Questionnaire template

Vendor security questionnaire template, 50 questions.

50 questions in thirteen groups, written for a supplier that will hold personal or confidential data, with the DPDP and GDPR points most templates leave out. Copy it and send it.

01

What should a vendor security questionnaire ask?

A vendor security questionnaire should ask what certifications cover the service, what data the vendor will process and where, how access is controlled, how data is encrypted, how fast breaches are reported, which sub-processors are involved, and whether your data trains AI models. Each answer should be backed by evidence or written into the contract.

Generic questionnaires tend to miss the questions that matter under Indian and EU privacy law: the country data is accessed from, erasure on withdrawal of consent, sub-processor notice and log retention. This one includes them.

02

How to use this template

  • Tier the vendor first. Send the whole questionnaire to vendors that will hold personal or confidential data; a shorter subset to the rest.
  • Ask for evidence, not adjectives. A certificate, a report, a configuration screenshot or a policy extract, attached to the answer.
  • Turn gaps into risks. Record anything unsatisfactory in the risk register with an owner and a treatment.
  • Write the answers into the contract. The breach, location, sub-processor and erasure answers belong in the data processing agreement.
  • Diarise the reassessment. Annually for high-risk vendors.
03

The questionnaire

vendor-security-questionnaire.txt
VENDOR SECURITY QUESTIONNAIRE

Vendor: [name]    Service: [description]    Completed by: [name, role, date]
Answer each question and attach evidence where asked. "Not applicable" needs a reason.

COMPANY AND GOVERNANCE
1. Legal entity name, registered address, and the countries where you have staff with access to our data.
   Answer:
   Evidence:
2. Who is accountable for information security? Give name, role and contact.
   Answer:
   Evidence:
3. Do you have a documented information security policy approved by management? When was it last reviewed?
   Answer:
   Evidence:
4. Do you maintain a risk register, and how often is it reviewed?
   Answer:
   Evidence:
5. Do you carry cyber insurance? State the cover amount.
   Answer:
   Evidence:

CERTIFICATIONS AND ASSURANCE
6. Which certifications or attestations do you hold (for example ISO/IEC 27001, SOC 2 Type II, ISO/IEC 27701, PCI DSS)? Provide the certificate or report, scope and date.
   Answer:
   Evidence:
7. Does the scope of those certifications cover the service you will provide to us?
   Answer:
   Evidence:
8. When was your last independent penetration test? Will you share a summary of findings and remediation?
   Answer:
   Evidence:
9. Do you run a vulnerability disclosure or bug bounty programme?
   Answer:
   Evidence:

DATA HANDLING AND PRIVACY
10. Which categories of our personal data will you process, and for what purposes?
   Answer:
   Evidence:
11. Will you sign a data processing agreement meeting section 8(2) of India's DPDP Act [and GDPR Article 28]?
   Answer:
   Evidence:
12. In which countries will our data be stored, processed or accessed from, including for support?
   Answer:
   Evidence:
13. Do you use our data, including inputs to AI features, to train or improve models? Can this be switched off contractually?
   Answer:
   Evidence:
14. How do you assist us with access, correction and erasure requests, and within what time?
   Answer:
   Evidence:
15. What is your retention period for our data, and how is it erased at the end of the contract? Do you provide written confirmation?
   Answer:
   Evidence:
16. How do you act on a withdrawal of consent that we pass on to you?
   Answer:
   Evidence:

ACCESS CONTROL
17. Is multi-factor authentication enforced for all staff access to systems holding our data?
   Answer:
   Evidence:
18. Is access granted on least privilege, and how often are access rights reviewed?
   Answer:
   Evidence:
19. How is privileged (administrator) access controlled, logged and reviewed?
   Answer:
   Evidence:
20. Do you support single sign-on (SAML or OIDC) for our users?
   Answer:
   Evidence:
21. How quickly is access removed when a member of staff leaves?
   Answer:
   Evidence:

ENCRYPTION AND KEY MANAGEMENT
22. Is our data encrypted in transit? State protocols and minimum versions.
   Answer:
   Evidence:
23. Is our data encrypted at rest, including backups? State algorithms.
   Answer:
   Evidence:
24. Who manages the encryption keys, how are they rotated, and can we use our own keys?
   Answer:
   Evidence:

INFRASTRUCTURE AND OPERATIONS
25. Which hosting or cloud providers do you use, and in which regions?
   Answer:
   Evidence:
26. How is our data logically separated from other customers' data?
   Answer:
   Evidence:
27. How are production systems hardened and configuration drift detected?
   Answer:
   Evidence:
28. What is your patching timeline for critical and high-severity vulnerabilities?
   Answer:
   Evidence:
29. Do you run endpoint protection and device management on staff laptops?
   Answer:
   Evidence:

APPLICATION SECURITY
30. Do you follow a documented secure development life cycle?
   Answer:
   Evidence:
31. Is code reviewed before merge, and are static analysis and dependency scanning run in CI?
   Answer:
   Evidence:
32. Are development, test and production environments separated, and is production data kept out of testing?
   Answer:
   Evidence:
33. How do you manage secrets such as API keys and credentials in code and pipelines?
   Answer:
   Evidence:

