In this guide
| Section | Topic |
|---|---|
| 1 | What Is a Vendor Security Questionnaire? |
| 2 | The Bigger Picture: Vendor Assessment Beyond Security |
| 3 | What a Vendor Security Questionnaire Covers |
| 4 | Why Vendor Security Questionnaires Exist |
| 5 | Common Frameworks: CAIQ, SIG, and HECVAT Compared |
| 6 | How Long Does It Take to Complete? |
| 7 | What Makes a Strong Answer |
| 8 | The AI Shift: How Vendor Assessment Is Evolving |
| 9 | Perspective 1: The Client Sending the Questionnaire |
| 10 | Perspective 2: The Vendor Receiving the Questionnaire |
| 11 | Reducing Questionnaire Volume with a Trust Center |
| 12 | Frequently Asked Questions |
Every vendor relationship is a calculated bet. You hand over access to your data, your infrastructure, and sometimes your customers' personal information, to an organisation whose internal controls you cannot directly inspect. The vendor security questionnaire is the instrument that makes that bet legible. It does not eliminate uncertainty. What it does is convert it into structured, reviewable, comparable information that procurement, legal, and security teams can assess, document, and act on.
What gives the questionnaire its weight is not length but accountability. A vendor who describes their encryption practices in writing is bound to that description in a way that a verbal reassurance on a sales call never achieves. When a vendor attaches a current SOC 2 Type II report alongside a signed Data Processing Agreement, those documents enter the procurement record. If the vendor's controls later prove inadequate, the questionnaire responses become the baseline against which that failure gets measured. Buyers know this. Vendors who take the process seriously know it too, and the ones who do not tend to find out the hard way.
This guide is about understanding: what vendor security questionnaires contain, why they carry legal weight, how the major frameworks compare, what buyers actually evaluate when they read responses, and why AI governance is reshaping the standard assessment. If you are looking for the operational layer, how to build a response library, automate completion, and compress turnaround from days to hours, that is covered in our guide on security questionnaire automation. For the broader due diligence process that questionnaires sit within, see our guide on supplier due diligence.
What Is a Vendor Security Questionnaire?
TL;DRA vendor security questionnaire is a structured written assessment that a buyer sends to a vendor before sharing access to data or systems. It requires the vendor to disclose, in writing, how it protects data, controls access, handles incidents, and meets regulatory obligations. Responses become part of the procurement record and carry contractual weight.
A vendor security questionnaire is a structured written assessment sent by a client organisation to a vendor before granting access to data, systems, or infrastructure. You may hear it called a vendor risk assessment questionnaire, third-party security assessment, or supplier due diligence questionnaire. The names shift across industries and procurement offices. The legal function they serve does not.
That function is documented due diligence: systematic, written verification that a third party meets a buyer's security, privacy, and compliance requirements. Under GDPR rules on data processors, this verification is not a suggestion. It is a legal obligation for any controller sharing personal data with a vendor. A controller who cannot demonstrate adequate verification has already failed a core GDPR requirement, regardless of whether anything subsequently goes wrong. The questionnaire is the primary mechanism through which that demonstration gets made. Full stop.
The Bigger Picture: Vendor Assessment Beyond Security
TL;DRThe questionnaire is one tool within a broader vendor assessment process that now spans security, privacy, AI governance, and operational resilience. Filed in isolation it produces compliance theatre; connected to a live risk register, contract negotiation, and renewal triggers, it becomes a genuine risk management instrument with ongoing accountability.
The questionnaire is one instrument within a wider process called vendor assessment or third-party risk management. The distinction matters because it shapes what the questionnaire is actually for.
A questionnaire that exists in isolation, completed, filed, and forgotten, generates compliance theatre. A questionnaire that feeds into an ongoing risk register, informs contract negotiation, and triggers reassessment at renewal is a genuine risk management tool. The difference is not the document. It is the process around it.
What gets assessed has expanded substantially in recent years. Security controls remain at the core, but they are now evaluated alongside privacy obligations under GDPR processor and controller rules, AI governance requirements under the EU AI Act, operational resilience including subprocessor chains, and contractual enforceability. A vendor that scores well on access controls but cannot produce a current Data Processing Agreement or a maintained subprocessor list? Not compliant with what modern due diligence actually requires.
