Vendor questionnaires
Build and manage questionnaires that speed up due diligence without endless bespoke answers.
Vendor questionnaires
Questionnaires are an interface between you and a vendor. Done well, they reduce risk and speed procurement.
In the current product these are vendor-assessment templates: you build the questions, assign a template
to a vendor, send the generated link to the vendor, and review the submitted responses on that vendor's
detail page. The external respondent uses /vendor/assessment/[assignmentId] without access to the rest of
your organization.
Use this when…
- you need to assess vendor security posture
- you need consistent vendor due diligence records for audits
- you’re standardizing repetitive customer/vendor questions
Recommended workflow
- Build a small template set:
- baseline security questionnaire
- privacy/data processing addendum (GDPR is a common reference point)
- Ask only what you will actually use to make decisions.
- Track completion and follow up.
- Store evidence (reports, answers) and link them to the vendor record.
Template directory and builder
/vendors/questionnaires lists templates and their linked frameworks. Create a reusable template rather
than cloning a customer spreadsheet into every vendor record. Open /vendors/questionnaires/[templateId]
to manage sections/questions, expected answer types, help text, and framework relationships.
Only active templates can be assigned from the vendor register. Keep retired or superseded templates for history instead of editing past meaning in place.
Assessment workflow
- Select the vendor and an active template.
- Confirm the vendor owner and contact responsible for follow-up.
- Send or copy the recipient link; the token grants access to that assignment, so handle it accordingly.
- Monitor completion and send reminders when needed.
- Review responses and supporting evidence rather than treating submission as approval.
- Update vendor inherent/residual risk, privacy facts, mitigations, and monitoring requirements.
- Record the review outcome and retain the assessment in the vendor activity trail.
Questions should drive decisions. If an answer would not change approval, mitigation, monitoring, or contract terms, consider removing it. Conversely, a yes/no answer to a critical control may require an artifact or follow-up explanation.
Compliance angle
- SOC 2 / ISO 27001: vendor oversight and risk management.
- GDPR: vendor/subprocessor assessment and contractual controls.