Question sets

Vendor Risk Questionnaire: Tiered Question Sets

A vendor risk questionnaire asks a supplier the things you cannot establish from their certifications, their website or a credit check. Most organisations send one questionnaire to every supplier, which produces slow, low-quality answers from the suppliers who matter. This page gives three sized question sets, the rule for choosing between them, and what to do with the answers.

By Farhan Ahmad · Founder & Chief Intelligence Architect · Reviewed September 26, 2026

The operating challenge

Sending one thorough questionnaire to every supplier is consistent and produces the worst available outcome. A long assessment sent to a low-consequence supplier teaches everyone involved that the process is an obstacle, and the critical supplier's response then receives the same attention as the stationery supplier's.

This guide was created to help software buyers evaluate a real workflow. It does not replace legal, regulatory, security, accounting, or operational review.

A five-step evaluation workflow

  1. Screen every request against three questions covering data, access and dependency.
  2. Route the supplier to a tier before any assessment is issued.
  3. Issue the question set sized to that tier rather than a single standard set.
  4. Score responses against disqualifying and acceptable criteria agreed in advance.
  5. Convert every gap into a register row with a named owner and a date.

Buyer checklist

  • Screening applied before the questionnaire, not after
  • Question count sized to consequence rather than contract value
  • Certification scope and exceptions interrogated, not just possession
  • An explicit question covering AI systems embedded in the service
  • Existing SIG or CAIQ responses accepted, with a short targeted supplement
  • Evidence expiry dates captured at the point of response

Useful outcomes

  • Careful answers in days rather than careless ones in weeks
  • Attention concentrated on the suppliers that warrant it
  • Findings that become owned actions instead of filed documents

How Qeluntra fits

Qeluntra connects authorized supplier, contract, procurement, finance, logistics, inventory, and operating context. AI-assisted recommendations remain explainable and consequential actions remain subject to human approval.

The mistake that makes questionnaires useless

The default behaviour is to build one thorough questionnaire and send it to everyone. It is defensible, it is consistent, and it reliably produces the worst possible outcome, for a reason that is worth stating plainly:

A 250-question assessment sent to a supplier who genuinely presents little risk teaches that supplier — and your own colleagues — that the questionnaire is an obstacle to be cleared rather than a question to be answered.

What follows is predictable. The supplier assigns it to whoever has capacity, answers are copied from a previous response, "yes" appears against controls nobody verified, and the document returns in six weeks. Your team, who have three hundred of these, skim it. The critical supplier's assessment receives the same five minutes as the stationery supplier's, because the process has flattened them.

Shorter questionnaires, sized to consequence, return better data. Fourteen questions that a supplier answers carefully in two days are worth more than two hundred answered carelessly in six weeks — and the time you save is what buys the attention the tier 1 assessment actually needs.

Choosing the set: three triggers

Size the questionnaire on consequence, not on contract value. The three questions below decide it, and any single "yes" promotes the supplier.

QuestionIf yes
1Will they process personal data, or hold data we would have to disclose a breach of?Tier 2 minimum
2Will they have access to our systems, networks or credentials — including an API key or an OAuth grant?Tier 2 minimum
3Does a business service we could not sustain for 30 days depend on them, or could we not replace them in that time?Tier 1

Special-category data under UK GDPR Article 9, payment card data, or a regulated function each promote directly to tier 1 regardless of the other answers.

Apply this before the questionnaire, not after. A screening form of these three questions plus company identity takes a requester ninety seconds and routes the supplier correctly. Most organisations discover the supplier was tier 3 only after having sent them the tier 1 assessment.

Tier 3: the fourteen-question screen

For suppliers with no data, no access and ready substitutes. The purpose is not assurance — it is to confirm the tiering decision was right and to catch the three things that are cheap to check and expensive to miss.

  1. Registered legal entity name, company number and country of registration
  2. Ultimate beneficial ownership — any parent or controlling entity
  3. Countries from which the service will be delivered
  4. Will you process any personal data on our behalf? (yes/no — a yes re-tiers)
  5. Will you require access to any of our systems or credentials? (yes/no — a yes re-tiers)
  6. Will any part of this service be subcontracted? To whom?
  7. Do you hold current public or product liability insurance? Level and expiry
  8. Do you hold professional indemnity insurance where relevant? Level and expiry
  9. Has the entity or any director been subject to insolvency proceedings in the last three years?
  10. Is the entity or any beneficial owner subject to sanctions in any jurisdiction in which we operate?
  11. Have you had a confirmed data breach in the last 24 months? If so, summarise
  12. Named contact for security or compliance matters
  13. Do you hold any security certifications? (ISO 27001, SOC 2, Cyber Essentials — with scope)
  14. Confirm acceptance of our supplier code of conduct

Questions 4, 5 and 6 are re-tiering triggers and should be wired as such. Subcontracting is the one most often skipped, and it is how a tier 3 supplier turns out to be a front for a tier 1 dependency.

