Vendor security questionnaires that actually work
A vendor security questionnaire works when it is short, matched to what the vendor can reach, and asks for evidence rather than yes or no. Tier the vendor first, then ask the 15 to 20 questions that carry the signal. For many vendors, a current SOC 2 report or ISO 27001 certificate with the right scope already answers most of them.
Why 300-question questionnaires fail
The vendor’s sales engineer pastes answers from the last questionnaire. Nearly everything comes back “yes”. Your side then has 300 answers from each of 80 vendors to read, so nobody reads them. The length hides the few answers that would have changed a decision.
Tier the vendor before you ask anything
What you ask depends on what the vendor can reach. A catering supplier needs a one-page form. A support firm with remote admin access to your servers needs the full set and evidence behind it. Tiering by data and access is the first step of any vendor risk management programme.
The questions that carry most of the signal
- Is multi-factor authentication enforced on all admin and remote access, and which accounts are exempt?
- Which of your staff can access our data, and how often is that list reviewed?
- In which countries is our data stored, and from where can it be accessed?
- Which subprocessors touch our data? Send the current list.
- Is our data encrypted at rest and in transit, and who controls the keys?
- How is our data separated from other customers’ data?
- How quickly were critical vulnerabilities actually patched last quarter? Real figures, not the policy target.
- When did you last restore from backup, and what was restored?
- Which security logs do you keep, and for how long?
- How soon will you tell us about an incident affecting our data, and who calls us?
- What was your last significant security incident, and what changed after it?
- When was your last independent penetration test, and can we see the summary?
- Which independent reports do you hold, and what exactly do they cover?
- How is access removed when one of your staff leaves?
- What access will your staff or tools have into our systems?
- How is our data returned or deleted when the contract ends, and will you confirm it in writing?
Add a few for your sector or for AI suppliers, not forty. For the other side of the table, see answering the AI security questionnaire.
Ask for evidence, not yes or no
“Do you enforce MFA?” gets a yes from almost everyone. “Send the MFA policy from your identity provider and list the accounts excluded from it” gets you the truth. The exclusions are the answer.
A confident yes to everything, with nothing behind it, is itself a finding.
When to accept a SOC 2 or ISO 27001 report instead
A SOC 2 report is issued by a CPA firm under the AICPA SOC framework. Accept it when it is a Type 2, its period ended within the last year, and it names the service you buy. Read the exceptions and the complementary user entity controls. Those are the controls the report assumes you run.
An ISO/IEC 27001 certificate covers a stated scope. Check that it was issued by an accredited certification body and that the scope covers your service, not one office or one product line.
Then ask only the gaps: data location, subprocessors, notification clock and exit. A report does not move your own duties. Under PIPEDA you stay accountable for personal information a vendor processes for you. How the two reports differ is covered in SOC 2 vs ISO 27001.
Questions we are asked
How many questions should a vendor security questionnaire have?
For most vendors, 15 to 20. The top tier may need more follow-up, but extra questions should come from gaps in the evidence, not from a longer template.
Can a SOC 2 report replace a questionnaire?
Often, for most of it. If the report is current, is a Type 2, and covers the service you actually buy, it answers the control questions better than self-reported answers. Ask separately about what it leaves out.
What if a vendor refuses to answer?
A refusal is an answer. Record it, decide whether the tier lets you proceed without the information, and if not, make the missing item a contract condition or choose another vendor.
How often should we send it again?
Every year for the top tier, at renewal for the middle tier, and only on a trigger for the lowest: a breach notice, a change of ownership, or a request for more access.
Getting a questionnaire that fits
Send us the questionnaire you use today and a rough list of vendors. The reply says what to cut and what to ask for as evidence. More pieces are indexed at writing.