For vendors, the implication runs equally deep. Receiving a questionnaire is not a sales obstacle to clear as quickly as possible. It is an opportunity to demonstrate, in writing and backed by evidence, that your organisation takes its obligations seriously. The vendor whose responses are precise, internally consistent, and supported by current certifications does not merely pass the review. They accelerate the procurement timeline and set themselves apart from competitors who treat the exercise as a copy-paste chore.
What a Vendor Security Questionnaire Covers
TL;DRVendor security questionnaires assess nine core risk domains: data protection and privacy, access control, encryption, incident response, infrastructure security, business continuity, supply chain risk, compliance certifications, and increasingly AI governance. The specific questions vary by framework, but these domains remain consistent across CAIQ, SIG, and HECVAT assessments.
Most vendor security questionnaires are built around the same underlying risk domains, regardless of which framework is used. The specific questions and depth vary. The terrain is consistent.
| Domain | What it is actually asking about |
|---|---|
| Data protection and privacy | How personal data is classified, stored, transmitted, retained, and deleted; DPA compliance and subprocessor management |
| Access control | Who can access systems and data, how authentication is enforced (MFA, SSO), how privilege is managed, and how access is revoked at offboarding |
| Encryption | Standards for data at rest and in transit; key management practices |
| Incident response | Detection procedures, response timelines, breach notification processes, and post-incident review |
| Infrastructure security | Network architecture, cloud hosting model, patch management, vulnerability scanning and penetration testing cadence |
| Business continuity | RTO/RPO commitments, disaster recovery testing, and documented continuity plans |
| Third-party and supply chain risk | Subprocessor inventory, contractual protections flowing downstream, fourth-party risk management |
| Compliance and certifications | SOC 2, ISO 27001, ISO 42001, GDPR documentation, and sector-specific regulatory alignment |
| AI governance (emerging) | AI system inventory, risk classification, training data governance, human oversight, and EU AI Act readiness |
Why Vendor Security Questionnaires Exist
TL;DRVendor security questionnaires exist because regulation requires documented due diligence before sharing personal data with third parties. Under GDPR, controllers must verify processor compliance or face fines up to EUR 10 million. SOC 2 and ISO 27001 both mandate structured vendor risk management. The questionnaire is the primary mechanism for meeting these obligations.
The proximate reason for vendor security questionnaires is straightforward enough: organisations need to know what risks they are taking on before they take them on.
The subtler reason is more instructive. When a breach occurs through a third party, it is almost never because the client organisation lacked the ability to ask about the vendor's controls. It is because nobody asked, the answers were accepted without evidence, or the questionnaire was filed without review. The MOVEit breach of 2023 illustrates the pattern with painful clarity: the initial vulnerability sat in a vendor's software, but the exposure cascaded across hundreds of organisations, government agencies, financial institutions, healthcare providers, each of which had granted that vendor access without maintaining a current picture of its security posture.
Regulation reinforces this requirement with teeth. Under GDPR rules on data processors, controllers must verify that processors provide sufficient guarantees of compliance. Failure to conduct adequate due diligence before sharing personal data with a vendor is itself a GDPR violation, attracting administrative fines of up to EUR 10 million or 2% of global annual turnover. The EU AI Act extends this logic to AI systems, requiring organisations to understand how vendors classify, govern, and oversee the AI tools they deploy. Both SOC 2 and ISO 27001 explicitly require structured vendor risk management processes as part of their control frameworks.
In this environment, vendor security questionnaires are not administrative overhead. They are a core component of regulatory compliance, operational resilience, and defensible risk management.
Common Frameworks: CAIQ, SIG, and HECVAT Compared
TL;DRThree frameworks dominate vendor security assessment. CAIQ targets cloud and SaaS vendors with approximately 200 controls mapped to the Cloud Controls Matrix. SIG covers enterprise-wide risk across 20 domains with 850+ questions in the full version. HECVAT serves higher education with 270+ questions addressing FERPA, HIPAA, and GDPR obligations specific to that sector.
Most organisations do not design questionnaires from scratch. They rely on established frameworks that standardise how risk is assessed, making vendor responses comparable across different procurement processes. Three dominate.
| Framework | Best suited for | Primary focus |
|---|---|---|
| CAIQ | Cloud/SaaS vendors; enterprise buyers with cloud-first governance | Cloud architecture and controls, mapped to the Cloud Controls Matrix (17 domains, approx. 200 controls) |
| SIG | Financial services, healthcare, large enterprise; broad third-party risk programmes | Enterprise-wide risk across 20 domains including AI governance (SIG Core: 850+ questions; SIG Lite: 125-175) |
| HECVAT | Universities, colleges, research institutions; FERPA, HIPAA, GDPR obligations | Higher education data privacy and regulatory compliance (Full: 270+ questions; Lite version available) |
Each framework represents a different lens on the same underlying question: is this vendor safe to work with? The CAIQ is closer to a technical blueprint review. The SIG questionnaire resembles a full organisational audit. The HECVAT reflects sector-specific regulatory complexity particular to higher education. In practice, vendors often encounter all three, sometimes within the same quarter. A response library that pre-populates answers across frameworks is the most efficient way to handle this volume. See our guides to the CAIQ, the SIG questionnaire, and the HECVAT for section-by-section walkthroughs of each.
