Vendors

Vendor questionnaires

Build templates, send assessments, and review answers with AI assistance, including the vendor's portal.

RolesViewerEditorAdminRoute/vendors/questionnairesShown toCompliance organizations

What it is

Questionnaires are how you ask vendors structured questions and keep their answers as evidence. A template defines the questions; an assessment is one template sent to one vendor, answered in a public portal, and reviewed by you question by question. AI reads the vendor's gathered documents to suggest answers to the vendor and to score the submission for you.

Where to find it

VendorsQuestionnaires
Questionnaire templates list with framework, type, and status filters and the insight stripQuestionnaire templates list with framework, type, and status filters and the insight strip
Templates. System templates ship with Noru and cannot be deleted.

Key actions

Create and build a template

Click Create Template. Noru creates "New Questionnaire Template" and opens the builder.
Under Template details, rename it, add a description, and pick frameworks ("Select compliance frameworks..."). To start from an existing one, use "Choose a template to base this on...".
Click Add your first question. For each question set the text, help text, category ("e.g., Security, Privacy, Operations..."), control reference ("e.g., SOC 2 CC6.1, ISO 27001 A.9.1.1..."), and options where the type needs them.
Drag questions to reorder. Use Preview mode ("This is how your questionnaire will appear to users.") to check the vendor's view.
Click Save.
The template builder with template details, the question list, and an inline question editorThe template builder with template details, the question list, and an inline question editor
The builder. Control references are what make answers useful as evidence.

Activate a template

Set the status to Active in Template details and save. Only active templates appear in the assign dialog and in bulk sends. Delete Question removes one question; Delete Template removes the whole template and cannot be undone.

Assign a questionnaire to a vendor

Open the vendor's Assessments tab and click the new-assessment button. The "New assessment" dialog opens.
Choose the Template (system templates carry a System badge) and write a message ("Add a message or instructions for the vendor…").
Under Recipients, pick vendor contacts or Add custom email…. Leaving it empty saves without sending.
Under Schedule & delivery, set the due date (today or later), recurrence (No recurrence, Annual, Bi-annual, Quarterly), and link expiration in days (default 30 days).
Click Send assessment (with recipients) or Save assessment (without).
The New assessment dialog with template, message, recipients, and schedule and delivery sectionsThe New assessment dialog with template, message, recipients, and schedule and delivery sections
Assigning. The submit label changes with whether recipients are selected.

What the vendor sees

The invitation email carries a link that verifies a one-time token and then opens the portal at /vendor/assessment/[assignmentId]. The vendor sees the questions, any "AI-suggested answers" drawn from their public documents, and can attach files. Submit is blocked until every required question is answered. Errors the vendor may meet: Access denied (missing, invalid, or expired link, or the wrong assessment), Assessment submitted (already done), and No questions found.

Review responses

Click Review on the assessment row. The "Review assessment" dialog opens.
Work through each question. Add notes ("Add notes on clarifications needed...") and click Approve, Clarify, or Reject. A decision saves the notes.
Use the sidebar to check Status, Due Date, Assigned By, Assigned To, Recurrence, Portal Link Expiration (7–180 days), Created, Submitted, Reviewed, Notes, and Notification Recipients, and the Quick Actions to send a reminder or change status.
Complete the review to move the assessment to Reviewed.

Clarify emails the vendor and moves the assessment back to In Progress; when they resubmit, only the clarified questions return to pending.

Use the AI assessment

On submission Noru runs an AI assessment automatically; you can rerun it on demand (toast "AI assessment completed"). It shows a Fulfillment Score, an Analysis, and Concerns. Per question, an AI-Suggested Answer with High, Medium, or Low Confidence and Source Documents points at the gathered vendor documents that support it.

From the vendor's Assessments tab: Send reminder (requires recipients), Copy assessment link, and Delete with the Delete Assessment confirmation.

Statuses and fields

StatusMeaningSet by
PendingpendingSent or saved; the vendor has not opened it.Assign
In Progressin_progressThe vendor has started, or a clarification was requested.Vendor portal or Clarify
SubmittedsubmittedAll required answers are in; AI assessment has run.Vendor portal
ReviewedreviewedYou completed the review.You
ExpiredexpiredThe portal link passed its expiration.Time

An Overdue chip appears on any row past its due date.

Question typeVendor enters
Yes/NoOne of two
TextFree text
Single ChoiceOne option
Multiple ChoiceSeveral options
DateA date
NumberA number
File UploadA file, stored as vendor evidence with source Assessment
Review decisionEffect
ApproveAnswer accepted
ClarifyVendor is emailed; assessment returns to In Progress
RejectAnswer recorded as unacceptable; nothing is sent

The templates list shows Name, Frameworks, Version, Questions, Status, and Last updated, with filters Framework, Type, and Status. The insight strip counts Templates, Active, Completion, In progress, and Pending. Bulk Delete templates skips System templates.

Tips and gotchas

The portal link is bearer access: whoever has it can answer. Set a short Portal Link Expiration, send to named contacts rather than shared inboxes, and prefer Send reminder over forwarding the link yourself.

Keep templates short and reference a control on every question. Thirty well-referenced questions get answered; two hundred generic ones get ignored, and the control reference is what turns an answer into evidence.

System templates are maintained by Noru. Base your own template on one to customise it; the original stays available to every organization.

What Noru does not do

The AI assessment scores how completely the answers address the questions against the documents it found; it does not verify that the answers are true, and it has not read the contract. AI-suggested answers are offered to the vendor as a convenience; check the Source Documents before you approve one. Noru does not chase vendors on its own: reminders go out when you click Send reminder.

Last updated on