Client Security Questionnaire: How to Answer It Without Guessing

A client security questionnaire is a set of questions a customer, insurer or prime contractor sends a supplier before signing, asking how the supplier protects the data it will hold. It tests evidence and ownership more than good intentions, so every answer needs a document behind it and a named person who keeps that document current.

The questionnaire arrives on a Tuesday and is due on Friday. Forty-one questions, a customer’s logo at the top, and a note saying the contract cannot be signed until it comes back.

It lands in the sales inbox. It is forwarded to the operations manager, who forwards it to the IT provider, who answers the eleven questions that belong to them and leaves the other thirty.

By Thursday somebody has written yes against most of those thirty. Yes is the answer that gets the contract signed, and nobody in the building can say for certain that it is wrong.

By Friday it is gone and nobody keeps a copy. The spreadsheet sits in somebody’s downloads folder, three of the answers were guesses, and the next customer will ask most of the same questions again in March.

The form is a procurement document with a deadline on it, and the deadline is the part businesses underestimate. A fortnight disappears into it, and the answers still go out as guesses.

That cost is already running. It shows up in senior hours and in tenders that go elsewhere, so it is worth pricing before the next form arrives.

The figures below are illustrative. Take a twenty-two person engineering consultancy in Christchurch that sells to two large corporates and a council.

Four questionnaires a year, none of them reusable, at about thirteen hours each between a director and an operations manager. At a blended $110 an hour that is roughly $5,700 a year of senior time spent retyping answers the firm has written before.

Then a tender the firm expected to win. The buyer set a two-week window for the security pack, the firm took five weeks, and the work went to a competitor.

The debrief gave one reason, and it was not price. That contract was worth $48,000, a one-off exposure sitting alongside the annual figure.

One boundary before we start. Where the honest answer is a certificate, what ISO 27001 certification involves is a different project on a different timescale, and this article stays with the form that has to go back on Friday.

What Is a Client Security Questionnaire?

A client security questionnaire is a structured set of questions a customer sends a supplier before signing, covering how the supplier protects data, controls access and responds to incidents. Buyers call it a vendor security questionnaire, and their procurement teams file it under third-party risk management, shortened to TPRM. On the buyer’s side the whole exercise sits inside a vendor risk assessment.

Longer versions are called a due diligence questionnaire, or DDQ. The label matters less than the source, because the bigger the buyer the more likely the form was lifted from a standard question set and sent unedited.

Two question sets turn up repeatedly. The Consensus Assessment Initiative Questionnaire, known as the CAIQ and published by the Cloud Security Alliance, and Standardized Information Gathering, known as SIG, both run to hundreds of items and both assume a cloud provider is answering.

Recognising the source saves an afternoon. A question that reads as nonsense against your business is often a hosting question asked of a firm that hosts nothing, and it can be closed with a reason in one line.

So read the covering email before the questions. It names who wants the form back and by when, and whether a person will read your answers or a scoring tool will.

Why does a customer send one at all?

Because the customer carries a duty it cannot pass to a supplier. Information privacy principle 5 under the Privacy Act 2020, the statute that replaced the Privacy Act 1993, requires an agency giving personal information to a service provider to do everything reasonably within its power to prevent unauthorised use or disclosure.

The questionnaire is that agency showing its working. Read the form as the customer’s own audit trail and the tone of it changes, because the person who sent it is under the same obligation you are being asked about.

That reading also tells you what to send back. Give the buyer a document they can put in their own file, and you have solved their problem as well as yours.

Ask who inside the buyer has to sign it off. A form headed for a risk committee needs different attachments from one a project manager is ticking through.

Which businesses get sent one?

Any business that holds, moves or can reach another organisation’s data. Professional services firms, software suppliers, payroll bureaux, logistics operators, marketing agencies and contractors with after-hours building access all receive them.

Size is a poor predictor. A six-person firm handling a bank’s customer records gets a longer form than a fifty-person firm that supplies stationery. The form is scaled to the data, so the supplier holding the least gets the shortest one.

What Do Buyers Check on a Security Questionnaire?

Buyers check evidence and ownership. Any business can say it has a control, and a buyer can only verify the one that is written down, covers everything it should, and gets checked by a named person on a known date.

Client security questionnaire: how a question is translated, routed to evidence and assigned to an owner

Take the most common question on any form. Do you enforce multi-factor authentication, usually shortened to MFA. Answered as asked, that is a yes for every business running Microsoft 365.

Answered as meant, it becomes three questions. On which systems, enforced by which policy, and who confirmed last month that no account carries an exception.

