All field notes
Vendor assessment19 min read

Vendor Assessment Questionnaire Template: 48 Questions

Copy a 48-question vendor assessment questionnaire template with evidence fields, risk routing, optional add-ons, scoring logic, and review steps.

Vendor Assessment Questionnaire Template: 48 Questions

A usable vendor assessment questionnaire template combines scoped questions with response, evidence, and internal decision fields—not just a list of security prompts. Copy the 48 core questions below into Excel, Word, or a form builder, then send only the modules that fit the vendor’s service. Four optional packs add up to 12 questions for AI features, privileged integrations, distributed software, and personnel access.

A vendor’s “Yes” is a claim. The assessment begins when a reviewer checks its scope, supporting evidence, owner, date, and exceptions.

This original template is an operational starting point rather than a licensed standard. It does not determine regulatory applicability, compliance, certification, or contractual position. Verify those questions against current official material and qualified counsel where appropriate.

The template produces two records, not one

A questionnaire collects vendor-supplied information. An assessment records what your organization concluded from that information. Keeping those records separate prevents vendor edits from changing internal analysis.

RecordPurposeTypical ownerVisible to vendor?
Vendor questionnaireCollect scoped answers, explanations, and evidence referencesVendor contactYes
Vendor assessment formRecord validation, gaps, follow-up, and dispositionInternal reviewerUsually no
TPRM checklistTrack the wider third-party risk management workflow from intake through exitProgram ownerUsually no

A TPRM checklist can therefore contain tasks such as classification, questionnaire selection, evidence review, decision recording, monitoring triggers, and offboarding. It is broader than the questionnaire itself.

For a SaaS-focused explanation of the parties, evidence, and exceptions involved, see Vendor Security Questionnaires: A Practical SaaS Guide.

A four-sheet workbook keeps claims and decisions apart

A practical Excel version uses four sheets:

  1. Intake and routing: vendor, service, business owner, intended use, data flow, access model, routing score, and selected modules.
  2. Questionnaire: the vendor-facing questions, response fields, explanations, and evidence IDs.
  3. Evidence register: artifact metadata and the questions each artifact supports.
  4. Review log: reviewer status, follow-up, gaps, accepted limitations, decision, and review triggers.

Use stable question IDs so references survive sorting and export. A useful questionnaire row contains these columns:

FieldWhat belongs in it
Question IDStable identifier such as Q19
ModuleData, access, resilience, or another topic
Applies?Yes, no, or pending scope review
QuestionOne testable prompt
Vendor responseYes, partial, no, not applicable, or planned
ExplanationScope, implementation, exclusions, and relevant context
Evidence IDReference into the evidence register
Evidence dateArtifact version, issue date, or test date
Vendor ownerPerson or function able to clarify the answer
Reviewer statusAccepted, clarification needed, gap recorded, or escalated
Follow-upSpecific unresolved request
Decision noteInternal rationale, not a copy of the vendor’s answer

Keep planned separate from yes. A future target date describes intent, not the current operating state. Likewise, “not applicable” becomes reviewable only when the explanation identifies the excluded component or use case.

An eight-field evidence register can use: evidence ID, artifact title, owner, version or date, covered system, linked question IDs, controlled location, and review trigger. That is enough metadata to detect a common failure: a valid document attached to the wrong product or environment.

Copy-ready vendor assessment questionnaire template

The questions below are original operational prompts. They do not reproduce CAIQ, HECVAT, SIG, ISO, or customer-owned questionnaire text. Evidence suggestions are examples; relevance depends on the assessed service and the access available to each party.

Q01–Q12 establish scope before technical review

IDModuleVendor questionPossible evidence or context
Q01Vendor profileIdentify the legal entity that contracts for and delivers the assessed service.Contracting details or corporate profile
Q02Vendor profileDescribe the service, intended use, and functions included in the assessment scope.Service description or scoped architecture summary
Q03Vendor profileList delivery models, hosting regions, and customer-controlled deployment choices.Current deployment documentation
Q04Vendor profileName contacts for commercial, security, privacy, incident, and technical follow-up.Contact and escalation matrix
Q05Data handlingIdentify the information categories the service stores, processes, transmits, or can access.Data inventory or service-specific data list
Q06Data handlingProvide a current data-flow view covering ingress, storage, transfers, and deletion paths.Diagram with systems and boundaries labeled
Q07Data handlingState storage and processing locations, including relevant fourth-party locations.Hosting and supplier location register
Q08Data handlingDescribe primary and backup retention, customer-configurable periods, and deletion verification.Retention schedule and deletion procedure
Q09GovernanceName accountable roles for security, privacy, continuity, and service operations.Responsibility matrix or policy ownership list
Q10GovernanceList policies relevant to the assessed service, with owner and latest review date.Policy index rather than unrestricted policy files
Q11GovernanceDescribe how service risks and exceptions are recorded, approved, and re-examined.Risk or exception workflow
Q12GovernanceDescribe general and role-specific security training for personnel supporting the service.Training curriculum and completion summary