How Long Does It Take to Complete a Vendor Security Questionnaire?
TL;DRFirst-time completion typically requires 6 to 15 hours of combined effort from security, legal, engineering, and compliance teams. With a maintained response library and current SOC 2 or ISO 27001 certifications, repeat completions drop to 1 to 3 hours of targeted review and updates.
Completion time depends almost entirely on the compliance infrastructure behind the vendor, not the questionnaire in front of them.
The same 200-question CAIQ takes a vendor with a current SOC 2 Type II report, a maintained ROPA, and a signed DPA template roughly two hours to review. It takes a vendor assembling that information from scratch several days. The questionnaire has not changed. The organisation behind the response has. For a practical guide to building the infrastructure that compresses completion time, see our guide on security questionnaire automation.
| Scenario | Typical completion time |
|---|---|
| First-time completion, no response library | 6 to 15 hours of combined effort across multiple teams |
| Established response library, manual process | 2 to 4 hours of review and customisation |
| Automation platform with pre-populated responses | 1 to 3 hours of review and exception handling |
| Published Trust Center allowing buyer self-service | Zero: the questionnaire is never sent |
The fourth row is the one worth building toward. When a buyer finds independently verified compliance documentation already published in a vendor's Trust Center before initiating a formal assessment, the questionnaire often never gets sent. This is not because the buyer is less rigorous. Quite the opposite. The questionnaire that never arrives cannot be answered incorrectly, cannot stall a deal, and cannot produce an audit trail that contradicts a response sent six months earlier. The vendor has already answered it in advance, with audited evidence rather than typed assertions.
What Makes a Strong Answer
TL;DRStrong questionnaire answers are specific, evidence-backed, and internally consistent. They name the exact controls in place rather than claiming general compliance, attach current certifications and audit reports, and acknowledge genuine limitations with documented compensating controls. Reviewers can distinguish rehearsed marketing language from practitioner precision within the first few responses.
Risk reviewers are experienced readers. They evaluate hundreds of questionnaires and they spot the same patterns that signal superficiality: marketing language where security documentation should be, controls described identically regardless of the question context, certifications claimed without attached reports. The vendors who advance through procurement fastest are not those who answer most comprehensively. They are those whose answers are specific enough to evaluate, consistent enough to trust, and evidenced enough to verify.
Three qualities determine the difference.
| Principle | Weak practice | Strong practice | Why it matters |
|---|---|---|---|
| Precision | We follow industry best practices. | We enforce MFA on all privileged access and encrypt data at rest using AES-256. | Generic answers provide nothing for a risk reviewer to evaluate or verify |
| Precision | Data is secured. | All customer data is encrypted at rest (AES-256) and in transit (TLS 1.3). | Specificity signals real engineering, not marketing |
| Consistency | Different answers across questionnaires | Standardised answer reused across all questionnaires, aligned with internal policies and certifications | Inconsistency creates doubt even when the underlying control is sound |
| Consistency | Terminology varies by team | Unified language aligned with SOC 2 report, ISO 27001 certificate, and GDPR documentation | Reviewers compare responses; divergence triggers follow-up |
| Evidence | We are compliant with SOC 2. | We maintain a SOC 2 Type II certification. See attached report, Section 3. | Assertions are evaluated on trust; evidence is evaluated on audit |
| Evidence | No supporting documentation attached | References to ISO 27001 certificate, DPA template, penetration test executive summary | Evidence converts the questionnaire into a due diligence asset, not just a declaration |
The AI Shift: How Vendor Assessment Is Evolving
TL;DRVendor assessment now includes dedicated AI governance sections driven by the EU AI Act and frameworks such as ISO 42001. Buyers increasingly ask about AI system inventories, training data governance, bias mitigation, human oversight mechanisms, and risk classification. Vendors deploying AI systems face new disclosure requirements that did not exist two years ago.