Most answers fall over on the third question. The control is running and the business is not at risk; nobody owns the monthly check, so there is nothing to attach.

The same shape repeats on joiners and leavers. A buyer asking about staff departures wants the record of a review, so point them at how access is granted and removed and attach the last one you ran.

How do you find the question behind the question?

Read each question for three things: the scope it assumes, the enforcement it implies and the owner it never names. A question names a control and stops there, which is why a bare yes answers none of them.

Write those three down and the box fills itself. A question about backups becomes the systems covered, the schedule they run on, and the date of the last restore test.

Do that translation once and keep it. You will paste the same three lines into the next four forms.

Which Questions Come Up on Nearly Every Security Questionnaire?

Nine come up on every form, whatever the buyer’s industry: access control, multi-factor authentication, patching, backup and restore, incident response, staff training, subcontractors, data location and breach notification. Answer those nine once and most of the next questionnaire is already written.

Each buyer words them differently. Build the answer library around the nine and treat everything else on a form as a one-off.

The question as asked What it is testing What to attach
Do you enforce MFA? Scope and exceptions Conditional access policy export, dated, with the exception list
How often do you patch? Whether patching is measured Patch compliance report for the last full month
Do you back up your data? Whether the restore was tested Date and result of the last restore test
Do you have an incident response plan? Whether anyone has opened it The plan, plus the date it was last exercised
Do you train staff on security? Completion rates, by name Training completion report by name
Who are your subcontractors? Whether you know Supplier list naming who touches customer data
Where is our data stored? Country and provider Data map naming the region for each system
Will you notify us of a breach? The timeframe you will commit to Breach clause and the internal escalation path
Do you hold certification? Evidence or ambition Certificate and scope statement, or a dated plan

Read the breach notification row carefully, because the law sets a floor a contract cannot lower. The Office of the Privacy Commissioner requires an agency with a privacy breach that has caused or is likely to cause anyone serious harm to notify the Commissioner and the affected people as soon as it is practically able.

A buyer will usually want a shorter clock than that and a named contact. Agree a timeframe you can meet on a Saturday, and write it into the plan you would follow on the day so the commitment and the runbook say the same thing.

The current edition is ISO/IEC 27001:2022, and the official abbreviation carries the IEC. That is why a buyer’s form asking about ISO 27001 and a certificate reading ISO/IEC 27001 can look like two different standards, and why nobody should redo the work on the strength of it. SOC 2, short for System and Organization Controls, sits on the same row of many forms and is a different report from a different scheme, so answer for whichever one you hold and name it.

What Belongs in a Security Evidence Pack?

Twelve artefacts cover every question in the list above and most of what sits around it. Assembling them once turns the second questionnaire from a fortnight into an afternoon, which is the argument for building the pack in an ordinary week, ahead of any deadline.

Four of the twelve come from your IT provider: the MFA enforcement report, the patching report, the access review record, and the backup with the date of its last restore test.

Four come from the business itself: the asset register, the supplier list, the data map and training completion. Nobody outside the business can assemble these, which is why they are the ones that go missing.

Four come from filing the business already has: the incident response plan, the policy set, the insurance schedule and the disposal certificates. These normally exist, and the date on them is the problem.

Security questionnaire evidence pack of twelve artefacts, with the four that go stale inside ninety days

Give every artefact an owner and a date. An asset register with no name against it is a document that was true once, and a buyer who spots an undated export will ask for a current one.

Store the pack somewhere a director can reach without asking anybody. If it only exists in one person’s OneDrive, it leaves when they do.

Keep it in one folder with a date on it. The next person to send it should not have to ask where anything is.

How often does each artefact go stale?

Four of the twelve go stale inside ninety days. The MFA enforcement report, the patching report, the access review record and the training completion report all describe a moving state, so a buyer reading a six-month-old export learns nothing from it.

The other eight hold for about a year. Put the four short-life items on a quarterly calendar reminder with a named owner, and the pack stays ready to send without anybody thinking about it.

How Should You Answer a Question You Cannot Say Yes To?

Say no, and attach a dated plan naming who is doing the work and when it finishes. Three answers are defensible on a client security questionnaire, and a yes chosen because it reads better is not among them.

Yes with the evidence attached. No with a dated remediation plan. Not applicable with a reason a stranger can follow without ringing you.

Client security questionnaire: the three defensible answers and the overstated yes that can void a claim

Buyers accept a no more often than suppliers expect. A deal is far more likely to end when the buyer discovers at contract stage that an earlier yes was decoration, because that discovery costs them the work they had already done on you.

