Common questions
What is a vendor risk questionnaire?
A vendor risk questionnaire is a structured set of questions sent to a supplier to gather assurance information that cannot be established from their certifications, public filings or website — covering how they handle data, control access, respond to incidents and recover from failure.
How many questions should a vendor risk questionnaire have?
It depends on consequence, not contract value. Around fourteen for suppliers with no data and no system access, roughly forty for suppliers processing personal data or holding access, and no more than about sixty for critical suppliers — where the difference should be verification of answers rather than more questions.
What is the difference between SIG and CAIQ?
SIG is maintained by Shared Assessments and covers third-party risk broadly across many domains. CAIQ is maintained by the Cloud Security Alliance, is freely available, and covers cloud service controls mapped to the Cloud Controls Matrix. SIG suits regulated sectors with counterparties already using it; CAIQ suits assessing a cloud service.
Should we accept a vendor's existing completed questionnaire?
Usually yes, followed by a short supplementary. A pre-completed SIG or CAIQ answers someone else's risk question, so accepting it saves both sides weeks, and six to ten targeted questions about your specific use of the supplier recover the relevance the standard set lacks.
What should you do with vendor questionnaire answers?
Score them against disqualifying and acceptable criteria agreed before the responses arrive, turn every gap into a supplier risk register row with an owner and a date, record the expiry of every piece of evidence supplied, feed unacceptable answers into contract negotiation, and retain the responses.
Do vendor questionnaires need to ask about AI?
They should. Where a vendor's product incorporates an AI system, EU AI Act Article 26 places deployer obligations on the organisation using it — human oversight, use in line with instructions, log retention. A questionnaire with no field for whether the service embeds AI, and whether your content is used for training, cannot surface that obligation.