For most of the questionnaire's history, the risk it was designed to assess was infrastructural: will the vendor's systems be breached, and if so, how fast will they respond? AI introduces a categorically different kind of risk. One that is harder to detect, slower to surface, and more difficult to assign responsibility for.
When a vendor's infrastructure fails, the failure is immediate and visible. When a vendor's AI system produces biased outputs or makes automated decisions affecting individuals without adequate human oversight, the harm may accumulate over months or years before anyone traces the vendor relationship as the source. That is a fundamentally different threat model, and the questionnaire frameworks are only beginning to catch up.
This is why the EU AI Act matters for questionnaires. It creates legal obligations that flow through vendor relationships in exactly the way GDPR does. An organisation that deploys a third-party AI system classified as high risk cannot discharge its compliance obligations by claiming the vendor is responsible. The deploying organisation has its own direct obligations under the Act. Verifying a vendor's AI governance posture is therefore not optional due diligence. It is a precondition of compliant deployment. For a deeper dive into how this regulatory framework applies to your AI systems, see our EU AI Act Guidebook and ISO 42001 Guidebook.
Perspective 1: The Client Sending the Questionnaire
TL;DRClients sending questionnaires should scope their assessment to the actual risk: a payroll processor handling employee data warrants deeper scrutiny than a marketing analytics vendor. Effective buyers tier vendors by data sensitivity, calibrate question depth accordingly, and review responses for internal consistency rather than keyword matching.
From the client's perspective, the primary objective is evaluating vendor risk in a consistent and defensible manner. This requires standardisation, comparability, and explicit alignment with regulatory frameworks. The GDPR's accountability principle, reinforced by EDPB Guidelines 07/2020, requires that due diligence can be demonstrated, not merely asserted.
Many organisations struggle with fragmented assessment processes. Different teams use different questionnaires. Responses arrive in incompatible formats. Comparisons are manual. There is no audit trail demonstrating that adequate oversight was performed. This creates both inefficiency and regulatory exposure: a controller that cannot document adequate vendor due diligence faces the same liability as one that conducted none at all.
Best practices for clients
- Standardise on recognised frameworks (CAIQ, SIG, HECVAT) adapted to your specific regulatory context
- Map every questionnaire section explicitly to GDPR processor requirements so the assessment simultaneously produces documented due diligence evidence
- Add structured AI governance questions where vendors operate AI systems in regulated contexts
- Require evidence, not assertions: current certifications and audit reports carry more weight than narrative descriptions of controls
- Maintain a centralised vendor risk repository so reassessment at contract renewal does not start from zero
Perspective 2: The Vendor Receiving the Questionnaire
TL;DRVendors receiving questionnaires should treat each one as a commercial differentiator, not an obstacle. Building a centralised response library, maintaining current certifications, and providing proactive evidence packages accelerates completion from days to hours. Precise, evidence-backed answers signal operational maturity and shorten procurement cycles significantly.
For vendors, questionnaires are frequently the most persistent bottleneck in the sales cycle. They arrive at the moment when deal momentum is highest and demand input from teams who have other priorities. The structural problem is not the questionnaire itself. It is the absence of a system to handle it.
Without a centralised response library, the same question gets answered from scratch each time it arrives, often by a different team member, in slightly different language. The result is inconsistency: two buyers in the same quarter receive subtly different descriptions of the same control. That inconsistency is an audit risk. And it is entirely preventable.
Best practices for vendors
- Build a centralised response library mapped to your SOC 2 Type II report, ISO 27001 certificate, and GDPR documentation (DPA, ROPA)
- Prepare ISO 42001 or EU AI Act readiness documentation now, before AI governance questions become standard in every enterprise assessment
- Standardise terminology across all questionnaire responses to align with your certifications and internal policies
- Publish your security posture proactively in a Trust Center: every buyer who self-serves your documentation before sending a questionnaire is an assessment you never have to complete
- Use security questionnaire automation to pre-populate responses from your live compliance documentation, reducing first-time completion from hours to minutes of review
Reducing Questionnaire Volume with a Trust Center
TL;DRA Trust Center is a vendor-published portal that proactively shares security documentation, certifications, and compliance posture with any buyer on demand. Organisations that publish a Trust Center report receiving 30 to 60 percent fewer inbound questionnaires because buyers can self-serve the information they need without initiating a formal assessment cycle.
There is a more consequential question than how to complete questionnaires faster: how to make them unnecessary.