Lawyers lift questionnaire answers into the supply agreement as warranties. A claim about encryption then becomes something the business has promised a customer it will do, with a remedy attached if it turns out to be untrue.

On a cyber insurance proposal form the same overstatement is dearer again. An insurer that finds the answer was wrong has grounds to question the claim in the week the business needs the policy to pay.

Should you ever leave a question blank?

No. A blank reads as a hidden no, and it invites the follow-up call the questionnaire was sent to avoid. Write not applicable and give one line of reason, such as the business holding no cardholder data and running no payment terminal.

The same applies to a question you do not understand. Ask the buyer what they mean, in writing, and attach the exchange to your answer.

Who Should Sign a Client Security Questionnaire?

A director or business owner should sign it. The signature turns a set of answers into a commercial representation the business stands behind, which is a different act from confirming that a setting is switched on.

The technical person is the wrong signatory for a reason that has nothing to do with competence. An IT provider can speak for the systems they manage and cannot speak for the subcontractor your operations team engaged last March.

Split the form before anybody writes in it. The provider supplies artefacts and operations confirms process. The director reads the whole thing and signs.

What should the IT provider be asked for?

Ask for the artefacts, and not for the answers. A provider can produce the conditional access export, the patch compliance report and the backup restore log inside a working day, and those three close about a third of a typical form.

Where a provider offers to complete the whole form, read it before it goes. Their scope and your business are rarely the same shape, and the questions about staff, subcontractors and physical premises belong to you.

Write that split down the first time and reuse it. Twenty minutes on a Monday saves the argument on the Thursday.

How Long Should a Client Security Questionnaire Take?

The first one takes fifteen to twenty hours, and the ones after it take two or three once the evidence pack exists. Most of that first block goes on finding documents. Very little of it goes on writing.

That gap decides more contracts than the answers do. A firm that returns a complete pack in two days is easier to buy from than a better-secured competitor that takes three weeks, because the buyer has a procurement deadline of their own.

Turnaround is also the one thing on this list a small business can win on outright. Nobody expects a twenty-person firm to out-secure a bank, and everybody notices the supplier who comes back first.

So put a target on it. Five working days from receipt to return, measured, is a number a sales meeting can hold somebody to.

What slows the first one down?

Waiting on reports that exist but have never been exported. Three or four days of a first questionnaire goes on chasing a provider for figures that take them twenty minutes to produce.

Ask for those exports in the first hour, before anybody starts writing. Send the list of nine recurring questions with the request, so the provider knows what the reports are for.

How Much Does It Cost to Get Questionnaire-Ready?

About $3,800 once, and around $95 a month afterwards, for a business of twenty to forty staff. Take the consultancy from the opening and put those numbers against its own.

The one-off covers the gap review, the twelve artefacts and an answer library written against the nine recurring questions. The monthly figure keeps the four short-life artefacts current, which is $1,140 a year.

Answering time then drops from about thirteen hours a questionnaire to three. Across four forms a year that is roughly $1,300 of senior time, and the monthly fee adds $1,140.

So the firm spends about $2,440 a year where it was spending $5,700. That is $3,260 back every year against $3,800 paid once, and the pack has covered itself before the second year is out.

The $48,000 tender sits outside that arithmetic and is the larger number. The two-day turnaround addresses it, and that only exists once the pack does.

Put both figures in front of whoever approves the spend. An owner wants the annual saving and the lost tender on the same page.

What makes one business cost more than another?

The number of systems holding customer data, and whether anyone has written them down. A firm running four systems it can name costs less to prepare than a firm running fourteen it discovers during the gap review.

The starting point matters more than the size. A business that has never run a restore test is buying the control as well as the evidence, and the way to separate the two is to find out what the true answers are before a buyer asks.

How Do You Answer a Security Questionnaire, Step by Step?

Read the whole form before answering a single question, because a third of it will be out of scope and knowing that changes how you budget the week. Then work through the six steps below.

  1. Sort every question into three piles on the first read: evidence exists, control exists but evidence does not, and control does not exist. An hour spent here saves three days later.
  2. Send the evidence list to your IT provider the same day. Name the report you want and the date range, because a vague request comes back as a screenshot.
  3. Answer the not applicable questions first, with one line of reason each. That usually clears a quarter of the form and shows the buyer you read it.
  4. Write each yes against its artefact, naming the document and its date inside the answer box. An answer that cites its own evidence rarely draws a follow-up question.
  5. Write each no with a dated plan, a named owner and a completion date the business can meet. A date you miss is worse than the no was.
  6. Have a director read the whole form and sign it. Then save the answers and the artefacts together as the pack, so the next client security questionnaire starts at question one with the work already done.