Scope answers are not administrative filler. Q02, Q05, and Q17 define which later evidence is relevant. If a vendor answers for its corporate environment while the buyer is assessing one hosted product, apparent contradictions will follow.

Q13–Q32 examine access, technology, development, and monitoring

IDModuleVendor questionPossible evidence or context
Q13Identity and accessList authentication methods available to customer users, including SSO and MFA options.Product configuration documentation
Q14Identity and accessExplain how privileged access is requested, approved, limited, and reviewed for the assessed service.Privileged-access workflow and review record
Q15Identity and accessDescribe joiner, mover, and leaver handling for workforce and contractor access.Access lifecycle procedure
Q16Identity and accessList customer administrator roles, permissions, audit events, and options for restricting vendor support access.Role matrix and audit-log documentation
Q17InfrastructureIdentify infrastructure providers, major service components, and shared-responsibility boundaries.Architecture diagram or responsibility matrix
Q18InfrastructureDescribe asset inventory, configuration baselines, and detection of unauthorized changes for in-scope components.Inventory and configuration-control summary
Q19InfrastructureDescribe encryption in transit and at rest, including responsibility for key generation, storage, rotation, and recovery.Cryptographic architecture or key-management summary
Q20InfrastructureExplain tenant separation or environment isolation and how the design is evaluated.Architecture and scoped test summary
Q21Secure developmentDescribe the development lifecycle and where code review and security checks occur.Development lifecycle diagram
Q22Secure developmentExplain how third-party code and dependencies are inventoried and evaluated.Dependency inventory process or component report
Q23Secure developmentSummarize pre-release testing and the route for documenting accepted exceptions.Release checklist and exception workflow
Q24Change managementDescribe production change approval, deployment, rollback, and customer notification options.Change procedure and sample record
Q25Vulnerability managementList vulnerability discovery inputs, scanning coverage, and testing cadence.Coverage summary and recent dated output
Q26Vulnerability managementExplain prioritization and remediation targets, including who can approve exceptions.Remediation policy and exception record
Q27Vulnerability managementProvide the date, scope, and status of the latest relevant independent security test.Controlled report or executive summary
Q28Vulnerability managementProvide the reporting channel for suspected vulnerabilities and describe triage.Disclosure page or internal workflow summary
Q29Logging and monitoringList security-relevant events recorded for the service and administrative activity.Event catalogue or logging specification
Q30Logging and monitoringState log retention, integrity measures, access restrictions, and time-synchronization approach.Logging architecture and retention configuration
Q31Logging and monitoringDescribe monitoring coverage, alert triage, escalation, and on-call boundaries.Monitoring and escalation procedure
Q32Logging and monitoringList audit events customers can view or export and identify known gaps.Product documentation or sample event schema

Avoid combining multiple controls into an unexplained yes/no cell. Q19, for example, asks about data state and key responsibility because “encrypted” alone does not reveal which component is covered or who controls the keys.