Tier 2: the thirty-eight-question assessment

For suppliers processing personal data or holding system access, where interruption is disruptive but survivable. The tier 3 fourteen still apply; these are in addition. Grouped so that a supplier can route sections to the right people rather than assigning the whole thing to one person.

Governance and people (6)

  • Is there an approved information security policy, and who owns it at board or executive level?
  • Is there a named data protection lead or DPO, and their contact details
  • Are background checks performed on staff with access to customer data, and to what standard?
  • Is security awareness training mandatory and how often is it refreshed?
  • What is the offboarding process for revoking access, and what is the target time to revocation?
  • How many staff will have access to our data, and in which roles?

Access control and authentication (7)

  • Is multi-factor authentication enforced for all staff access to systems holding customer data? For administrative access specifically?
  • How is privileged access granted, reviewed and revoked, and at what frequency is it reviewed?
  • Is access to customer data segregated by customer, and by what mechanism?
  • Are shared or service accounts used, and how are their credentials managed?
  • What authentication options are available to our users — SSO, SAML, SCIM provisioning?
  • How are secrets and API keys stored and rotated?
  • Can you produce an access log for our data on request, and for what retention period?

Data handling (8)

  • Which categories of our data will be processed, and for what purpose?
  • In which countries will data be stored, processed and backed up?
  • What is the lawful transfer mechanism for any transfer outside the UK/EEA?
  • Is data encrypted at rest and in transit, and with what algorithms and key management?
  • What is the data retention period, and what is the deletion process on termination?
  • Can data be exported in a documented, machine-readable format, and what is the process and timescale?
  • Full list of sub-processors with the function each performs
  • How are we notified of sub-processor changes, and with what notice period?

Security operations (9)

  • Is there a documented incident response plan, when was it last tested, and what was the outcome?
  • What is your breach notification commitment to customers, in hours?
  • How is vulnerability management performed, and what are the remediation SLAs by severity?
  • When was the last independent penetration test, by whom, and can a summary be shared?
  • Are critical and high findings from that test remediated? Any outstanding?
  • How is logging and monitoring performed, and what is log retention?
  • Is there a change management process for production changes?
  • How is malware protection and endpoint security managed?
  • Do you operate a vulnerability disclosure programme?

Resilience and contractual (8)

  • What is the committed availability target, and actual availability over the last 12 months?
  • What are the recovery time and recovery point objectives?
  • When was business continuity last tested and what was the result?
  • Backup frequency, retention, and when a restore was last verified
  • Which of your own suppliers would interrupt this service if they failed?
  • Will you accept our data processing terms, or do you require your own?
  • What is your cyber insurance cover and its limit?
  • Does the service incorporate any AI system, and if so for what function and with what training-data use of our content?

The last question is newer than most questionnaire libraries. If a vendor's product embeds an AI system, EU AI Act deployer obligations under Article 26 may attach to you as the organisation using it — human oversight, use per instructions, log retention. A questionnaire with no field for it cannot surface the obligation, and most questionnaires written before 2024 have none.

Tier 1: what to add, and what to stop asking

For tier 1 the instinct is to extend the questionnaire. Resist it. Beyond roughly sixty questions the marginal question returns no information, because the supplier has stopped reading carefully. The tier 1 difference should be in verification, not volume.

Add these to the tier 2 set

  • Evidence requests, not assertions. Not "is MFA enforced" but "provide a screenshot of the enforcement policy or the relevant section of your SOC 2 report".
  • Scope interrogation. For each certification: the exact scope statement, the systems in and out of scope, the report period, and any qualified opinions or exceptions. This is where the real findings are.
  • Fourth-party detail. Not just sub-processors but infrastructure dependencies — cloud provider and regions, CDN, identity provider, payment processor.
  • Exit and portability specifics. The actual export format, a tested timescale, what assistance is contractually committed, and what happens to backups.
  • Financial standing. Filed accounts, audit opinion, any going-concern qualification, and revenue concentration if they are small.
  • Named individuals for security, data protection and service escalation, with a right to contact them directly.

Stop asking these, at any tier

  • "Do you take security seriously?" and its many disguises. No information content.
  • Anything a certificate already answers — if you have the SOC 2, do not ask the questions the SOC 2 covers. Ask about its scope and exceptions instead.
  • Yes/no questions on things that are matters of degree. "Is data encrypted?" gets a yes from everyone. "Which algorithm, and how are keys managed?" separates them.
  • Questions you will not act on. If no answer to a question would change your decision, it is costing goodwill for nothing.

SIG, CAIQ and when a standard set is worth it

Two industry questionnaires come up constantly, and the honest position is that they solve a problem you may not have.

