Skip to main content

Free questionnaire

Vendor security questionnaire

A proportionate supplier questionnaire that gets real answers, tiered by the risk the vendor actually presents.

XLSX

Get your copy

Three fields. No follow-up sequence unless you ask for one.

We record the page and campaign you arrived from. See our privacy policy.

What is inside

  • Tiered question sets by vendor criticality
  • Scoring model and escalation thresholds
  • Contract clause suggestions
  • Reassessment cadence

Who it is for

Procurement and third-party risk teams. It is written to be usable on its own, without a consultant sitting next to you. If you want one anyway, that is what the consultation is for.

Why most vendor questionnaires do nothing

Third party risk assessment in practice is frequently a hundred question spreadsheet, answered by the vendor's sales engineer, filed, and never referred to again. It generates evidence that a process ran without generating any information about risk.

There are three reasons it fails. The questions are generic, so they are answered generically. There is no verification step, so a yes is worth exactly as much as the vendor's willingness to type yes. And there is no consequence attached to the answers, so nothing changes based on them.

This questionnaire is built to avoid all three. It is shorter than most, deliberately, because a shorter set of questions that get read is worth more than a long set that get filed.

The questions that actually separate suppliers

Ask what happens to your data when the contract ends. The answer reveals whether they have thought about data lifecycle at all, and it is the question most often met with silence.

Ask how many people at the vendor can access your data, and how that number is enforced rather than intended. Any supplier who answers with a policy rather than a mechanism is telling you the control is aspirational.

Ask when they were last tested independently, by whom, and whether you can see the scope. Not the report, which they may not be able to share, but the scope, which they should be able to.

Ask about their own suppliers. Your fourth party risk is real and almost never assessed. A vendor who cannot name the sub-processors handling your data has not managed that risk on your behalf.

Ask what their notification commitment is if they are breached, in hours, and what triggers it. A contract that says promptly means nothing when you are the one with a six hour CERT-In clock running.

How to weight the answers

Not every question deserves equal weight, and treating them equally is how a critical supplier passes on the strength of good answers to unimportant questions.

Weight by what the supplier can actually reach. A vendor with production database access and a vendor with your marketing email list are not comparable risks regardless of how they score. Segment your suppliers by access first, then apply the questionnaire proportionately.

Treat evidence as worth more than assertion. A supplier who attaches a certificate scope statement, a penetration test summary or an architecture note has told you something. A supplier who ticks yes has told you they can tick.

Treat a candid no better than an evasive yes. A supplier who says they do not do something, and explains what they do instead, is easier to manage than one whose answers are uniformly reassuring.

Making the assessment change something

An assessment with no consequence is theatre. Before you send the questionnaire, decide what outcomes are available: proceed, proceed with contractual conditions, proceed with compensating controls on your side, or decline.

Contractual conditions are the most useful and the least used. Breach notification timelines in hours, audit rights, sub-processor change notification, data location commitments and deletion obligations at termination all belong in the contract rather than in the questionnaire response, because only one of those is enforceable.

Set a reassessment trigger rather than an annual date. Suppliers should be reassessed when their access changes, when they have an incident, when they change sub-processors, or when the service materially changes. An annual calendar reminder tests the supplier as they were.

Finally, record the decision. The point of the exercise is a defensible judgement about a supplier, and a questionnaire response with no conclusion attached is not one.

Segmenting your suppliers before you assess them

Assessing every supplier to the same depth is how organisations end up assessing none of them properly. Segment first, by what the supplier can actually reach.

Critical suppliers hold production data, have privileged access, or sit in a path where their unavailability stops your business. These deserve the full questionnaire, evidence rather than assertion, contractual conditions and an exercised audit right.

Significant suppliers hold personal data but not the crown jewels, or their failure is disruptive rather than existential. Full questionnaire, evidence for the answers that matter, contractual conditions.

Everyone else gets a short screen and a contract clause. A stationery supplier does not need a hundred questions, and pretending otherwise is what makes the process collapse under its own weight.

Fourth party risk, and why it belongs here

Your supplier's suppliers hold your data too, and almost no assessment reaches them. A vendor who cannot name their sub-processors has not managed that risk on your behalf, and under the DPDP Act you remain accountable regardless of how many layers down the processing happens.

Ask for the list, ask to be notified of changes, and put the notification requirement in the contract rather than in the questionnaire. Concentration is worth checking too: several of your suppliers are probably built on the same underlying platform, which is a correlated failure your individual assessments will not surface.