Answering a security questionnaire

How to answer a security questionnaire, starting with the one you were sent.

Someone in procurement has sent you a spreadsheet. Forty rows, maybe two hundred, a deadline, and a contract that does not move until it comes back. Paste the questions or upload the file and you get every row sorted into data protection, security, commercial and other, a count of what a record could answer, and one line per data protection row on what a good answer contains. No account. Then the guide below says how to answer the rest.

Check the questionnaire you were sentSee a filled-in review

The checker and the guide need no account. The file is read once and not kept.

Check the questionnaire you were sent

Paste the questions or upload the spreadsheet. You get every row sorted into data protection, security, commercial and other, how many a Rowpa record could draft with citations, and what a good data protection answer contains. Free, no account, and the file is not kept.

Copy them straight out of the portal or the spreadsheet. Numbering and bullets are fine. Up to 150 questions.

Free. No account needed.

What you are actually holding

Whatever it is called, and it will be called a vendor security assessment, a supplier assurance questionnaire, a third-party risk questionnaire, a due diligence form or somebody's initials followed by the word Lite, the sheet is four things stacked on top of each other.

Company and contract facts. Legal entity, registered address, who signs, insurance, where you operate. Twenty seconds each, and you know all of them.

Data protection. What personal data you touch on their behalf, who else touches it, where it goes, how long you keep it, what happens in a breach, how a person exercises their rights. Usually a tenth of the sheet, sometimes half if the sender is a public body or a data protection officer rather than a security team.

Security controls. Multi-factor authentication, device encryption, patching, backups, access reviews, malware protection, staff screening, penetration testing. The bulk of a general assessment, and the part that worries small suppliers most.

Evidence requests. Attach your policy. Attach the pen test summary. Attach the certificate. These are not questions, they are file requests, and they are usually the ones that stall the sheet for a week.

The four groups need four different approaches, and treating the whole sheet as one long homework exercise is why it takes people a fortnight. The checker above does the sorting; the rest of this page is the approach for each group.

The rows you can answer today, and what a good answer says

01
Do you keep a record of processing activities?
A good answer names the record, says when it was last reviewed and how many activities it covers, and offers it. "Yes, maintained internally, last reviewed 21 August 2026, 19 activities, extract available on request." A bad answer is the single word Yes, because it invites the follow-up that costs you another week.
02
List every sub-processor that will handle our data
Name, what they do, and the country the data sits in, for each one. The reviewer is checking whether you know, not whether the list is short. If you publish a sub-processor list at a fixed address, give the URL: it answers this row now and every future change without another email.
03
Does data leave the UK or the EEA, and on what basis?
Name the recipient, the country, and the mechanism: an adequacy decision, standard contractual clauses, the UK addendum, or the EU-US framework. "No" is a valid answer if it is true, and a reviewer will check it against your sub-processor list, so the two must agree.
04
What is your breach notification commitment?
Give the number of hours and say what starts the clock. "Confirmed incidents affecting your data, notified within 48 hours of confirmation." Do not promise 24 hours to win the row; you will be held to it, and 72 is the regulator's deadline to a supervisory authority, not yours to a customer.
05
How do you handle data subject requests?
Say who receives them, how you acknowledge, and the deadline you work to, which is one month. If you act as their processor, the honest and correct answer is that you forward the request to them and assist, rather than answering it yourself.
06
Is multi-factor authentication enforced?
Answer per system rather than in general. "Yes on email and on the systems holding customer data; not yet on the accounting package." A partly is a survivable answer. A yes that a reviewer disproves in the next call is not.
07
Backups, and have you tested a restore?
Two different questions, and the second is the one that matters. If you have never run a full restore drill, say so and say when you will. Reviewers see that answer often enough to recognise honesty, and it beats a yes you cannot evidence.
08
Do you use AI tools, and is our data used for training?
The row that arrived in 2025 and is now on most sheets. Name the tools, say what they touch, and state whether the vendor trains on your data. If you have not checked the vendor's terms, check them before you answer this one.

