Ask fewer questions with a clearer purpose
A long security questionnaire can look thorough while failing to address the service your business will use. Start by describing the proposed use, information, integrations and access. The third-party risk checklist places that intake in the wider relationship lifecycle. Then ask questions that would change the approval decision or conditions.
NIST SP 800-161 Revision 1, Update 1 supports risk-based supply-chain assessment.1 NIST's final SP 1326 adds ICT-supplier due-diligence considerations.2 The questions below are an original working set, not a reproduction of either publication or a universal regulatory questionnaire.
Prepare the context before sending questions
Tell the supplier which service and environment are being evaluated and what your organization expects to do with them. Identify the review period, contact and appropriate method for sharing sensitive evidence.
Ask the business requester to confirm the planned data and privileges. A supplier cannot answer accurately if procurement describes a low-risk scheduling tool while the implementation team intends to upload confidential client records.
Determine review depth from inherent exposure. Sensitive data, production administration or a hard-to-replace service justifies more scrutiny than a low-impact, easily substituted tool. Do not use the same lengthy questionnaire for every relationship simply because it already exists.
Essential question groups
Service and responsibility
- Which exact service, environments and legal entities does your answer cover?
- Which controls are your responsibility, and which must our organization configure or operate?
- Which material subcontractors or hosting services support this use, and how are relevant changes communicated?
Request an explanation of exclusions. “Company-wide” may still omit a newly acquired service or a separate regional environment.
Information handling
- What information is collected, processed, stored or generated for the service, and where?
- How are retention, return, export and deletion handled for our use?
- How are important confidentiality and privacy requirements addressed, including access to customer information?
Do not impose a guessed legal requirement. Your own privacy and legal reviewers should establish applicable roles and terms. The questionnaire gathers facts needed for that discussion.
Access and administration
- How is staff and administrative access approved, restricted, reviewed and removed?
- How are service accounts and support access managed, including accountability and expiration where relevant?
- What authentication options and customer access controls exist, and which are optional or dependent on configuration?
Ask for a scope-specific explanation rather than an unrestricted account list. The goal is meaningful assurance about the process, not unnecessary disclosure of personal information or secrets.
Changes and vulnerabilities
- How are relevant software and configuration changes reviewed, tested and authorized?
- How are security issues identified, prioritized and addressed, including exceptions?
- What testing or assessment evidence is available for the service, and what are its dates and boundaries?
Avoid inventing universal patch deadlines. Compare the supplier's practice with the needs and obligations of the proposed relationship, then record any required conditions through the normal governance process.
Operations, incidents and recovery
- How are service or security anomalies detected, escalated and handled?
- What incident communication arrangements can be agreed for this relationship?
- What is backed up, how is restoration checked, and what service dependencies remain?
- What availability or recovery commitments are actually offered in the contract, rather than informally described?
Keep proposed contractual commitments separate from observed test results. A successful test can support a defined scenario without proving every future interruption will meet the target.
Supporting evidence and exit
- Which independent reports or certificates cover this service, and how can an authorized reviewer inspect them?
- What customer responsibilities, exceptions or limitations should our reviewer consider?
- How can we retrieve usable information and revoke integrations when the relationship ends?
There is no requirement to ask all 19 questions in every review. Select and adapt them to the use. Ask additional questions where the business model or jurisdiction makes them necessary.
Evaluate answers rather than counting yes boxes
Use a consistent disposition with a reason:
| Disposition | Meaning | Next step |
|---|---|---|
| Supported for the stated purpose | Relevant evidence supports the claim within scope | Record source, date and limits |
| Partly supported | Evidence covers only part of the proposed use | Clarify the remaining boundary |
| Supplier claim not yet checked | Explanation exists without sufficient support | Request appropriate follow-up |
| Contradictory or concerning | Available facts conflict or indicate a gap | Investigate and escalate as needed |
| Not applicable with rationale | The question does not fit the scoped use | Retain the explanation |
An empty answer is not automatically a failed control. It is missing information. A checked “yes” is not automatically evidence of an effective control. Both should be evaluated in context.
NIST SP 800-53A distinguishes examination, interview and testing.3 That helps reviewers choose follow-up: inspect a relevant record, discuss a responsibility or verify a safe scenario, rather than repeatedly request another written assertion.
Worked example: a backup answer that needs clarification
This fictional supplier answers “yes” to backups and says recovery is tested regularly. Its supporting document describes infrastructure backups, while the proposed service includes customer configuration stored in a separate component.
The reviewer asks which records and configuration the test covered, when it was performed and whether the restored service was usable. The supplier clarifies that the separate component is excluded from the existing exercise.
The result is partly supported, with a material gap for the proposed use. The business could seek further evidence, negotiate a condition, maintain its own authorized export or choose another arrangement. The proper authority makes that decision; the reviewer does not silently mark the answer complete.
A follow-up action records its owner, evidence needed, due date and what use is permitted meanwhile. If the supplier later supplies an expanded test, retain the earlier answer and explain how the disposition changed.
Handle reports and sensitive material carefully
Check the named organization, service, dates and permitted use of a supplied report or certificate. Inspect relevant exceptions and customer responsibilities. Do not interpret a company logo or trust-center badge as complete coverage.
Use approved sharing and access controls. Redaction may be appropriate, but it should preserve the information needed for the review. Do not ask for passwords, private keys or unnecessary customer data as evidence.
If a supplier cannot share a detailed document, discuss a controlled review or another suitable source. Record the resulting limitation instead of pretending the unavailable material was inspected. The evidence-collection guide explains how to retain scope and provenance through a controlled handoff.
Close with a decision, not a questionnaire score
Summarize the proposed use, criticality, important supported facts, unresolved questions and conditions. Record reviewers and the authorized decision, then define ongoing review triggers.
Keep the questionnaire connected to supplier intake, contract decisions, onboarding and exit. A numerical answer score can be a sorting aid if its method is clear, but should not replace evaluation of a critical unresolved dependency.
The most effective questionnaire produces a smaller set of better-supported decisions. It should help your business understand exactly what it is relying on, what remains uncertain and who owns the next step.
Sources and references
-
NIST. Cybersecurity Supply Chain Risk Management Practices, SP 800-161 Revision 1, Update 1 (2024-11-01). Current guidance treats supplier risk through its lifecycle; supports risk-based due diligence and monitoring. ↩
-
NIST. Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide, SP 1326 (2026-07-08). Final July 2026 guide concerns ICT suppliers and risk-prioritized due diligence; not a general legal checklist for every supplier. ↩
-
NIST. Assessing Security and Privacy Controls, SP 800-53A Revision 5 (2022-01). Describes examination, interview and testing methods; source examples are adapted, not a claim to meet federal requirements. ↩

