level security program: policies, ownership, staff training, incident response, insurance Approved policy set with review dates, security awareness training records, incident response plan and test results Policies exist, but nobody can show they were reviewed this year or that staff actually completed training
Product How the product handles institutional data: authentication, SSO, roles, logging, retention and deletion SSO and MFA configuration, role definitions, audit log samples, documented retention and deletion behavior Retention and deletion get answered from intent rather than from what the product does today
Infrastructure Hosting, network controls, encryption, vulnerability management, backup and recovery Architecture description, encryption standards in transit and at rest, scan and patch cadence, restore test evidence Hosting and subprocessor detail stays vague, and a restore has never actually been tested end to end
IT Accessibility WCAG conformance, assistive technology support, accessibility testing and remediation practice Accessibility conformance report, documented testing method, remediation backlog with timelines Teams answer this section and assume it replaces the VPAT request. Institutions still ask for both.
Case-Specific Extra blocks triggered by what you handle: payment data, PHI, research data, minors, on-premise deployment The framework evidence you already hold for PCI, HIPAA or FERPA scope, plus deployment documentation Vendors answer every case-specific block instead of letting the Start Here routing decide which ones apply
Artificial Intelligence Whether the product uses AI, what it does, training data, human oversight and the controls an institution gets AI system inventory, documented purpose and limitations, training data provenance, human oversight records, opt-out controls New in HECVAT 4 and the most common hard stop. AI features shipped long before anyone built an inventory or oversight record to point at.
Privacy Data collected, sharing, subprocessors, student data protections, breach notification Records of processing, subprocessor list, DPA terms, education specific commitments, notification timelines Student data commitments get answered from the general privacy policy rather than the education specific terms institutions require

Section names and the seven section structure reflect HECVAT 4, current version 4.1.6 as listed by EDUCAUSE on July 22, 2026. Question counts vary by the routing your product triggers, so the roughly 321 questions in the full workbook is a ceiling rather than what most vendors answer.

Good questions

Questions about HECVAT

HECVAT stands for the Higher Education Community Vendor Assessment Toolkit. It is a standardized security questionnaire that colleges and universities send to vendors before buying software that will touch institutional or student data. It was developed by EDUCAUSE with Internet2 and REN-ISAC, and it is maintained by EDUCAUSE today.
They were consolidated. HECVAT 4 replaced the separate Full, Lite and On-Premise workbooks with a single questionnaire in February 2025. You now complete a core set of questions and a Start Here tab routes you through the remaining sections based on your solution type, deployment model and the data you handle. Guidance still telling vendors to choose between Lite and Full is out of date.
EDUCAUSE lists HECVAT 4.1.6 as the current version as of July 22, 2026. The HECVAT 4 line launched on February 10, 2025, which is the release that consolidated the three workbooks and added the Artificial Intelligence and IT Accessibility sections. Published guides cite that launch build as both 4.0 and 4.1.5, so quote the version off the workbook you were sent rather than off an article. Point releases since then have refined wording and guidance rather than restructuring the instrument.
Reported effort for a first HECVAT is commonly 8 to 20 hours of work spread across security, engineering, legal and privacy. The range is wide because it depends on how much of your evidence already exists in a usable form. Vendors answering from a maintained control library rather than from scratch generally spend far less, and later HECVATs cost a fraction of the first one.
Yes. EDUCAUSE makes the HECVAT available at no cost to colleges and universities and to the vendors who sell to them. It is copyrighted by EDUCAUSE, and institutions may adapt it for their own nonprofit use. Any cost you incur is the internal time to answer it, or tooling you choose to speed that up.
Whoever has the most complete knowledge of the product, which in practice means several people. Security owns the Organization and Infrastructure sections, engineering owns Product, privacy or legal owns Privacy and the data protection terms, and the AI section usually needs whoever shipped the AI features. One person guessing across all seven sections is how inaccurate answers reach a buyer.
Not a central one. EDUCAUSE does not collect or host completed HECVATs. Vendors keep their own completed workbook and share it directly with institutions, either proactively during the sales process or on request. Publishing your current HECVAT on your own trust page or handing it over early is the practical way to get ahead of a procurement review.
Institutions are generally advised to ask for a HECVAT completed within the last twelve months, so treat it as an annual refresh. Update it sooner if something material changes: a new subprocessor, a new hosting region, an acquisition, a significant AI feature, or a change to how you retain or delete institutional data.
HECVAT assesses security and privacy risk, and VPAT documents accessibility conformance against standards such as WCAG and Section 508. HECVAT 4 includes an IT Accessibility section, but that is a screen rather than a substitute. Institutions commonly require both a HECVAT and a VPAT or Accessibility Conformance Report for each product, including at renewal.
There is no law requiring it, but in practice a great many institutions will not complete a purchase or a renewal without one, and vendor risk management is a stated top priority in the 2026 EDUCAUSE Top 10. Refusing tends to end the deal rather than shorten the review. Smaller vendors are expected to complete it too, though the conditional routing means a low risk product answers fewer questions.
No, and buying that way is the expensive mistake. A HECVAT is not a separate compliance program. It asks the same underlying questions as a SIG from a bank, a CAIQ from a cloud buyer and the control testing behind a SOC 2 audit: how you authenticate, what you log, how you encrypt, who has access, how you handle an incident, what your subprocessors do. When those answers live in one evidence-backed control library, a new questionnaire format becomes a mapping exercise rather than a rewrite. That is the difference between answering your fourth HECVAT this quarter in an afternoon and treating each one as a fresh project.
No, though it helps a great deal. Institutions still want the HECVAT because it asks product and education specific questions a SOC 2 report does not cover, including student data handling, accessibility and now AI. A current SOC 2 report makes many HECVAT answers straightforward to evidence, and attaching it alongside the workbook usually speeds up the review.
No. Scrutineer is readiness and response software, not a certifying body or an assessor. Nobody certifies a HECVAT: it is a self-reported questionnaire that an institution reviews and may challenge. What Scrutineer does is hold the controls and evidence behind each answer, draft the workbook from them, and keep it current so what you send is accurate and defensible.

Keep reading

Guides that go deeper on this framework

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification