All field notes
Security questionnaire tool17 min read

Security Questionnaire Tool: How to Pick One and Prove It in 72 Questions

A security questionnaire tool is judged on answer provenance, review control and file fidelity. Use a weighted scorecard, a 72-question bake-off and a cost model.

Security Questionnaire Tool: How to Pick One and Prove It in 72 Questions

Short answer: A security questionnaire tool drafts cited answers to an incoming assessment from your own policies and documents, then holds those drafts behind human review before export. The catch is that five different product types share this name — the framework below helps you pick the one built for answering, not scoring.

A security questionnaire tool is software that takes the workbook a buyer sent you, drafts answers from documents you already hold, and keeps those drafts behind a review step until a named person releases them. The AI, the knowledge base, the Slack integration — implementation detail wrapped around those three moves. Common formats include CAIQ, HECVAT, NIS2- and DORA-aligned workbooks, ISO 27001-style questionnaires, and the custom Excel sheets many buyers build in-house; a usable tool should handle whichever one lands in your inbox, not just the tidiest.

What complicates the search is that five distinct products are sold under the same phrase, and two of them solve the mirror-image problem: assessing other people's security rather than answering for your own. Buy from the wrong aisle and you end up with a vendor-risk platform that distributes and scores questionnaires elegantly and cannot draft a single answer about your own encryption keys.

Three properties decide most of the rest: where the answer text comes from, who can release it, and what the file looks like when it comes back. Below is a taxonomy, a weighted scorecard with the weights filled in, a 72-question trial protocol with explicit stop rules, an evidence-freshness cadence, and a cost model you can populate with your own measurements.

Five products, one search term

Product typeOptimises forWho sits hereWhere it stops
Answer-drafting toolsTurning a received workbook into drafted, cited answersThe team that gets the questionnaireRarely does continuous control monitoring or audit evidence collection
Trust centres and document portalsPublishing evidence so buyers self-serve before they askVendors fielding the same recurring questions every weekA buyer with a mandated form still sends the form
GRC suites with a questionnaire moduleOne system of record across controls, evidence and answersTeams already running their audit programme in that suiteThe module generally assumes you run the rest of the platform
TPRM and assessor platformsSending, chasing and scoring incoming questionnairesProcurement and vendor-risk teamsNot built to draft answers about your own company
A spreadsheet plus a maintained answer libraryControl, no licence costLow and predictable volumeThe library rots quietly the moment its owner changes role

Before comparing features, settle which seat you occupy. If you are the buyer sending assessments out, rows one to three are the wrong aisle entirely and the relevant question is workflow and scoring, not drafting. If you are the vendor being assessed, a trust centre reduces how many questionnaires arrive but does not help with the regulated buyer whose procurement policy names a specific workbook.

Plenty of teams sit in both seats. They rarely need one tool for both, and a product that claims to do both well deserves a longer trial than one that picks a side.

Three questions that settle most shortlists

Where does the answer text come from?

There are two mechanisms behind any generated answer, and vendors do not always distinguish them. Either the tool retrieves passages from documents you uploaded and composes an answer around them, or it produces fluent text from general model knowledge about how SaaS companies usually work. The second reads better in a demo. It is also the mechanism that can tell a buyer you rotate keys annually when you do not rotate them at all.

The test is not whether a citation appears. It is whether you can open the citation, land on the paragraph, and read the sentence the answer is standing on. A citation that names a document without a location is a bibliography, not evidence.

Who can release an answer?

Ask what the tool does when nobody reviews. Some products treat review as an optional workflow step that a hurried admin can skip; others hold the export until each answer carries a reviewer and a state. This is the difference between a drafting assistant and an unattended answering machine, and it is worth pinning down in writing rather than inferring from a settings screen.

Related: Whether the tool records who approved what and when, and whether that record survives an export. Six months later, when a buyer asks why you answered the way you did, that trail is the entire defence.

What does the file look like coming back?

