Security work has taught me to distrust assumptions that have not been tested recently.
A diagram can say encryption is in place while the restore job fails because the key lives in a different account. A firewall rule can carry a comment that says temporary for six months. A control can look complete in a review pack while the owner has changed and nobody updated the evidence.
The fix is not to become cynical about every document. The fix is to connect each control to a verification date, an owner and a result someone can repeat. If a rule is temporary, the ticket needs a real expiry date. If a backup depends on a key, the restore test needs to prove that dependency still works.
Assumptions are useful when they are named. They become risky when they sit silently inside diagrams, tickets and old decisions.
Before a security review, I try to ask a simple question: what have we actually checked, and what are we only carrying forward because it was true last time?