Back to Resources
Third-Party Risk Questionnaire: visual preview
Questionnaire

Third-Party Risk Questionnaire

Standardized Vendor & Partner Security Evaluation

Overview

Every third-party relationship introduces risk. Suppliers, partners, and service providers all have access to something valuable: your data, your systems, or your customers. This questionnaire gives you a standard way to evaluate the security, privacy, and business continuity capabilities of a third party before onboarding and throughout the relationship.

The structure follows the supplier risk practices in NIST SP 800-161 Revision 1, which covers cybersecurity supply chain risk management. Below you will find sample questions with the evidence to request, a short form for low-risk vendors, and a worked scoring example.

Questionnaire Sections

  • Company profile and business context
  • Information security governance and policy framework
  • Data handling, classification, and protection practices
  • Access control and authentication mechanisms
  • Network architecture and perimeter security
  • Vulnerability management and patching cadence
  • Incident response capabilities and breach history
  • Business continuity and disaster recovery planning
  • Compliance certifications and regulatory obligations
  • Subcontractor and fourth-party management practices

Sample Questions and the Evidence to Request

DomainQuestionEvidence to request
GovernanceWho is accountable for information security, and to whom do they report?Org chart or named role in the security policy
Data protectionWhere is our data stored, and is it encrypted at rest and in transit?Architecture diagram, encryption standard, region list
Access controlIs MFA enforced for all staff and administrators who can reach our data?Identity provider policy screenshot or audit report section
Vulnerability managementWhat are your remediation timelines by severity, and do you meet them?Policy plus a recent metrics extract
Incident responseHow quickly will you notify us of an incident affecting our data?Contract clause and incident response plan summary
Business continuityWhat are your recovery time and recovery point objectives, and when were they last tested?Test report or summary
ComplianceWhich independent attestations do you hold, and what exceptions were noted?SOC 2 Type II report or ISO 27001 certificate and scope
SubcontractorsWhich subprocessors handle our data, and how do you assess them?Subprocessor list and assessment procedure

Risk Scoring Model

DomainWeightScoring criteria
Data Protection25%Encryption, classification, DLP, retention policies
Access Control20%MFA enforcement, RBAC, privileged access management
Incident Response15%Documented IRP, testing frequency, notification SLAs
Compliance15%Active certifications, recent audit results, remediation tracking
Business Continuity15%RTO/RPO targets, backup testing, failover capabilities
Subcontractor Risk10%Fourth-party inventory, flow-down requirements, monitoring

Filled Example: Scoring One Vendor

DomainWeightScore (1 to 5)Weighted
Data Protection25%41.00
Access Control20%30.60
Incident Response15%20.30
Compliance15%40.60
Business Continuity15%30.45
Subcontractor Risk10%20.20
Total100%3.15 of 5

Reading the Score

The example above is a fictional payroll SaaS provider. A total of 3.15 looks acceptable, but the domain scores tell the real story: incident response and subcontractor management both scored 2. Set a rule that any domain at 2 or below needs a remediation plan regardless of the total, otherwise a strong certification can hide a weak notification process. A simple set of bands works for most programs: 4.0 and above approve, 3.0 to 3.9 approve with conditions, below 3.0 escalate to the risk owner. Agree the bands before you score, not after.

Contextualizing for Your Organization

Not every vendor needs the same level of scrutiny. Tailor the depth of your questionnaire to the risk tier of the relationship. A cloud provider hosting customer PII deserves the full questionnaire, evidence requests, and possibly an on-site assessment. A marketing agency with no system access might only need a short-form self-attestation. The key is having a consistent framework that scales with risk without creating unnecessary friction for low-risk partnerships.

Short-Form Questionnaire for Low-Risk Vendors

  • 1. What services will you provide, and will you access any of our systems or data?
  • 2. Do you hold a current SOC 2 Type II report, ISO 27001 certificate, or equivalent?
  • 3. Is MFA enforced for every account that can reach customer data?
  • 4. Is customer data encrypted at rest and in transit?
  • 5. Have you had a security incident affecting customer data in the last 24 months?
  • 6. How quickly will you notify us of an incident that affects our data?
  • 7. Do you use subprocessors for our data, and can you share the list?
  • 8. Where will our data be stored and processed?
  • 9. Do staff receive security training at least once a year?
  • 10. Who is your security contact, and how do we reach them out of hours?

Evidence and Verification

Request supporting documentation for critical answers: SOC 2 Type II reports, penetration test summaries, incident response plans, and data flow diagrams. Cross-reference self-reported answers with publicly available information like breach disclosures, security ratings, and compliance databases. Consider using automated third-party risk rating services to supplement the questionnaire with continuous monitoring data.

Ongoing Monitoring

The initial assessment is just the starting point. Establish a reassessment cadence based on risk tier: annually for critical vendors, every 18 months for high-risk, and every two to three years for medium and low-risk relationships. Between assessments, monitor for trigger events like data breaches, leadership changes, financial instability, or regulatory actions that should prompt an ad-hoc review.

Frequently asked questions