Purpose: Select questions according to the vendor’s service, access, data, criticality, and concentration. A questionnaire is evidence gathering, not automatic approval.
Question groups
Service and ownershipWhat service is provided, who owns it, and which business process depends on it?
DataWhat information is collected, stored, transmitted, retained, returned, or destroyed?
Access and integrationWhat accounts, administrative access, APIs, agents, network connections, or physical access are required?
Security governanceWho is accountable, how are risks assessed, and how are exceptions managed?
Identity and accessHow are privileged access, multifactor authentication, joiners, movers, leavers, and reviews handled?
Vulnerability and changeHow are software changes, vulnerabilities, dependencies, and urgent fixes managed?
Incident notificationWhat events trigger notice, how quickly, and what information is supplied?
Continuity and recoveryWhat dependencies, backups, recovery objectives, tests, and manual alternatives exist?
SubcontractorsWhich sub-processors or fourth parties are used, and how are they governed?
ExitHow are access, data, integrations, and transition support handled at termination?
Worked examples
| Example | Context / Rating | Condition / Safeguard | Decision / Result |
|---|
How to use this page
- Tier the vendor before choosing question depth.
- Ask for evidence only where it changes the decision.
- Record gaps and compensating measures.
- Put critical commitments into the contract.
- Reassess after material service, ownership, or integration change.
Cautions
- A certificate does not answer every service-specific risk question.
- Generic yes/no answers require follow-up.
- Questionnaires should not request confidential technical detail without a clear need.
Educational use: Tailor the language and decision authority to the organization. This page is not a certification, legal opinion, security assessment or substitute for professional advice.
Frequently asked questions
Can a small organization use this tool?
Yes. Reduce the number of fields or questions, but retain the scenario, business consequence, accountable owner, decision and review date.
Does this replace professional advice?
No. It is an educational structure. Legal, insurance, compliance, cybersecurity and other professional decisions may require qualified advice.
How often should it be updated?
Update it when the related service, supplier, data, threat conditions, controls, incident history or business priorities change materially.