A Trust Center is a vendor-published portal, publicly accessible or gated by NDA, that places your security documentation in the buyer's hands before they think to ask for it. When a buyer finds current certifications, a DPA template, a maintained subprocessor list, and a penetration test summary already indexed and searchable, the formal questionnaire process frequently never begins.
This is not a marginal efficiency gain. A questionnaire that never arrives cannot be answered incorrectly, cannot stall a deal, and cannot create an audit trail that contradicts a response sent six months earlier. Every SOC 2 Type II report, ISO 27001 certificate, and GDPR documentation set that a buyer self-serves converts a reactive compliance obligation into a proactive trust signal. The procurement conversation starts from verified credibility rather than unverified assertion.
A Trust Center and security questionnaire automation serve different but complementary functions: the Trust Center eliminates questionnaire volume at the top; automation compresses the effort for assessments that still arrive. The formal questionnaire sent after a buyer has already reviewed your Trust Center is narrower in scope, faster to complete, and easier to approve because the reviewer already understands your posture. You can launch your own at whisperly.ai/free-trust-center.
Related Whisperly Guides
| Guide | Why it connects to this article |
|---|---|
| Security Questionnaire Automation | The parent guide: how to automate vendor security questionnaire responses at scale |
| Trust Center | Proactively publish your security posture to reduce inbound questionnaire volume |
| Vendor Assessment | How Whisperly manages the sending side: building, distributing, and scoring questionnaires |
| Supplier Due Diligence Checklist | The broader due diligence process that vendor security questionnaires sit within |
| CAIQ Guide | Complete walkthrough of the Cloud Security Alliance questionnaire framework |
| SIG Questionnaire Guide | Complete walkthrough of the Shared Assessments SIG Core and SIG Lite |
| HECVAT Guide | Higher education vendor assessment framework for academic institutions |
| SOC 2 Guidebook | The most commonly requested certification in vendor security questionnaires |
| ISO 27001 Guidebook | Information security certification that addresses the majority of questionnaire control domains |
| ISO 42001 Guidebook | AI governance certification: the primary evidence asset for emerging AI questionnaire sections |
| GDPR Guidebook | Data protection compliance documentation required in the privacy and compliance sections |
| ROPA Automation | Records of Processing Activities: core evidence for subprocessor and data flow questions |
Automate your vendor security questionnaire responses with Whisperly
Your SOC 2 report, ISO 27001 certificate, GDPR documentation, and prior questionnaire responses already contain the answers to the majority of vendor security questionnaire controls. Whisperly connects those documents to an AI-driven matching engine that pre-populates responses, assigns confidence ratings, and routes the remaining questions to the right reviewer. From days of manual effort to hours of focused review.
Book a demo | Explore questionnaire automation | Launch your free Trust Center
Frequently Asked Questions
What is a vendor security questionnaire?
A vendor security questionnaire is a structured assessment document sent by a buyer, customer, or partner organisation to a vendor before granting access to data or systems. It asks the vendor to disclose how it protects data, manages access, secures infrastructure, responds to incidents, and meets regulatory requirements. Some organisations call it a vendor risk assessment questionnaire or third-party security assessment; the names shift, but the function remains identical. For the broader process this document sits within, see our guide to supplier due diligence.
How long does it take to complete a vendor security questionnaire?
That depends entirely on what you have prepared before the questionnaire arrives. Without a pre-built response library, first-time completion typically requires 6 to 15 hours of combined effort across security, legal, engineering, and compliance teams. With a well-maintained library backed by SOC 2 and ISO 27001 certifications, repeat completions drop to 1 to 3 hours of targeted review. The questionnaire itself has not changed between those two scenarios. Your readiness has.
What frameworks are commonly used?
Three dominate the market. The CAIQ (Cloud Security Alliance) focuses on cloud vendors and maps to the Cloud Controls Matrix. The SIG questionnaire (Shared Assessments) covers broad enterprise-wide risk across 20 domains. The HECVAT (EDUCAUSE) targets higher education institutions with their particular mix of FERPA, HIPAA, and GDPR obligations. Many enterprise organisations use all three, selecting the framework based on vendor type and relationship risk level.
What evidence should vendors provide?
Strong responses attach audited evidence, not just narrative assertions. At minimum: a current SOC 2 Type II report, an ISO 27001 certificate with statement of applicability, a signed GDPR Data Processing Agreement template, a current subprocessor list and Records of Processing Activities, and a penetration test executive summary. Each certification converts multiple individual questions into a single, independently verified reference. That is the efficiency lever most vendors underestimate.