Frequently Asked Questions

What is the difference between a security questionnaire and a security audit?

A questionnaire asks the supplier to describe and evidence its own controls, and an audit sends someone in to examine the environment and establish what those controls are. Only one of them arrives with somebody else’s deadline attached. Businesses that have never been audited often discover during their first questionnaire that they cannot answer eight or nine questions with evidence.

Can you refuse to complete a client security questionnaire?

You can, and it usually costs the contract. Buyers treat a refusal as a no to every question on the form. A better approach is to answer the questions that apply and mark the rest not applicable with a reason. Where a form clearly assumes a different kind of supplier, ask the buyer to shorten it while there is still time to use the answer.

Do you need ISO 27001 certification to answer a buyer’s security questions?

No. New Zealand buyers generally accept documented controls with evidence attached, and certification only becomes necessary when a specific customer or sector requires it. A dated remediation plan against a gap is accepted far more often than businesses expect.

What happens if you answer a security questionnaire incorrectly?

An overstated answer reappears as a warranty in the supply agreement, so an inaccurate yes becomes something the business has contractually promised. On an insurance proposal form it gives the insurer grounds to question a claim. An answer corrected before signing costs one awkward email. After an incident it is a matter for the lawyers on both sides.

How much does a security evidence pack cost to build?

For a business of twenty to forty staff, expect around $3,800 to assemble the twelve artefacts and an answer library, with roughly $95 a month to keep the short-life items current. Businesses running more systems, or systems nobody has documented, sit above that range. The saving comes from the answering time, which drops from around thirteen hours a questionnaire to three. On four questionnaires a year the pack covers its own cost before the second year is out.

Is the customer or the supplier responsible for data security?

Both are, and that is why the questionnaire exists. The Privacy Act 2020 puts a duty on the customer to take every reasonable step in its power to stop a supplier misusing or disclosing the personal information it hands over, so the customer keeps that duty after the data has been handed over. The supplier remains responsible for its own systems and staff.

Does a small business get a shorter questionnaire than a large one?

No. The length of the form follows the sensitivity of the data, so a six-person firm holding health or financial records will receive a longer questionnaire than a fifty-person firm supplying office consumables.

Can an IT provider complete a security questionnaire for you?

An IT provider can answer the questions covering the systems they manage and supply the reports behind them, which covers about a third of a form. Questions about staff, subcontractors, premises, insurance and contracts belong to the business. Read anything a provider drafts on your behalf before it is signed, because the signature binds the business.

How quickly must a New Zealand business report a privacy breach?

As soon as it is practically able, where the breach has caused or is likely to cause anyone serious harm, and the Office of the Privacy Commissioner and the affected people are both notified. Buyers ask for a shorter contractual timeframe on top of that, commonly twenty-four or forty-eight hours to notify them directly.

What is a CAIQ or a SIG questionnaire?

The Consensus Assessments Initiative Questionnaire and Standardized Information Gathering are two standard question sets that large buyers send instead of writing their own. Both run to hundreds of items and both assume a cloud service provider is answering, so a business that hosts nothing will find whole sections out of scope. Recognising the source lets you close those questions quickly with a reason.

What should you do first when a security questionnaire arrives?

Read the whole form and sort every question into evidence exists, control exists without evidence, and control does not exist. Send the evidence list to your IT provider on the same day, because a first questionnaire runs to five weeks when the exported reports arrive last.

Exodesk has supported South Island businesses since 1989 and works with clients across Canterbury, Otago and Southland from offices in Christchurch and Dunedin. Our team works through a supplier security assessment with you, gathers the evidence behind each answer, and leaves you with a pack you can send again.

Contact us today to discuss how we can help your business or connect with us on LinkedIn to stay updated with more insights.

Next step

Could you answer the next one in two days?

Most of the delay is not the answering. It is hunting for the policy nobody can find, and guessing at controls nobody has checked. A free IT assessment establishes what your answers actually are and gathers the evidence behind them, so the next form starts with the work already done.

For the security work behind those answers, see cyber security.

Start typing and press Enter to search

Franchise IT support: five identical franchise shopfronts connected to a head office, two of them off the group standardIT support for law firms: a law office desk with a matter file and ledger screen in front of a deed safe Call Us Now