Skip to content
  • Questionnaires
  • Scoring

Vendor risk assessment questionnaire: what to ask, and how to score the answers

Updated 8 min read

A vendor risk assessment questionnaire does two jobs. It gets the vendor to state, in writing, what controls they have. And it gives you a structure for judging whether that is enough. Most questionnaires do the first job badly and the second not at all: too many questions, none of them weighted, and a result that is a pile of PDFs rather than a decision.

This guide covers what to ask by risk tier, how the questions map to SOC 2, ISO/IEC 27001, NIST CSF and GDPR so the answers double as audit evidence, and a scoring method simple enough to explain and consistent enough to defend.

Three principles before the first question

  1. Ask in proportion to the risk. The vendor that hosts your production database and the vendor that supplies office plants do not get the same form. Tier first (see Vendor risk tiering: how to classify third parties and set a review cadence), then pick the question set for the tier.
  2. Ask for evidence, not adjectives. “Do you encrypt data at rest?” invites “yes”. “Describe how data at rest is encrypted and attach the relevant section of your most recent SOC 2 report or policy” invites something you can check.
  3. Decide how you will score before you send it. A questionnaire scored after the answers arrive is scored to the answers. Fix the weights and thresholds in advance and apply them to every vendor in the tier.

The domains that matter

Whatever framework you answer to, vendor security questions cluster into the same eight domains. The table shows where each domain lands in the frameworks most SMB buyers are held to, so a single questionnaire produces evidence for all of them.

DomainWhat you are checkingSOC 2 (TSC)ISO 27001:2022NIST CSF 2.0
GovernanceSomeone owns security; policies exist and are reviewedCC1, CC25.1, 5.2, 5.4GV.PO, GV.RR
Access controlLeast privilege, MFA, joiner/leaver process, admin accessCC6.1–CC6.35.15–5.18, 8.2, 8.5PR.AA
Data protectionEncryption in transit and at rest, classification, retention, deletionCC6.1, CC6.7, C15.12, 5.13, 8.10, 8.24PR.DS
Secure development & changeCode review, testing, separation of environments, change approvalCC8.18.25–8.32PR.PS
Vulnerability & patchingScanning cadence, patch SLAs, penetration testingCC7.18.8ID.RA, PR.PS
Incident responseDocumented process, notification commitments, testingCC7.3–CC7.55.24–5.28RS, RC
Continuity & resilienceBackups, restore testing, RTO/RPO, DR exercisesA15.29, 5.30, 8.13, 8.14RC.RP
Their own suppliersSub-processor list, their vendor assessments, contractual flow-downCC9.25.19–5.23GV.SC

Add a privacy domain wherever personal data is in scope: lawful basis and instructions, sub-processor authorisation, international transfers, data subject request support, breach notification timing, deletion at end of contract. Those map to GDPR Articles 28, 32, 33 and 44–49, and are covered in GDPR processor due diligence: vetting vendors that handle personal data.

What to ask, by tier

Critical and high tier: the full assessment

These vendors touch confidential or personal data, have privileged access, or would stop the business if they failed. Ask across all eight domains plus privacy, and ask for evidence with each section. A representative set:

  • Do you hold a current SOC 2 Type II report or ISO/IEC 27001 certificate? Attach the report, or the certificate and statement of applicability, and state the scope.
  • Who is accountable for information security, and how often are policies reviewed and approved?
  • How is access to customer data restricted, logged and reviewed? Is MFA enforced for all staff and for administrative access?
  • How is customer data encrypted in transit and at rest? Who manages the keys?
  • Describe your vulnerability management: scanning frequency, remediation SLAs by severity, and the date and scope of your last independent penetration test. Attach the summary.
  • Describe your incident response process. Within how many hours will you notify us of a confirmed security incident affecting our data? Is this in the contract?
  • What are your recovery time and recovery point objectives for the service we use? When was recovery last tested, and what was the result?
  • List the sub-processors and hosting providers involved in delivering the service, and how you assess them. How much notice do we get before a change?
  • Where is our data stored and processed? What transfer mechanism applies to any international transfer?
  • Have you had a security incident affecting customer data in the last 36 months? If so, what changed as a result?

Medium tier: the short form

Medium-tier vendors handle internal or limited personal data, or provide a service you could replace with effort. Fifteen to twenty-five questions: one or two per domain, with evidence requested only for certification, encryption, incident notification and sub-processors. Accept a recent SIG Lite, CAIQ or public trust-centre page in place of answers where it covers the same ground.