Q33–Q48 cover incidents, resilience, fourth parties, assurance, and exit

IDModuleVendor questionPossible evidence or context
Q33Incident responseDescribe incident roles, severity model, and the latest exercise date.Response plan index and exercise summary
Q34Incident responseDescribe the customer-notification decision process, channels, contacts, and contract-specific timing inputs.Communication workflow and contact matrix
Q35Incident responseExplain how event evidence, timelines, and customer communications are preserved during response.Case-management or evidence-handling procedure
Q36Incident responseDescribe post-incident review and how corrective actions receive owners and status.Redacted review template or action log
Q37ContinuityIdentify dependencies and recovery priorities for functions in the assessed scope.Business impact or dependency summary
Q38ContinuityDescribe backup scope, separation, restoration method, latest test date, and result.Backup design and restoration-test summary
Q39ContinuityDescribe the latest continuity or recovery exercise scenario, scope, date, and unresolved actions.Exercise report or action register
Q40ContinuityState availability design, failover assumptions, offered recovery targets, and material exclusions.Resilience architecture and service terms
Q41Fourth partiesList fourth parties supporting critical functions or handling customer information for the service.Service-specific supplier register
Q42Fourth partiesDescribe how relevant fourth parties are selected, monitored, and re-evaluated.Supplier review workflow
Q43Fourth partiesDescribe the process for fourth-party changes and customer notice or choice, where offered.Change process and customer documentation
Q44Fourth partiesIdentify geographic, provider, or single-component concentrations that could affect continuity.Dependency map and treatment notes
Q45AssuranceList current certifications, attestations, tests, or audits with scope, period, and exclusions.Scoped certificate, report, or summary
Q46AssuranceList material open findings, exceptions, or qualifications relevant to the use case and their current treatment status.Findings register or treatment summary
Q47ExitDescribe customer export formats, data portability, access period, and transition assistance at exit.Export documentation and service terms
Q48ExitDescribe return or deletion across primary, replicated, and backup data, including available confirmation.Offboarding and deletion procedure

This core set centers information security and operational resilience for technology vendors. Broader procurement reviews can attach organization-approved modules for product quality, commercial viability, sustainability, or other concerns without mixing those decisions into the security score.

Four conditional packs expand 48 questions to 60

Conditional packs keep specialized questions away from vendors that cannot answer them meaningfully. Add a pack only when the feature or access exists in the proposed use case.

IDTriggerAdditional question
A01AI or ML featureIdentify customer inputs, generated outputs, metadata, and the retention applied to each.
A02AI or ML featureState whether customer content is used for model training or tuning, what choices exist, and which providers participate.
A03AI or ML featureDescribe human review, abstention, logging, and communicated limitations for generated output.
P01Privileged integrationList requested permissions, API scopes, network paths, and the purpose of each.
P02Privileged integrationDescribe storage, rotation, revocation, and emergency handling for tokens or secrets.
P03Privileged integrationIdentify recorded integration activity and the customer’s emergency-disable route.
S01Distributed softwareDescribe how releases or packages are signed and how customers can verify origin and integrity.
S02Distributed softwareDescribe update distribution, supported versions, rollback, and handling of failed updates.
S03Distributed softwareState what component or dependency information is available for the delivered package.
H01Personnel accessDescribe approval and scoping of personnel access to customer systems or information.
H02Personnel accessDescribe the managed device or remote-work controls used for that access.
H03Personnel accessExplain how access changes when an assigned person changes role or leaves the engagement.

All four packs produce a 60-question maximum in this model. A vendor with no AI feature, distributed component, privileged integration, or personnel access stays at 48 or fewer after applicability filtering.

Route review depth with a transparent 100-point model

The following score is an original routing device, not an external benchmark or measure of vendor quality. It estimates how deeply your intended use deserves review. Rate each factor from 0 to 4, then calculate:

Routing score = Σ (factor rating ÷ 4 × factor weight)

FactorWeightRating 0 anchorRating 4 anchor
Information exposure30No organizational information beyond public materialBroad access to restricted or high-impact information
Access privilege25No account, integration, or environment accessAdministrative, production, or extensive write access
Operational dependency20Optional service with a simple workaroundService interruption stops a critical workflow without a practical workaround
Integration depth15Isolated or manual exchangePersistent agent, network connection, or bidirectional API integration
Exit friction10Straightforward export and replacementComplex migration, proprietary dependency, or concentrated knowledge

Intermediate ratings describe conditions between the anchors. A conservative pilot can rate an unknown factor as 4 until intake clarifies it; a team may adopt another documented unknown-handling rule.

ScorePilot routeQuestionnaire depth
0–24Scope screenQ01–Q12 and Q45–Q48: 16 questions, with reviewer discretion to expand
25–49Core reviewAll 48 core questions
50–74Enhanced reviewCore questions plus each relevant three-question pack
75–100Named-reviewer routeTailored questions plus reviewers selected for the data, access, resilience, and exit concerns

Internal policy, contract terms, official requirements, or counsel-led analysis can override these pilot bands. No numeric result authorizes approval by itself.