SIGCAIQ
Maintained byShared AssessmentsCloud Security Alliance
ScopeBroad third-party risk across many domainsCloud service controls, mapped to the CSA Cloud Controls Matrix
SizeVery large; published in Core and Lite variantsLarge, but narrower in focus
CostLicensed — membership or purchaseFreely available
Best whenRegulated sector, and counterparties already respond in SIGAssessing a cloud service, especially one with a published STAR entry

The genuine advantage of a standard set is that mature suppliers keep a completed one on the shelf, so you get an answer in days rather than weeks. The genuine disadvantage is that a pre-completed response was written for someone else's risk question, and reading it does not tell you what your exposure is.

A workable compromise: accept a supplier's existing SIG or CAIQ in place of your tier 2 set, then send a short supplementary of the six to ten questions specific to your use of them. You get the speed of the standard response and the relevance of a targeted one, and the supplier is not asked to retype two hundred answers they have already written down.

If they publish a CSA STAR entry, read it before sending anything at all.

What to do with the answers

The questionnaire is an input, not an outcome. The step that is most often missing is the one that converts it into something with an owner.

  1. Score against a pre-agreed rule, not a reading. Decide in advance which answers are disqualifying, which require a compensating control, and which are acceptable. Doing this before you see the responses is what stops the assessment bending toward the answer the business wants.
  2. Every gap becomes a register row. A finding that does not become a risk with an owner, a treatment and a date has not been managed — it has been noticed. This is the single highest-value habit in the whole process.
  3. Record the expiry of every piece of evidence. Certificates, insurance, penetration test dates. Expiry is the field that drives the monthly sweep.
  4. Feed disqualifying answers back into contracting. If a supplier cannot commit to 72-hour breach notification, that is a contract clause to negotiate now, not a note to find again at renewal.
  5. Keep the responses. When something goes wrong eighteen months later, what they told you at onboarding is materially relevant — contractually and sometimes legally.

And the discipline that makes the whole thing credible: if the answers never change an outcome — if no supplier is ever rejected, re-tiered or required to remediate — then the questionnaire is a ritual, and everyone involved already knows it.

The part that is coordination rather than judgement

Read back through the five steps above and notice how they divide. Deciding what disqualifies a supplier is judgement and should stay with people. Issuing the right set, chasing it, recording expiry dates, and turning each gap into a register row with an owner is coordination — and coordination is where questionnaire processes actually fail, not at the scoring.

StepWhat it is
Screening three questions and routing to a tierCoordination — and the step most often skipped, which is why tier 3 suppliers receive tier 1 assessments
Issuing the right set and chasing itCoordination
Scoring against pre-agreed criteriaJudgement. Agreed in advance, by people
Turning gaps into register rows with owners and datesCoordination — and the step whose absence means findings were noticed rather than managed
Recording evidence expiryCoordination
Feeding unacceptable answers into contract negotiationBoth

In Qeluntra the assessment is a stage a supplier passes through on the way in, rather than a document that comes back by email — so the findings land on the supplier record instead of being copied to it, and the expiry dates are attached to the evidence rather than to someone's calendar.

The check that tells you whether any of this is worth doing. If no supplier has ever been rejected, re-tiered or required to remediate on the strength of a questionnaire answer, the process is a ritual — and automating a ritual produces a faster ritual. Fix that first, with the shorter question sets above, before changing where the process runs.

Common questions

What is a vendor risk questionnaire?

A vendor risk questionnaire is a structured set of questions sent to a supplier to gather assurance information that cannot be established from their certifications, public filings or website — covering how they handle data, control access, respond to incidents and recover from failure.

How many questions should a vendor risk questionnaire have?

It depends on consequence, not contract value. Around fourteen for suppliers with no data and no system access, roughly forty for suppliers processing personal data or holding access, and no more than about sixty for critical suppliers — where the difference should be verification of answers rather than more questions.

What is the difference between SIG and CAIQ?

SIG is maintained by Shared Assessments and covers third-party risk broadly across many domains. CAIQ is maintained by the Cloud Security Alliance, is freely available, and covers cloud service controls mapped to the Cloud Controls Matrix. SIG suits regulated sectors with counterparties already using it; CAIQ suits assessing a cloud service.

Should we accept a vendor's existing completed questionnaire?

Usually yes, followed by a short supplementary. A pre-completed SIG or CAIQ answers someone else's risk question, so accepting it saves both sides weeks, and six to ten targeted questions about your specific use of the supplier recover the relevance the standard set lacks.

What should you do with vendor questionnaire answers?

Score them against disqualifying and acceptable criteria agreed before the responses arrive, turn every gap into a supplier risk register row with an owner and a date, record the expiry of every piece of evidence supplied, feed unacceptable answers into contract negotiation, and retain the responses.

Do vendor questionnaires need to ask about AI?

They should. Where a vendor's product incorporates an AI system, EU AI Act Article 26 places deployer obligations on the organisation using it — human oversight, use in line with instructions, log retention. A questionnaire with no field for whether the service embeds AI, and whether your content is used for training, cannot surface that obligation.

SIG and CAIQ are maintained by Shared Assessments and the Cloud Security Alliance respectively. The question sets below are original and are a practical starting point, not a substitute for either.