# The Third-Party Risk Questionnaire: What to Ask and Why > Security questionnaires are the backbone of third-party risk management — when they are focused. What to include, how to avoid questionnaire fatigue, and how to turn answers into decisions. Source: https://playciso.com/blog/third-party-risk-questionnaire-guide · Published: 2026-09-26 · Publisher: PlayCISO (https://playciso.com) --- The security questionnaire is the workhorse of third-party risk management, and also its most abused tool. Sent thoughtfully, it is a fast filter that tells you which vendors need a closer look. Sent as a 300-question spreadsheet to every supplier, it produces fatigue, rushed answers, and assurance theatre. The difference is scoping and decision rules. ## What to ask Map questions to the controls that actually predict risk: - Data handling: what data is accessed, where it is stored/processed, encryption, retention, deletion. - Access & authentication: MFA, least privilege, tenant segregation. - Compliance: SOC 2 Type II, ISO 27001, relevant regulatory attestations. - Incident response: breach-notification timelines and process. - Sub-processors: who they rely on and how they govern them. - Business continuity: backup and disaster recovery. ## Avoiding questionnaire fatigue Scope depth to the vendor's risk tier — a low-risk supplier should not get the same list as one handling regulated data. Reuse standardised frameworks (SIG, CAIQ) so vendors can answer once, accept recent attestations (SOC 2, ISO 27001) in place of re-answering, and spend your review time on the high-risk vendors where answers change decisions. ## Answers are claims, not facts Treat questionnaire responses as self-reported. For higher-risk vendors, require evidence — a current SOC 2 Type II report, ISO 27001 certificate, pen-test summary — to corroborate. The questionnaire tells you where to look; evidence tells you whether to trust. ## Turn answers into decisions Decide in advance what answers trigger: blockers, remediation-before-onboarding, contractual commitments, or accept-with-monitoring. Pre-agreed thresholds turn a pile of answers into approve, approve-with-conditions, or reject — otherwise you have generated paperwork, not risk management. Structure the review with the free [Vendor Risk tool →](/tools/vendor-risk) and track findings in the [Risk Register](/tools/risk-register). ## Frequently asked questions **What goes in it?** Questions mapped to data handling, access, compliance, incident response, sub-processors and continuity — scoped to risk tier. **How to avoid fatigue?** Tier and scope, reuse SIG/CAIQ, accept attestations, focus effort on high-risk vendors. **Trust the answers?** They are self-reported claims — require evidence for higher-risk vendors. **Turn into decisions?** Pre-agree what each answer triggers: block, remediate, contract, or accept-with-monitoring.