Use the short version
Public-data vendors, low-dependency tools, and suppliers with no production or personal-data access can use a short intake focused on scope, owner, and evidence availability.
Use this vendor security assessment questionnaire before approval, renewal, or AI rollout to request the evidence your team needs for security, privacy, subprocessors, integrations, red flags, and risk decisions.
Ask for evidence first, then score the vendor. Do not approve AI vendors, broad integrations, or regulated data processors from a short yes/no form.
A useful vendor security assessment questionnaire asks what data the supplier can touch, which controls protect it, what proof exists, which exceptions remain, and who owns the approval decision. The output should not be a yes/no form; it should produce evidence a reviewer can inspect and a risk record that can be scored, renewed, and reused.
Public-data vendors, low-dependency tools, and suppliers with no production or personal-data access can use a short intake focused on scope, owner, and evidence availability.
Vendors with customer data, regulated data, broad integrations, AI processing, admin access, or material business dependency need full security, privacy, and evidence review.
Escalate when evidence is missing, subprocessors are unclear, OAuth scopes are broad, AI data use is ambiguous, or the vendor asks for exceptions without compensating controls.
Use these sections to keep supplier review focused on evidence, not generic assurances.
Each question should result in proof a reviewer can open, inspect, and reuse.
| Question | Evidence to request |
|---|---|
| What data will the vendor access, store, process, or only view? | Data inventory, data flow summary, environment scope, data residency note, and retention statement. |
| Which subprocessors or fourth parties can touch the data? | Public subprocessor list, DPA, region, purpose, criticality tier, and change-notification process. |
| What security evidence can the vendor provide? | SOC 2, ISO 27001, CAIQ, SIG, penetration test summary, security overview, access control policy, and incident response summary. |
| How are privileged actions and support access controlled? | SSO/MFA proof, RBAC model, admin access procedure, support access logging, offboarding process, and access review evidence. |
| What integrations, OAuth scopes, or API permissions are requested? | Scope list, minimum-scope justification, token storage, token revocation runbook, and scope-change approval owner. |
| Does the vendor use AI, agents, MCP servers, or automated decisions? | Model provider list, data-use terms, training/retention posture, prompt injection controls, human review, audit log sample, and disable path. |
| How does the vendor handle incidents and customer notification? | Incident response policy, notification timeline, escalation contacts, customer communication process, and evidence retention process. |
Use this table to turn supplier responses into review decisions instead of collecting unscored answers.
| Review area | Acceptable answer | Evidence | Red flag |
|---|---|---|---|
| Data access and residency | The vendor describes exact data types, processing locations, retention period, deletion path, and whether data is viewed, stored, transformed, or exported. | Data flow diagram, data inventory, retention policy excerpt, residency statement, and deletion procedure. | The answer says data is secure without naming data categories, systems, regions, retention windows, or deletion owners. |
| Identity and privileged access | SSO, MFA, RBAC, least-privilege roles, access reviews, support access logging, and offboarding are enforced for production or customer-data access. | SSO configuration, MFA policy, role matrix, admin access procedure, access review sample, and support access audit sample. | Shared admin accounts, optional MFA, no access review cadence, or support staff can access customer data without a ticketed reason. |
| Security assurance | The vendor can provide current third-party assurance or a practical control package for the specific service being purchased. | SOC 2 Type II, ISO 27001 certificate, CAIQ, SIG, penetration test summary, vulnerability management summary, and security overview. | Evidence is stale, belongs to a different product, is unavailable until after contract signature, or excludes the environment you will use. |
| Privacy and subprocessors | The vendor names subprocessors, processing purposes, regions, change-notice process, DPA status, and any regulated-data constraints. | DPA, BAA when needed, subprocessor list, transfer mechanism, retention terms, deletion SLA, and change-notification policy. | Subprocessors are undisclosed, model providers are missing, changes happen without notice, or retention/deletion terms conflict with your policy. |
| Integrations and API scopes | Requested permissions are specific, justified, revocable, and mapped to business functions with an owner for scope changes. | OAuth scope list, API permission matrix, token storage design, revocation runbook, integration diagram, and change approval record. | Broad read/write scopes are requested for convenience, tokens cannot be revoked quickly, or nobody owns scope review after rollout. |
| AI, agents, and automation | AI use is explicit: model providers, training posture, retention, human review, tool access, audit logs, and disablement path are documented. | AI terms, provider list, data-use statement, tool permission list, audit log sample, human-review workflow, and emergency disable procedure. | The vendor cannot explain where prompts, outputs, embeddings, logs, or tool calls go, or whether customer data trains models. |
Use the answers to decide review depth instead of treating every vendor as the same risk.
Public or low-sensitivity data, no production access, current evidence available, standard review cadence.
Business data or limited personal data, narrow integration scopes, partial evidence, or moderate operational dependency.
Customer data, confidential data, broad read/write access, AI processing, stale evidence, or contractual commitments.
Regulated data, production admin access, mission-critical operations, missing evidence, or high-impact automated decisions.
Ask these when the vendor uses AI, agents, MCP, browser automation, or broad integrations.
Turn questionnaire answers into scored risk decisions and reusable evidence.
Use the spreadsheet structure when the supplier questionnaire produces enough evidence to score.
Escalate to AI-specific review when a supplier uses models, agents, MCP servers, or automated decisions.
Reuse approved vendor evidence in customer security questionnaires and answer libraries.
Use software when spreadsheet follow-up, stale evidence, and repeated supplier reviews slow the process.
Use privacy fields when vendors process personal data, PHI, sensitive data, or AI prompts.
Use the MCP gateway checklist when vendors connect agents, tools, OAuth scopes, or token passthrough.
Short answers for teams designing supplier intake and evidence review.
It is a supplier due diligence questionnaire that collects security, privacy, data access, AI use, evidence, and mitigation details before a vendor is approved, renewed, or escalated.
No. The questionnaire asks the supplier for answers and proof. The template scores those answers, records the decision, assigns owners, and tracks mitigation.
It should include model providers, customer-data use, training posture, retention, deletion, subprocessors, OAuth scopes, tool permissions, human review, audit logs, and emergency disablement.
No. Low-risk vendors can use a short questionnaire, while vendors with customer data, regulated data, AI processing, broad integrations, or production access need deeper evidence.
Yes. A PDF works for one-time collection, but a spreadsheet or workflow tool is better when you need owners, risk tiers, evidence links, exception dates, and renewal tracking.
An acceptable answer names the control owner, scope, evidence, current status, review cadence, and any exceptions. A yes/no answer without evidence should not close the review.
Send the formats you receive, your current answer-library setup, and whether you need portal support. We will use those signals to prioritize the next comparison updates.