Why questionnaires exist — and what the buyer actually wants
The person sending you a questionnaire usually did not write it and cannot waive it. Enterprise third-party risk teams must evidence that every supplier was assessed; the questionnaire is that evidence. Understanding this changes how you answer: your reader is building a defensible file, not conducting an interrogation. Clear, consistent, evidence-referenced answers make their job easy — and easy files get approved faster.
What gets suppliers rejected is rarely a missing control. It is contradictions (question 41 contradicts question 87), evasion (“see attached policy” with no page reference), and silence on follow-ups. Small firms with honest gaps and clear remediation dates pass review constantly.
Triage before answering
- Confirm scope. Which service, which data, which environments? A questionnaire scoped to “suppliers processing personal data” may barely apply if you only receive business contact details. Agreeing scope first can remove half the questions.
- Ask what they accept in lieu. Many buyers accept a recent SOC 2 report, ISO 27001 certificate, Cyber Essentials Plus, or a completed industry-standard questionnaire (CAIQ, SIG) instead of their bespoke form — but only if you ask.
- Identify the knockouts. Scan for questions marked mandatory or phrased absolutely (“Do you encrypt all data at rest?”). Deal with these first; if one is a genuine blocker, better to negotiate early than after two weeks of form-filling.
- Nominate one owner. Questionnaires answered by committee contradict themselves. One person answers; specialists review.
Five answering principles
- Answer the question asked, then stop. Volunteered detail creates follow-ups and future audit surface.
- Never claim a control you do not run. Questionnaire answers get incorporated into contracts by reference. A false “yes” is a breach waiting to be discovered at the worst time — during an incident.
- “No, because…” beats a fake yes. Proportionality is a legitimate answer: “No dedicated SOC; we are a 12-person company. Alerting from our cloud provider routes to the on-call engineer with a 15-minute response target during business hours.”
- “Not yet, by [date]” is a strong answer. Risk teams can approve suppliers with documented remediation plans. They cannot approve vagueness.
- Reference evidence precisely. “Yes — MFA enforced tenant-wide via conditional access; enforcement report available on request” reads very differently from a bare “yes”.
Build the answer bank once
The compounding asset is a maintained answer bank: your canonical answers, organised by theme, reused across every questionnaire. Most forms — bespoke or standard — draw from the same underlying domains, so structure yours the same way. For each entry keep four fields: the canonical answer (two to four sentences, honest, current), the evidence pointer (which document or report proves it), the owner, and the last-verified date.
| Section | Covers |
|---|---|
| Company & governance | Legal entity, insurance held, who owns security, policy review cycle |
| People | Vetting, security training, joiner/leaver process, confidentiality terms |
| Access control | MFA, SSO, privileged accounts, access review cadence |
| Infrastructure & hosting | Cloud providers and regions, tenancy model, network controls |
| Data handling | What you store, encryption at rest/in transit, retention, deletion on exit |
| Endpoints | Device management, disk encryption, malware protection |
| Development & change | Code review, dependency updates, separation of environments |
| Incident response | Plan, roles, customer notification commitments and timescales |
| Business continuity | Backups, restore testing, recovery targets |
| Sub-processors | Who they are, what they see, how you assess them |
| Certifications & assurance | Cyber Essentials, ISO 27001, SOC 2, penetration tests — with dates |
Review the bank quarterly and after any material change. An answer bank with stale dates is worse than none — it industrialises wrong answers. This page itself is the template: reproduce the eleven sections above in a shared document and you have the structure enterprise reviewers expect.
Handling the hard questions
“Do you have ISO 27001 / SOC 2?”
If no: say no, state what you do hold (for a UK SME, Cyber Essentials is a meaningful and recognised answer), and whether certification is planned. Many buyers have a proportionate track for small suppliers — your honesty routes you into it.
“Describe your SOC / 24×7 monitoring.”
Answer proportionately, as above. Enterprise reviewers know a 10-person firm has no SOC; they are checking whether anyone would notice an incident.
“Have you had a security incident in the last 3 years?”
Answer truthfully and briefly: what happened, impact, what changed afterwards. A disclosed, remediated incident is survivable; a discovered concealment usually is not — contractually and reputationally.
Absolute questions (“all”, “always”, “every”)
Qualify precisely rather than rounding up: “All customer data at rest is encrypted (provider-managed AES-256). Two internal legacy file shares hold no customer data and are scheduled for decommissioning in Q4.”
Escaping the loop entirely
The questionnaire loop exists because SMEs have no standard way to prove posture continuously — so every buyer asks everything, every time, in their own format. The answer bank shrinks the cost per questionnaire; shared, verifiable evidence shrinks the number of questionnaires.
That is the design goal of the TrustQuant Trust Passport: a shareable, independently verifiable credential of your current resilience rating that answers the recurring 80% of questions before the form arrives — leaving only the genuinely bespoke ones. Read a sample report to see the evidence behind it, or join the Q3 2026 pilot to help shape it.