How is AI changing vendor security questionnaires?
Questionnaires increasingly include dedicated AI governance sections. This shift is driven by the EU AI Act and evolving enterprise risk management standards. Common new questions cover AI system inventory, training data governance, bias mitigation practices, human oversight mechanisms, and ISO 42001 certification status. Vendors without structured AI governance documentation will face growing friction in enterprise procurement. The trend is not speculative; it is already visible in 2026 assessment cycles.
Are vendor security questionnaires legally required?
No specific law mandates this particular document format. However, conducting adequate vendor due diligence is a legal obligation under GDPR for any controller sharing personal data with a third party. Failure to do so attracts administrative fines of up to EUR 10 million or 2% of global annual turnover. The vendor security questionnaire is the most common practical mechanism for discharging that obligation. Whether you use this format or another, the underlying legal requirement exists regardless.
How can vendors reduce the time spent on questionnaires?
Three approaches, layered together, produce the most significant results. First, build a centralised response library mapped to your certifications and GDPR documentation. Second, publish your security posture proactively in a Trust Center so buyers can self-serve before sending a questionnaire. Third, use security questionnaire automation to pre-populate responses from your live compliance documentation. Together, these measures can reduce response time from days to hours and cut inbound questionnaire volume substantially.
What is the difference between a vendor security questionnaire and a Trust Center?
A vendor security questionnaire is a formal, buyer-initiated assessment sent to a specific vendor. A Trust Center is a proactive, vendor-published portal containing the same underlying security documentation, accessible to any buyer on demand. The questionnaire is reactive. The Trust Center is proactive. Many vendors use both: the Trust Center reduces the volume of inbound questionnaires; automation handles the residual assessments that still arrive. The combination is more effective than either approach alone.
Related reading: AI Vendor Risk: How AI Is Redefining Third-Party Assessment covers why traditional vendor questionnaires miss AI-specific risks and how to extend your assessment framework.
To improve your team's approach, explore our security questionnaire best practices guide.
Further Reading on Whisperly
Questions & Answers
What is a vendor security questionnaire?+
A vendor security questionnaire is a structured assessment document sent by a buyer, customer, or partner organisation to a vendor before granting access to data or systems. It asks the vendor to disclose how it protects data, manages access, secures infrastructure, responds to incidents, and meets regulatory requirements. For more on the broader process, see our guide on vendor assessment.
How long does it take to complete a vendor security questionnaire?+
Without a pre-built response library, first-time completion typically requires 6 to 15 hours of combined effort across security, legal, engineering, and compliance teams. With a well-maintained library backed by SOC 2 and ISO 27001 certifications, repeat completions drop to 1 to 3 hours of targeted review. Learn how to accelerate this with security questionnaire automation.
What frameworks are commonly used?+
Three dominate the market: the CAIQ (Cloud Security Alliance) for cloud vendors, the SIG questionnaire (Shared Assessments) for broad enterprise-wide risk, and the HECVAT (EDUCAUSE) for higher education institutions.
What evidence should vendors provide?+
A current SOC 2 Type II report, an ISO 27001 certificate with statement of applicability, a signed GDPR Data Processing Agreement template, a current subprocessor list and Records of Processing Activities, and a penetration test executive summary. See our supplier due diligence checklist for the full documentation requirements.
How is AI changing vendor security questionnaires?+
Questionnaires increasingly include dedicated AI governance sections driven by the EU AI Act and evolving enterprise risk management standards, covering AI system inventory, training data governance, bias mitigation, human oversight, and ISO 42001 certification status. Read more about AI vendor risk assessment.
Are vendor security questionnaires legally required?+
No specific law mandates the document format, but conducting adequate vendor due diligence is a legal obligation under GDPR for any controller sharing personal data with a third party, subject to fines of up to EUR 10 million or 2% of global annual turnover. Our GDPR guidebook covers these obligations in detail.
How can vendors reduce the time spent on questionnaires?+
Build a centralised response library, publish your security posture in a Trust Center, and use security questionnaire automation to pre-populate responses from live compliance documentation.
What is the difference between a vendor security questionnaire and a Trust Center?+
A vendor security questionnaire is a formal, buyer-initiated assessment. A Trust Center is a proactive, vendor-published portal containing the same underlying documentation, accessible to any buyer on demand. Learn more about setting up a free Trust Center.
Reviewed by: Tamara Zavisic, AI Governance Consultant