Supplier due diligence

Vendor risk assessment questionnaire

Use this vendor security assessment questionnaire before approval, renewal, or AI rollout to request the evidence your team needs for security, privacy, subprocessors, integrations, red flags, and risk decisions.

Best useBefore approval

Ask for evidence first, then score the vendor. Do not approve AI vendors, broad integrations, or regulated data processors from a short yes/no form.

What a vendor security assessment questionnaire should include

A useful vendor security assessment questionnaire asks what data the supplier can touch, which controls protect it, what proof exists, which exceptions remain, and who owns the approval decision. The output should not be a yes/no form; it should produce evidence a reviewer can inspect and a risk record that can be scored, renewed, and reused.

Use the short version

Public-data vendors, low-dependency tools, and suppliers with no production or personal-data access can use a short intake focused on scope, owner, and evidence availability.

Use the full version

Vendors with customer data, regulated data, broad integrations, AI processing, admin access, or material business dependency need full security, privacy, and evidence review.

Escalate the review

Escalate when evidence is missing, subprocessors are unclear, OAuth scopes are broad, AI data use is ambiguous, or the vendor asks for exceptions without compensating controls.

Questionnaire sections

Use these sections to keep supplier review focused on evidence, not generic assurances.

Company and service scopeLegal entity, service description, business owner, data processing role, support model, and renewal or onboarding context.
Data accessCustomer data, employee data, PHI, credentials, logs, source code, payment data, or confidential business data handled by the vendor.
Security controlsSSO, MFA, RBAC, encryption, vulnerability management, incident response, backups, secure SDLC, and audit logging.
Privacy and subprocessorsDPA, BAA, retention, deletion, data residency, subprocessors, model providers, support access, and change notification.
AI and automationAI features, model providers, customer-data training posture, human review, MCP/tool access, OAuth scopes, and audit trail evidence.
Risk decisionRisk tier, missing evidence, compensating controls, approval owner, exception expiration, mitigation owner, and next review date.

Supplier questions and evidence to request

Each question should result in proof a reviewer can open, inspect, and reuse.

QuestionEvidence to request
What data will the vendor access, store, process, or only view?Data inventory, data flow summary, environment scope, data residency note, and retention statement.
Which subprocessors or fourth parties can touch the data?Public subprocessor list, DPA, region, purpose, criticality tier, and change-notification process.
What security evidence can the vendor provide?SOC 2, ISO 27001, CAIQ, SIG, penetration test summary, security overview, access control policy, and incident response summary.
How are privileged actions and support access controlled?SSO/MFA proof, RBAC model, admin access procedure, support access logging, offboarding process, and access review evidence.
What integrations, OAuth scopes, or API permissions are requested?Scope list, minimum-scope justification, token storage, token revocation runbook, and scope-change approval owner.
Does the vendor use AI, agents, MCP servers, or automated decisions?Model provider list, data-use terms, training/retention posture, prompt injection controls, human review, audit log sample, and disable path.
How does the vendor handle incidents and customer notification?Incident response policy, notification timeline, escalation contacts, customer communication process, and evidence retention process.

Acceptable answers, evidence, and red flags

Use this table to turn supplier responses into review decisions instead of collecting unscored answers.

Review areaAcceptable answerEvidenceRed flag
Data access and residencyThe vendor describes exact data types, processing locations, retention period, deletion path, and whether data is viewed, stored, transformed, or exported.Data flow diagram, data inventory, retention policy excerpt, residency statement, and deletion procedure.The answer says data is secure without naming data categories, systems, regions, retention windows, or deletion owners.
Identity and privileged accessSSO, MFA, RBAC, least-privilege roles, access reviews, support access logging, and offboarding are enforced for production or customer-data access.SSO configuration, MFA policy, role matrix, admin access procedure, access review sample, and support access audit sample.Shared admin accounts, optional MFA, no access review cadence, or support staff can access customer data without a ticketed reason.
Security assuranceThe vendor can provide current third-party assurance or a practical control package for the specific service being purchased.SOC 2 Type II, ISO 27001 certificate, CAIQ, SIG, penetration test summary, vulnerability management summary, and security overview.Evidence is stale, belongs to a different product, is unavailable until after contract signature, or excludes the environment you will use.
Privacy and subprocessorsThe vendor names subprocessors, processing purposes, regions, change-notice process, DPA status, and any regulated-data constraints.DPA, BAA when needed, subprocessor list, transfer mechanism, retention terms, deletion SLA, and change-notification policy.Subprocessors are undisclosed, model providers are missing, changes happen without notice, or retention/deletion terms conflict with your policy.
Integrations and API scopesRequested permissions are specific, justified, revocable, and mapped to business functions with an owner for scope changes.OAuth scope list, API permission matrix, token storage design, revocation runbook, integration diagram, and change approval record.Broad read/write scopes are requested for convenience, tokens cannot be revoked quickly, or nobody owns scope review after rollout.
AI, agents, and automationAI use is explicit: model providers, training posture, retention, human review, tool access, audit logs, and disablement path are documented.AI terms, provider list, data-use statement, tool permission list, audit log sample, human-review workflow, and emergency disable procedure.The vendor cannot explain where prompts, outputs, embeddings, logs, or tool calls go, or whether customer data trains models.