The workbook the buyer sent has a shape: an instructions tab, a response tab with three-state dropdowns, a comments column, conditional follow-ups that only appear when you answer "No", and a hidden scoring sheet the buyer's tooling reads. If the tool returns clean text in a different structure, someone on your side spends an evening re-keying it, and that evening belongs in the cost model.

A weighted scorecard, with the weights filled in

Feature checklists flatten everything to equal importance. Weight them instead, score each candidate 1–5, and multiply. The weights below are a starting framework, not a benchmark — adjust them to what actually matters for your workbooks.

CriterionWeightA 5 looks like
Answer provenance25Every answer cites a locatable passage in a document you uploaded; unsupported questions come back empty or flagged
Review control20Per-answer approval state, named reviewer, nothing exportable until reviewed, trail survives export
File fidelity15Returns the buyer's workbook with tabs, dropdowns, conditional logic and comment columns intact
Data handling and residency15Documented processing locations, subprocessor list, retention and deletion periods, data-processing terms readable before signup
Cost shape10Priced on something you can forecast; you can model what happens at three times your current volume
Library maintenance10Answers have owners, versions, expiry dates and recorded exceptions
Format coverage5Multi-tab workbooks, Word, PDF, free-text and the portals your buyers use

Two rules make this usable within your own process. A weighted total below 350 (70% of the possible 500 across these seven rows) is a reasonable cutoff for leaving the shortlist. And a score below 3 on either provenance or review control is worth treating as a veto regardless of the total — a tool that writes convincingly from nowhere can still score well everywhere else, and is the one that creates work rather than removing it.

The 72-question bake-off

Trials fail because teams feed the tool a fresh questionnaire and have no ground truth to check against. Build the trial set from workbooks you have already completed and defended, so you know every correct answer before the tool speaks.

Build the set

Seventy-two questions, drawn from your last three completed questionnaires, is one workable size — treat the split below as illustrative and adjust the counts to whatever history you actually have:

  • Roughly 24 repeat questions you have likely answered at least twice before — for example, encryption at rest, MFA enforcement, backup frequency, offboarding timelines.
  • Roughly 18 scoped questions where the true answer carries a condition: production but not the sandbox, the EU tenant but not the US one, the managed service but not the on-premise agent.
  • Roughly 15 questions with no evidence behind them — controls you operate informally, or documents you never wrote down. The correct behaviour is a blank or a flag.
  • Roughly 9 rephrasings of questions already in the set, worded as a different buyer would word them.
  • Roughly 6 trap questions asking about something you demonstrably do not do: an authorisation you do not hold, a region you do not operate in, a certification you have never pursued.

What to score

For each returned answer, check four things: A citation is present and opens to a specific passage; the claim matches what that passage actually says; any scope in the true answer survived into the draft; and the answer fits the cell's permitted values. As a practical sampling rule, verify the claim-to-passage match on the no-evidence and trap items in full and on roughly a quarter of the remainder — an afternoon's work for a set this size.

Record wall-clock minutes for three phases separately: upload and setup, review, export and repair. You need those three numbers for the cost model below, and no vendor can supply them for your workbooks.

The stop rules

  • Any of the trap questions answered affirmatively: Stop the trial. One invented control is a pattern worth investigating, not an outlier to shrug off.
  • More than a couple of the no-evidence items returned as confident answers instead of blank or flagged: The tool is filling gaps with plausible text.
  • Two or more contradictions among the rephrased questions: The same buyer question is producing different claims depending on wording, which is the version of inconsistency that surfaces in a follow-up call.
  • Then count, honestly, how many of the repeat-and-scoped answers you would export unchanged. That count — not a feeling about the demo — is the number to compare across candidates.

The failure mode nobody demos: The confident wrong answer

A blank cell is cheap. Someone notices it, chases the owner, and fills it. The more expensive failure is a well-written answer to a control you do not operate, because a reviewer working through a long row of questions at pace tends to approve what reads well and slow down only for what reads badly. Fluency is the camouflage.

