The Third-Party Risk Questionnaire: What to Ask and Why
A third-party security questionnaire collects a vendor's self-reported security posture as the first step of due diligence. Done well, it is a fast filter that surfaces the areas needing evidence and the vendors needing deeper review. Done badly โ a 300-question spreadsheet sent to every supplier regardless of risk โ it produces questionnaire fatigue, rushed answers, and a false sense of assurance. The fix is scoping the questionnaire to the vendor's risk tier, asking questions that map to real controls (data handling, access, compliance, incident response, sub-processors), requesting evidence for high-risk areas, and having a clear rule for what an answer triggers. Standardised frameworks (such as SIG or CAIQ) help, but the discipline that matters is turning answers into decisions.
The security questionnaire is the workhorse of third-party risk management, and also its most abused tool. Sent thoughtfully, it is a fast filter that tells you which vendors need a closer look. Sent as a 300-question spreadsheet to every supplier, it produces fatigue, rushed answers, and assurance theatre. The difference is scoping and decision rules.
What to ask
Map questions to the controls that actually predict risk:
- Data handling: what data is accessed, where it is stored/processed, encryption, retention, deletion.
- Access & authentication: MFA, least privilege, tenant segregation.
- Compliance: SOC 2 Type II, ISO 27001, relevant regulatory attestations.
- Incident response: breach-notification timelines and process.
- Sub-processors: who they rely on and how they govern them.
- Business continuity: backup and disaster recovery.
Avoiding questionnaire fatigue
Scope depth to the vendor's risk tier โ a low-risk supplier should not get the same list as one handling regulated data. Reuse standardised frameworks (SIG, CAIQ) so vendors can answer once, accept recent attestations (SOC 2, ISO 27001) in place of re-answering, and spend your review time on the high-risk vendors where answers change decisions.
Answers are claims, not facts
Treat questionnaire responses as self-reported. For higher-risk vendors, require evidence โ a current SOC 2 Type II report, ISO 27001 certificate, pen-test summary โ to corroborate. The questionnaire tells you where to look; evidence tells you whether to trust.
Turn answers into decisions
Decide in advance what answers trigger: blockers, remediation-before-onboarding, contractual commitments, or accept-with-monitoring. Pre-agreed thresholds turn a pile of answers into approve, approve-with-conditions, or reject โ otherwise you have generated paperwork, not risk management.
Structure the review with the free Vendor Risk tool โ and track findings in the Risk Register.
Frequently asked questions
What goes in it? Questions mapped to data handling, access, compliance, incident response, sub-processors and continuity โ scoped to risk tier.
How to avoid fatigue? Tier and scope, reuse SIG/CAIQ, accept attestations, focus effort on high-risk vendors.
Trust the answers? They are self-reported claims โ require evidence for higher-risk vendors.
Turn into decisions? Pre-agree what each answer triggers: block, remediate, contract, or accept-with-monitoring.
Ready to practise the decisions these articles describe?
Run a free War Room โ