LOGGING AND MONITORING
34. Which events are logged for systems processing our data (access, admin actions, data export)?
   Answer:
   Evidence:
35. How long are logs retained? (The DPDP Rules 2025 require at least one year for relevant logs.)
   Answer:
   Evidence:
36. Are logs monitored for suspicious activity, and by whom, around the clock or in business hours?
   Answer:
   Evidence:

INCIDENT RESPONSE AND BREACH NOTIFICATION
37. Do you have a documented incident response plan, and when was it last tested?
   Answer:
   Evidence:
38. Within how many hours will you notify us of a personal data breach or security incident affecting our data?
   Answer:
   Evidence:
39. What information will the notification include, and who will be our contact during an incident?
   Answer:
   Evidence:
40. Have you had a security incident or personal data breach in the last 24 months that required notification to a regulator or customers?
   Answer:
   Evidence:

BUSINESS CONTINUITY
41. What are your recovery time and recovery point objectives for the service?
   Answer:
   Evidence:
42. How often are backups taken, and when was a restore last tested?
   Answer:
   Evidence:
43. Do you have a business continuity plan covering loss of a region, a key supplier or key staff?
   Answer:
   Evidence:

SUB-PROCESSORS AND SUPPLY CHAIN
44. List the sub-processors that will handle our data, with their service and location.
   Answer:
   Evidence:
45. How will you notify us of a new sub-processor, and can we object?
   Answer:
   Evidence:
46. How do you assess the security of your own suppliers?
   Answer:
   Evidence:

PEOPLE
47. Are staff with access to our data background-checked, subject to local law?
   Answer:
   Evidence:
48. Do all staff sign confidentiality agreements and complete security training on joining and annually?
   Answer:
   Evidence:

AI FEATURES
49. Does the service use AI or machine-learning models on our data? Which providers, and where do they run?
   Answer:
   Evidence:
50. How do you evaluate and monitor AI features for accuracy, harmful output and data leakage?
   Answer:
   Evidence:
04

What each group is for

GroupQuestionsWhy it is there
Company and governance5Who is accountable, and where people with access sit.
Certifications and assurance4Independent evidence; check the scope covers your service.
Data handling and privacy7The DPDP and GDPR questions: purpose, location, AI training, rights, erasure, withdrawal.
Access control5Most breaches start with a credential. MFA and prompt removal matter most.
Encryption and key management3Whether a stolen disk or backup exposes your data.
Infrastructure and operations5Tenant separation, patching and drift.
Application security4Whether vulnerabilities are caught before release.
Logging and monitoring3Whether unauthorised access would be noticed, and whether logs exist a year later.
Incident response and breach notification4Whether you will hear about a breach in time to meet your own 72-hour clock.
Business continuity3Whether the service comes back, and how much data is lost when it does.
Sub-processors and supply chain3Where your data goes next.
People2Screening, confidentiality and training.
AI features2Which models touch your data, and whether they are tested.

Question counts are generated from the template, so they always match it.

05

Which vendor answers should go into the contract?

Four vendor answers should always be written into the contract: the breach notification window, the countries where data is stored or accessed, the notice period and objection right for new sub-processors, and the erasure commitment at contract end and on withdrawal of consent. A questionnaire answer is a statement; only a contract clause can be enforced.

For your own side of the exchange, when customers send you questionnaires, the enterprise security solution keeps the controls and evidence those questions are answered from. Our own answers are on the trust and security page, including which certifications are still in progress.

More free templates: the full template library, including a 5×5 risk register, a record of processing activities, a vendor security questionnaire and a DPDP consent notice.

Questions

The things people ask us

What is a vendor security questionnaire?

A vendor security questionnaire is a structured set of questions a buyer sends a supplier before sharing data or systems with it, covering governance, certifications, data handling, access control, encryption, incident response and sub-processors. The answers, and the evidence behind them, decide whether the supplier is acceptable and what the contract must add.

How many questions should a vendor security questionnaire have?

Enough to cover the risk, and no more. Around 50 is right for a vendor that will hold personal or confidential data. For a low-risk supplier, such as a tool with no access to your data, the governance and certification sections alone are usually enough. Tier vendors first, then send the length the tier deserves.

Can a SOC 2 or ISO 27001 report replace the questionnaire?

Partly. A current SOC 2 Type II report or ISO 27001 certificate whose scope covers the service answers many control questions with independent evidence. It does not answer the data-specific questions: where your data will live, which sub-processors see it, breach notice timing and AI training use. Ask those anyway.

What should we do with the answers?

Score them against your requirements, record gaps as risks with an owner, and write the essential answers into the contract, especially breach notice hours, data location, sub-processor notice and erasure. An answer in a questionnaire is a representation; a clause in the data processing agreement is an obligation.

How often should vendors be reassessed?

Annually for vendors holding sensitive or personal data, every two to three years for low-risk ones, and immediately after a breach at the vendor, a change of ownership, or a change to the service that alters what data it holds. Track the next review date in your risk register so it does not rely on memory.

Does the DPDP Act require vendor security assessments?

Not as a named procedure. But the Data Fiduciary stays responsible for processing done on its behalf under section 8(1), must protect data including in processing by a Data Processor under section 8(5), and under Rule 6 should provide for safeguards in the contract. Assessing the vendor before signing is how you know what to require.

Book a walkthrough

Answer questionnaires from evidence.

We show the controls and evidence behind a real questionnaire answer, collected from a connected account rather than written from memory.