Overview
Before you hand a vendor your data or let them connect to your network, you need to know what their security looks like from the inside. This questionnaire gives you a structured way to evaluate vendors across the areas that matter most: how they handle your data, who has access, how they respond to incidents, and whether they can prove compliance when asked. It is designed to be practical for both the team sending it and the vendor filling it out.
Assessment Domains
- Organizational security governance and leadership
- Data protection, encryption, and classification practices
- Identity and access management controls
- Network security architecture and segmentation
- Incident response capabilities and breach history
- Business continuity and disaster recovery readiness
- Compliance certifications and audit reports
- Subprocessor and fourth-party risk management
Risk Tiering Framework
| Tier | Criteria | Assessment depth |
|---|---|---|
| Critical | Processes or stores sensitive data, has network access, or supports revenue-critical functions | Full questionnaire, SOC 2 report review, onsite or virtual assessment |
| High | Accesses internal systems or handles moderate-sensitivity data | Full questionnaire plus evidence requests |
| Medium | Limited data access, no direct system connectivity | Abbreviated questionnaire with self-attestation |
| Low | No data access, no system connectivity, commodity services | Automated risk scoring with periodic reassessment |
How to Evaluate Responses
Look beyond yes-or-no answers. Ask for evidence: screenshots of configurations, copies of policies, recent penetration test summaries, and SOC 2 or ISO 27001 reports. Pay close attention to how the vendor handles access reviews, vulnerability patching timelines, and incident notification commitments. A vendor that says they encrypt data at rest but cannot specify the algorithm or key management approach is a red flag. Score each domain on a 1-to-5 maturity scale and set minimum thresholds per risk tier.
Common Vendor Red Flags
- No SOC 2, ISO 27001, or equivalent third-party audit in the past 18 months
- Inability to provide a documented incident response plan
- Shared credentials or no MFA for administrative access
- No encryption at rest or in transit for customer data
- Refusal to disclose subprocessors or fourth-party dependencies
- No defined SLA for breach notification timelines
Integration with Your TPRM Program
This questionnaire works best when it is part of a broader third-party risk management lifecycle. Use it during vendor onboarding, then schedule periodic reassessments based on the risk tier. Critical vendors should be reassessed annually at minimum, with continuous monitoring through tools that track breach disclosures, certificate expirations, and dark-web mentions. Store all vendor assessments in a central repository so your procurement, legal, and security teams all work from the same data.