Two habits help catch it, though neither is foolproof. First, a review rule with a narrow, explicit exception path: reject any answer whose citation you cannot open and read in one click, unless a reviewer has already independently confirmed the same fact from the source document elsewhere in the review. Second, hold back a few questions you know you cannot answer and check that they come back empty — a tool that never says "no evidence found" has likely not been tested on the case that matters. We wrote more about where the automation boundary sits in AI Security Questionnaire Automation With Human Review.

What actually breaks in real workbooks

Format handling is where trials that went well can fall apart in week three. The recurring offenders:

  • Merged cells and multi-row questions, where one question spans three rows and the tool answers each row separately.
  • Dropdown validation on the answer column: A tool that writes "Yes, with exceptions" into a cell that only accepts Yes / No / N/A produces a file the buyer's parser may reject.
  • Conditional follow-ups that unlock on a negative answer — answer honestly and new rows appear that nobody's word count anticipated.
  • Instruction tabs carrying the buyer's own definitions, which change what a question means. "Do you encrypt data at rest?" means something different when the workbook defines at-rest to include backups and ephemeral caches.
  • Portals with no export, where answers get typed into a web form and the tool becomes a clipboard.

Ask each vendor to run one of your own genuinely messy workbooks, not their sample. Sample files are usually chosen to demonstrate the product cleanly, not to represent a real worst-case document.

Evidence freshness: The cadence that keeps a library from rotting

Any tool worth buying builds a reusable answer library, and every library decays. The decay is uneven — some answers stay true for years, some are stale within a quarter. A single annual review treats them identically, which is one reason libraries drift.

Answer contentSuggested re-check intervalTrigger that overrides the clock
Subprocessor and hosting-region listRoughly every 90 daysNew vendor contract signed
Headcount, team structure, on-call rotaRoughly every 90 daysReorganisation or team split
Incident response contacts and escalation pathRoughly every 180 daysRole change in the response team
Penetration test summary and remediation statusRoughly every 12 monthsNew test report issued
Certificate or attestation scope and datesRoughly every 12 monthsNew report, or scope change at renewal
Backup restore and DR exercise resultsRoughly every 12 monthsAfter each exercise
Architecture and data-flow diagramsOn changeNew region, new data store, new integration
Encryption and key-management specificsOn changeKMS migration or key-rotation policy revision
Retention and deletion periodsOn changePolicy revision

These intervals are a starting cadence, not a compliance requirement — several rows above move on a roughly 90-day clock, which is the practical argument against a library that only gets touched when a questionnaire arrives. The structural side of this — owners, versions, expiry, exceptions — is covered in Build a Security Questionnaire Answer Library That Lasts.

The cost model, written out

Two numbers decide whether a tool earns its keep, and only you can measure them: minutes per question answering manually, and minutes per question reviewing a draft. Everything below is arithmetic on top of those two.

Manual minutes   = Q × t_manual + (S × i)
Tool minutes     = Q × t_review + setup + (Q × r × t_rewrite)
Internal saving  = (Manual minutes − Tool minutes) / 60 × loaded_rate

Where Q is questions per workbook, S is the number of questions routed to a subject-matter expert, i is the full interruption cost of one such routing (count the context switch, not the typing), r is the share of drafts you rewrite, and setup covers upload, formatting and export repair.

Example (illustrative numbers only — not benchmarks, not sourced, and not typical of any particular deployment; substitute your own measurements from the bake-off):

  • Q = 180, t_manual = 4.0 min, S = 25, i = 25 min → manual: 720 + 625 = 1,345 minutes (about 22 hours)
  • t_review = 1.5 min, setup = 45 min, r = 0.15, t_rewrite = 6 min → tool: 270 + 45 + 162 = 477 minutes (about 8 hours)
  • Difference in this example: roughly 14 hours per workbook. At a loaded rate you pick yourself, that is the ceiling on what the tool could be worth per workbook — for your own numbers, not these.

The decision rule that falls out: Compare the per-workbook price plus amortised library maintenance against that figure, then divide the annual maintenance by your annual workbook count. Below roughly four workbooks a year the maintenance term tends to dominate and the arithmetic usually stops working — the library can cost more to keep current than the drafting saves. Above a dozen, the two numbers that matter most are t_review and r, both of which your trial measured and neither of which appears on any vendor's pricing page.