Fictional worked example: A service receives an information-exposure rating of 3, access privilege of 2, operational dependency of 4, integration depth of 3, and exit friction of 1. Its calculation is 22.5 + 12.5 + 20 + 11.25 + 2.5 = 68.75. Rounded for display, 69 routes to enhanced review. The score explains review depth; it does not say that the fictional vendor is safe, unsafe, compliant, or non-compliant.

Grade evidence separately from the vendor’s answer

Do not convert response vocabulary into a risk score. “No” may describe an irrelevant control, while “Yes” may lack usable proof. Apply a separate evidence level to each material answer:

LevelEvidence stateReviewer interpretation
E0No artifact or verifiable referenceUnsupported claim; request context or record the gap
E1Narrative explanation onlyScope is clearer, but implementation remains uncorroborated
E2Named artifact with owner, date, and relevant scopeReview the content, exclusions, and accessibility
E3Scoped artifact plus validation context such as a test, exercise, or independent reportExamine method, period, findings, and applicability rather than accepting the label

E3 is not automatically decisive. An independent report can exclude the product under review. A recent document can describe the wrong environment. Conversely, an older architecture diagram may remain usable if its owner confirms that the relevant design has not changed.

Open follow-up when one of these conditions appears:

  • The answer conflicts with the cited artifact.
  • “Not applicable” lacks a scope explanation.
  • The artifact excludes the assessed product, region, or period.
  • A planned control is described as operating today.
  • A material answer has no accessible evidence or accountable owner.
  • The answer omits a known exception revealed elsewhere in the questionnaire.

Reviewer labels such as accepted, clarification needed, gap recorded, and escalated describe workflow state. They do not certify a control or erase residual uncertainty.

How to conduct a vendor assessment in seven steps

1. Define the proposed use

Record the service, users, information, integrations, regions, environments, and business workflow. Assess the proposed configuration rather than the vendor’s entire company in the abstract.

2. Route before reading polished answers

Score the inherent use case using information exposure, privilege, dependency, integration, and exit friction. Doing this first keeps the vendor’s writing quality from changing the depth assigned to the use case.

3. Select questions by applicability

Choose the 16-question screen, 48-question core, or relevant add-on packs. Mark exclusions explicitly. Sending all 60 questions to every supplier creates noise without clarifying the actual decision.

Public examples illustrate the value of scope. Carnegie Mellon University’s vendor technology workbook separates SaaS-specific prompts, while the CISA Vendor SCRM Template frames its purpose around normalizing questions for ICT suppliers and providers. These references do not make a local questionnaire equivalent to either source.

4. Issue response instructions

Define the response vocabulary, evidence-ID convention, controlled sharing route, assessment scope, and clarification contact. Ask for explanations that identify product, environment, geography, and exclusions instead of generic corporate statements.

5. Validate claims against evidence

Check artifact scope, date, owner, accessibility, and consistency. Record missing proof without inventing a positive or negative answer. If several questions cite one document, confirm that the relevant sections actually address each claim.

6. Record gaps without rewriting history

Preserve the vendor’s answer, then add a separate reviewer note. Capture the concern, affected use, available compensating measure, owner, decision route, and next trigger. A vendor correction can become a new response version rather than silently replacing the original.

7. Record the decision and its trigger

State who decided, what scope was accepted, which conditions remain, and what event reopens the review. Useful triggers include a material service change, new integration, changed information flow, incident affecting the assessed scope, expired evidence, fourth-party change, or planned exit.

If your organization is completing a customer’s assessment rather than issuing one, use the responder workflow in How to answer security questionnaires: step-by-step guide.

Three failure modes reveal a weak template early

One corporate “Yes” covers several products

The answer may describe headquarters policy while the reviewed product uses a different hosting model or team. Detect this by requiring the service, environment, and evidence scope in separate fields.

Certification replaces question-level analysis

A certificate or attestation is an artifact with a stated scope, period, and exclusions. Record it in Q45, then connect it only to questions the reviewed material actually supports.

More questions replace a decision

A reviewer requests another policy whenever uncertainty appears but never states the unresolved decision. Use one follow-up field that asks: What fact would change the disposition? If no possible answer would change it, further document collection is unlikely to resolve that decision.