Low tier: confirmation, not assessment

Low-tier vendors see no confidential data and hold no access. Confirm the contract terms, record the tier and the reason, and move on. A questionnaire here costs the vendor time and teaches your own team that questionnaires are a formality.

A scoring method you can explain

The purpose of scoring is consistency, not precision. Two people assessing the same vendor with the same evidence should reach the same rating, and the rating should be explicable to an auditor in a sentence. The method below has three parts.

1. Score each answer on a fixed scale

ScoreMeaningExample
0Control absent, or no answer“We do not perform penetration tests.”
1Control claimed but partial, informal, or unevidenced“We encrypt data at rest.” (no detail, nothing attached)
2Control in place, described specifically, and evidencedAES-256 at rest via provider-managed keys; SOC 2 report section CC6.1 attached
N/ANot applicable to this service; excluded from the maximumPayment card handling for a vendor that never sees cards

2. Weight each question by how much it matters

Weight questions 1, 2 or 3 according to how much the control matters for this vendor’s tier and data. Encryption and access control weigh 3 for a vendor holding customer records and 1 for one holding marketing copy. Set the weights per tier template, not per vendor, so the same vendor type is always scored the same way.

3. Express the result as a percentage, and set thresholds

Score = sum of (answer score × weight) ÷ sum of (2 × weight) for all applicable questions. Then apply thresholds fixed in advance:

  • 85% and above: accept.
  • 60–84%: accept with conditions — the specific gaps, a remediation date, or a compensating control on your side.
  • Below 60%: reject, or escalate for a documented risk acceptance by someone senior enough to own it.

Two refinements keep the method honest. First, some questions are knock-outs: a critical-tier vendor with no MFA on administrative access or no breach-notification commitment fails regardless of the percentage. List the knock-outs in the template. Second, any override of the computed rating needs a written reason and an approver, and the original score stays in the record.

Running the questionnaire without chasing

  • Send it with a deadline and a named contact at the vendor, and say what decision depends on it. Questionnaires without a consequence sit in inboxes.
  • Let the vendor answer once and reuse it. Ask for their existing SOC report or standard questionnaire first; only ask your own questions for the gaps.
  • Review answers against evidence as they arrive, not at the end. A “yes” with nothing attached goes back with a request the same day.
  • Record the score, the decision and the date together. The questionnaire is evidence only alongside the judgement made on it.
  • Schedule the next one when you close this one. Reassessment cadence comes from the tier; the record should show the next due date.

Where to go next

The questionnaire is step three of the process in Vendor due diligence: a practical guide for small and mid-sized businesses. For how tiering should set the depth of the questionnaire, read Vendor risk tiering: how to classify third parties and set a review cadence. If you are preparing for a specific audit, SOC 2 vendor management: what auditors expect from your third-party programme and ISO 27001 supplier relationships: meeting Annex A 5.19–5.23 with evidence explain what the auditor will sample from the answers you collect.

Frequently asked questions

How many questions should a vendor risk assessment questionnaire have?
As few as the risk tier justifies. A critical vendor handling customer personal data warrants 40–60 questions across security, privacy, continuity and compliance. A medium-tier vendor needs 15–25. A low-tier one may need only confirmation of contract terms. Long questionnaires sent to every vendor produce late, low-quality answers.
Should I use a standard questionnaire like SIG or CAIQ?
They are useful as question banks and many larger vendors will already have completed one, so accept a recent SIG Lite or CAIQ in place of your own. For your own questionnaire, draw from them selectively rather than sending the full set; the standard questionnaires assume an enterprise reviewer on the other end.
How do I score questionnaire answers?
Weight each question by how much the control matters for that vendor's tier, score each answer on a fixed scale (for example 0 = no control, 1 = partial, 2 = in place and evidenced), and express the result as a percentage of the maximum. Set thresholds for accept, accept with conditions, and reject, and record any override with a reason.
What if a vendor refuses to complete the questionnaire?
Ask what they will provide instead: a SOC 2 Type II report, an ISO 27001 certificate with statement of applicability, or a completed standard questionnaire usually answers most of it. If they will provide nothing and the tier is critical or high, that is itself a finding, and the decision to proceed needs a named approver.