Standalone tool or the questionnaire module in a suite

Suites have a real advantage that standalone tools cannot match: When your controls, evidence and audit artefacts already live in one platform, the questionnaire module inherits them and stays current without a second import. If you are running an audit programme in a GRC platform today, evaluate its module first — the integration you avoid building is worth more than a marginally better drafting engine.

The trade-off runs the other way when questionnaire answering is the only job. Then you are weighing a module's packaging, quotas and contract length against a tool that does one thing. Packaging changes faster than any comparison article, so verify current terms on the vendor's own pages rather than trusting a table — including this one: Vanta's questionnaire automation page, Conveyor's product page and Responsive's security questionnaire software page. Check three things on each: Whether it is sold on its own, whether there is an annual volume cap, and what the shortest commitment is.

Disclosure: Compliance Concierge, which publishes this page, sells one of these — the answer-drafting kind, hosted in Frankfurt, with answers cited to your uploaded documents and a mandatory review gate ahead of export. Run the bake-off above on us too.

Data handling questions worth putting in writing

Your documents contain your architecture, your gaps and your exception register. Where that material is processed and how long it survives is a procurement question, not a marketing one. Ask for written answers to these before uploading anything:

  • In which regions is the data processed, and in which is it stored? Are those the same?
  • Which subprocessors touch the content, and is the list published before signup or only after?
  • Is customer content used to train models, and does that answer differ between plan tiers?
  • What are the retention periods, and what happens to uploaded documents when the account closes?
  • Are the data-processing terms readable before you create an account?

Whether any of this satisfies a particular obligation in your sector is a question for your own counsel and your own data-protection function — the point here is only that you get the answers in writing early enough to act on them, and that you check the vendor's own documentation rather than a summary.

Questions people ask

What is a security questionnaire?

A structured set of questions a buyer sends a supplier to understand how that supplier handles data, access, incidents and continuity. Some are industry workbooks with an established structure; many are a spreadsheet somebody's security team assembled from three earlier ones. The format matters less than the pattern: The same handful of topics recur, phrased differently every time, which is what makes a reusable answer library viable in the first place.

What tools are used for security assessment?

Depends on which side of the assessment you sit. Assessors typically use TPRM platforms for distribution, chasing and scoring, sometimes alongside external attack-surface scanning. Suppliers use answer-drafting tools, trust centres, and the evidence stores they already run. Scanners and questionnaires answer different questions — one observes what is externally visible, the other asks about what is not.

Is there a free security questionnaire tool?

Free options generally arrive in three shapes: A free tier limited to a first questionnaire or a question count, a time-boxed trial of the paid product, and free templates or spreadsheets that automate nothing. Before treating a free tier as a plan, check what it covers on the vendor's own pricing page — question limits, whether export is included, and whether data handling terms differ from the paid tiers.

What about PDF and portal questionnaires?

PDFs vary widely: A text-layer PDF extracts cleanly, a scanned one needs OCR, and a fillable form needs field-level writing. Portals are harder — if the buyer's system has no import, drafting still helps but the last mile is manual paste. Put one PDF and one portal questionnaire into every trial, because a tool can handle Excel well and neither of the other two.

When a tool is the wrong answer

Under roughly six questionnaires a year, with a stable product and one person who knows the answers, a maintained document plus a disciplined review habit will likely serve you better than a licence — the library maintenance is the same work either way, and the drafting saving may be too small to cover it. The step-by-step manual process is worth running for a quarter first: It produces the two timing numbers the cost model needs, and it tells you whether your real bottleneck is drafting at all.

It often is not. If your questionnaires stall because an engineer takes days to confirm one control, no drafting tool touches that. Fix the evidence ownership, then buy.

From guidance to finished work

Answer the next questionnaire with evidence.

Upload the questionnaire and the policies behind it. Compliance Concierge drafts cautious, cited answers while every final decision stays with a human reviewer.

The questionnaires this covers

This article discusses the questionnaires below. Each page explains how that workbook is structured and what answering it actually involves.

Continue reading