Overview
Every third-party relationship introduces risk. Suppliers, partners, and service providers all have access to something valuable: your data, your systems, or your customers. This questionnaire gives you a standard way to evaluate the security, privacy, and business continuity capabilities of a third party before onboarding and throughout the relationship.
The structure follows the supplier risk practices in NIST SP 800-161 Revision 1, which covers cybersecurity supply chain risk management. Below you will find sample questions with the evidence to request, a short form for low-risk vendors, and a worked scoring example.
Questionnaire Sections
- Company profile and business context
- Information security governance and policy framework
- Data handling, classification, and protection practices
- Access control and authentication mechanisms
- Network architecture and perimeter security
- Vulnerability management and patching cadence
- Incident response capabilities and breach history
- Business continuity and disaster recovery planning
- Compliance certifications and regulatory obligations
- Subcontractor and fourth-party management practices
Sample Questions and the Evidence to Request
| Domain | Question | Evidence to request |
|---|---|---|
| Governance | Who is accountable for information security, and to whom do they report? | Org chart or named role in the security policy |
| Data protection | Where is our data stored, and is it encrypted at rest and in transit? | Architecture diagram, encryption standard, region list |
| Access control | Is MFA enforced for all staff and administrators who can reach our data? | Identity provider policy screenshot or audit report section |
| Vulnerability management | What are your remediation timelines by severity, and do you meet them? | Policy plus a recent metrics extract |
| Incident response | How quickly will you notify us of an incident affecting our data? | Contract clause and incident response plan summary |
| Business continuity | What are your recovery time and recovery point objectives, and when were they last tested? | Test report or summary |
| Compliance | Which independent attestations do you hold, and what exceptions were noted? | SOC 2 Type II report or ISO 27001 certificate and scope |
| Subcontractors | Which subprocessors handle our data, and how do you assess them? | Subprocessor list and assessment procedure |
Risk Scoring Model
| Domain | Weight | Scoring criteria |
|---|---|---|
| Data Protection | 25% | Encryption, classification, DLP, retention policies |
| Access Control | 20% | MFA enforcement, RBAC, privileged access management |
| Incident Response | 15% | Documented IRP, testing frequency, notification SLAs |
| Compliance | 15% | Active certifications, recent audit results, remediation tracking |
| Business Continuity | 15% | RTO/RPO targets, backup testing, failover capabilities |
| Subcontractor Risk | 10% | Fourth-party inventory, flow-down requirements, monitoring |
Filled Example: Scoring One Vendor
| Domain | Weight | Score (1 to 5) | Weighted |
|---|---|---|---|
| Data Protection | 25% | 4 | 1.00 |
| Access Control | 20% | 3 | 0.60 |
| Incident Response | 15% | 2 | 0.30 |
| Compliance | 15% | 4 | 0.60 |
| Business Continuity | 15% | 3 | 0.45 |
| Subcontractor Risk | 10% | 2 | 0.20 |
| Total | 100% | 3.15 of 5 |
Reading the Score
The example above is a fictional payroll SaaS provider. A total of 3.15 looks acceptable, but the domain scores tell the real story: incident response and subcontractor management both scored 2. Set a rule that any domain at 2 or below needs a remediation plan regardless of the total, otherwise a strong certification can hide a weak notification process. A simple set of bands works for most programs: 4.0 and above approve, 3.0 to 3.9 approve with conditions, below 3.0 escalate to the risk owner. Agree the bands before you score, not after.
Contextualizing for Your Organization
Not every vendor needs the same level of scrutiny. Tailor the depth of your questionnaire to the risk tier of the relationship. A cloud provider hosting customer PII deserves the full questionnaire, evidence requests, and possibly an on-site assessment. A marketing agency with no system access might only need a short-form self-attestation. The key is having a consistent framework that scales with risk without creating unnecessary friction for low-risk partnerships.
Short-Form Questionnaire for Low-Risk Vendors
- 1. What services will you provide, and will you access any of our systems or data?
- 2. Do you hold a current SOC 2 Type II report, ISO 27001 certificate, or equivalent?
- 3. Is MFA enforced for every account that can reach customer data?
- 4. Is customer data encrypted at rest and in transit?
- 5. Have you had a security incident affecting customer data in the last 24 months?
- 6. How quickly will you notify us of an incident that affects our data?
- 7. Do you use subprocessors for our data, and can you share the list?
- 8. Where will our data be stored and processed?
- 9. Do staff receive security training at least once a year?
- 10. Who is your security contact, and how do we reach them out of hours?
Evidence and Verification
Request supporting documentation for critical answers: SOC 2 Type II reports, penetration test summaries, incident response plans, and data flow diagrams. Cross-reference self-reported answers with publicly available information like breach disclosures, security ratings, and compliance databases. Consider using automated third-party risk rating services to supplement the questionnaire with continuous monitoring data.
Ongoing Monitoring
The initial assessment is just the starting point. Establish a reassessment cadence based on risk tier: annually for critical vendors, every 18 months for high-risk, and every two to three years for medium and low-risk relationships. Between assessments, monitor for trigger events like data breaches, leadership changes, financial instability, or regulatory actions that should prompt an ad-hoc review.