Excel, Word, and PDF serve different review moments

FormatFitsPreserve carefullyCommon limitation
Excel or XLSXConditional modules, filtering, evidence registers, and review queuesStable IDs, validation lists, formulas, hidden columns, and version labelCopies can diverge and formulas can be overwritten
WordSmaller narrative reviews and comment-based collaborationTable headers, question IDs, evidence references, and tracked decisionsAggregation and conditional routing are manual
PDFA fixed issued or approved snapshotVisible version, scope, issue date, IDs, and referenced attachmentsSorting, status updates, and evidence navigation are limited

For Excel, keep formulas out of vendor-editable decision columns and protect the review log from external edits. For Word, repeat table headers across pages. For PDF, retain selectable text and explicit evidence IDs rather than embedding unlabeled screenshots.

A simple version convention such as VAQ-2026-08-v1.0 distinguishes the template release from each vendor response. Give each response its own identifier, for example VAQ-Vendor-Service-2026-08-R1. These are naming examples, not prescribed standards.

Map frameworks through a ledger, not a marketing label

Calling a questionnaire “ISO 27001 aligned,” “NIST ready,” or “CAIQ compatible” can imply more than topical overlap. Keep framework mapping in a separate ledger with seven fields: source name, source version, source control or question ID, local question ID, mapping rationale, reviewer, and verification date.

Before reproducing wording from CAIQ, HECVAT, SIG, ISO publications, or another maintained framework, obtain the current source from its owner and check its usage terms. This article intentionally supplies original questions rather than copied framework content.

A mapping ledger also exposes version drift. When a source changes, the team can inspect affected local IDs instead of renaming the entire questionnaire. The mapping remains a navigational aid; applicability, conformity, certification, and legal conclusions stay separate.

Automation fits the clerical layer; people retain the decision

Questionnaire automation can assist with importing rows, preserving IDs, detecting duplicates, routing owners, proposing evidence references, and flagging unanswered fields. Human review remains relevant where the work involves scope, exceptions, conflicting evidence, disclosure choices, or acceptance of a gap.

A generated draft is still a claim. Citation to a source document makes its basis inspectable, but the reviewer still checks whether the source covers the service and whether the wording overstates it.

Compliance Concierge addresses the responder side of this workflow: it drafts answers from a customer’s uploaded evidence, cites the supporting documents, and keeps export behind human review. It does not decide whether a vendor is suitable or turn an answer into a compliance determination. AI Security Questionnaire Automation With Human Review explains that division of work in more detail.

Frequently asked questions

What is a vendor questionnaire?

A vendor questionnaire is a structured request for supplier-provided information about a defined service or relationship. A usable version records the answer, explanation, evidence reference, evidence date, and accountable contact. The vendor supplies those fields; the reviewer records conclusions separately.

What is a vendor assessment form?

A vendor assessment form is the internal record of scope, validation, unresolved gaps, follow-up, disposition, and review triggers. It can reference a vendor questionnaire, but it should not let the supplier edit internal decision rationale.

What is a TPRM checklist?

A third-party risk management checklist tracks the wider operational process: intake, classification, questionnaire selection, evidence review, decision, monitoring triggers, and exit. The questionnaire is one input to that checklist rather than the whole process.

How many questions should a vendor assessment contain?

Question count follows scope rather than an industry-wide target. This model offers a 16-question screen, a 48-question core, and four three-question add-on packs. If every pack applies, the maximum is 60. Internal policy, contractual context, official requirements, and specialist judgment can produce a different route.

Can I use this as a free Word, Excel, or PDF template?

Yes. Paste the tables into a four-sheet workbook for routing and analysis, a Word table for narrative collaboration, or a PDF for a fixed issue copy. Preserve question IDs, version, scope, evidence references, and a separate internal review record across formats.

Can a completed questionnaire prove that a vendor is compliant?

No. It records claims, evidence, and review decisions within a stated scope. It does not establish regulatory applicability, legal interpretation, certification, or conformity by itself. Verify those matters against current official sources and qualified counsel where relevant.

What should I do first?

Create the four workbook sheets, paste Q01–Q48, and select one pilot service. Complete Q01–Q12 internally before sending the questionnaire. If those answers leave the information flow, access model, or operational dependency unknown, resolve the scope first; the remaining questions will then have something concrete to assess.

From guidance to finished work

Answer the next questionnaire with evidence.

Upload the questionnaire and the policies behind it. Compliance Concierge drafts cautious, cited answers while every final decision stays with a human reviewer.

The questionnaires this covers

This article discusses the questionnaires below. Each page explains how that workbook is structured and what answering it actually involves.

Continue reading