Risk tier after the questionnaire

Use the answers to decide review depth instead of treating every vendor as the same risk.

Low

Public or low-sensitivity data, no production access, current evidence available, standard review cadence.

Medium

Business data or limited personal data, narrow integration scopes, partial evidence, or moderate operational dependency.

High

Customer data, confidential data, broad read/write access, AI processing, stale evidence, or contractual commitments.

Critical

Regulated data, production admin access, mission-critical operations, missing evidence, or high-impact automated decisions.

Extra AI vendor questions

Ask these when the vendor uses AI, agents, MCP, browser automation, or broad integrations.

  1. Which model providers, gateways, or AI subprocessors process prompts, outputs, embeddings, logs, or evaluation traces?
  2. Can customer data be used for model training, fine-tuning, evaluation, or human review?
  3. What data is retained, where is it stored, and how can it be deleted or excluded from processing?
  4. Which tools, MCP servers, browser extensions, or integrations can the vendor call on behalf of users?
  5. What per-request audit trail exists for model calls, tool calls, denied actions, reviewers, and admin policy changes?
  6. Who can revoke tokens, disable the AI workflow, reduce scopes, or pause vendor use after an incident?

Next steps

Turn questionnaire answers into scored risk decisions and reusable evidence.

Download the vendor risk template

Use the spreadsheet structure when the supplier questionnaire produces enough evidence to score.

Use an AI vendor questionnaire

Escalate to AI-specific review when a supplier uses models, agents, MCP servers, or automated decisions.

Map evidence to customer answers

Reuse approved vendor evidence in customer security questionnaires and answer libraries.

Automate evidence follow-up

Use software when spreadsheet follow-up, stale evidence, and repeated supplier reviews slow the process.

Add privacy review fields

Use privacy fields when vendors process personal data, PHI, sensitive data, or AI prompts.

Review MCP and tool access

Use the MCP gateway checklist when vendors connect agents, tools, OAuth scopes, or token passthrough.

Vendor risk questionnaire FAQ

Short answers for teams designing supplier intake and evidence review.

What is a vendor risk assessment questionnaire?

It is a supplier due diligence questionnaire that collects security, privacy, data access, AI use, evidence, and mitigation details before a vendor is approved, renewed, or escalated.

Is a vendor risk assessment questionnaire the same as a vendor risk assessment template?

No. The questionnaire asks the supplier for answers and proof. The template scores those answers, records the decision, assigns owners, and tracks mitigation.

What should an AI vendor questionnaire include?

It should include model providers, customer-data use, training posture, retention, deletion, subprocessors, OAuth scopes, tool permissions, human review, audit logs, and emergency disablement.

Should every vendor answer the same questionnaire?

No. Low-risk vendors can use a short questionnaire, while vendors with customer data, regulated data, AI processing, broad integrations, or production access need deeper evidence.

Can this questionnaire be used as a PDF or spreadsheet template?

Yes. A PDF works for one-time collection, but a spreadsheet or workflow tool is better when you need owners, risk tiers, evidence links, exception dates, and renewal tracking.

What makes a vendor security questionnaire answer acceptable?

An acceptable answer names the control owner, scope, evidence, current status, review cadence, and any exceptions. A yes/no answer without evidence should not close the review.

Need a shortlist for your workflow?

Send the formats you receive, your current answer-library setup, and whether you need portal support. We will use those signals to prioritize the next comparison updates.

Request a shortlist