What a drafted review looks like, ten rows

Do you maintain a record of processing activities under Article 30?
Yes. Maintained in Rowpa, last reviewed 21 August 2026, 19 activities.
Your record: review status
List all sub-processors that will handle our data, with hosting location.
Draft from the vendor record. Confirm each processor's current location, agreement and transfer safeguard before sending the pack.
Your record: vendors
Is personal data transferred outside the UK or EEA? On what basis?
Yes, to Stripe Inc. (US) under the EU-US Data Privacy Framework with UK Extension, for payment processing only.
Your record: transfers
What is your data breach notification commitment to customers?
Confirmed incidents affecting your data are notified within 48 hours of confirmation, per our breach procedure.
Your record: breach procedure
Do any of your tools process our data using AI? Is it used for training?
Anthropic API is listed for document drafting. Confirm the applicable account agreement, training terms, retention settings and processing locations before approving this answer.
Your record: AI tools
Is multi-factor authentication enforced for all staff accounts?
Yes. Enforced on email and on the main business systems (Google Workspace, Xero, HubSpot).
Your security posture: MFA
When was your last external penetration test? Please attach the summary.
No external test has been carried out. Dependency scanning runs on every build, and code review is required before merge.
Your security posture: penetration test
Describe your backup and restore testing frequency.
Daily backups to a separate service. Restore has been tested in part: files restored once, no full drill yet.
Your security posture: backups
What is your cyber insurance cover limit?
Yes, cover is in place. The certificate travels with the pack, valid to 31 March 2027.
Your documents: cyber insurance certificate
Provide two customer references we may contact.
Left blank. Rowpa does not record this and will not guess it.
Only you can answer this

Ten rows from a sample review, drafted from a fictional company's record, its security profile and the certificates it has uploaded. The blank row is the point. Nothing is claimed that the record does not hold.

The structure of a security questionnaire

Every questionnaire you will be sent has the same skeleton, whether it is a 30-row sheet from a marketing agency or a 600-row SIG from a bank. There is a cover block that asks who you are. There are sections, each with a heading and a run of numbered rows. Each row has a question, an answer cell that is either free text or a dropdown of Yes, No and N/A, and usually a comments or evidence column beside it. Some rows are parents with sub-questions a, b and c underneath. Some rows are hidden until you answer the row above.

Read the whole thing once before you answer anything. Ten minutes. You are looking for three things: the answer format each section expects, the rows that ask for a file rather than a sentence, and the rows that repeat a question already asked in another section under a different name. Hosting location, sub-processors and international transfers are the same fact asked three ways, and the sheet will be read as one document, so the three answers have to agree.

Then sort the rows into the four groups above. The checker on this page does the first pass for you. On a general vendor security questionnaire the split is usually company facts 10 percent, data protection 10 percent, security controls 70 percent, evidence requests 10 percent. On a questionnaire from a data protection officer or a public body, the data protection share climbs to half.

The standard sections, and who owns each

The section names vary. The sections do not. Here they are in the order they usually appear, with the person in a small company who actually holds the answer.

  • Organisation. Legal name, company number, registered address, who is accountable for information security and for data protection, insurance. Owner: whoever runs the company. Twenty minutes.
  • Governance and policies. Do you have an information security policy, is it approved, when was it reviewed, does anyone read it. Owner: the same person. If you have nothing written, this is where the sheet starts to hurt; see the section on the answer library.
  • People. Screening, contracts with confidentiality clauses, security awareness training, leavers. Owner: whoever hires.
  • Access control. Multi-factor authentication, password management, shared accounts, admin rights, joiner and leaver process, periodic access review. Owner: whoever administers your email and your main systems, which in a five-person firm is one person and in a fifty-person firm is an IT provider.
  • Devices and endpoints. Company-owned or personal, managed or not, disk encryption, screen lock, endpoint protection, automatic updates. Owner: the same.
  • Infrastructure and operations. Hosting, network, firewalls, patching windows, logging, vulnerability management, change control. Owner: your developer or your hosting provider. Most of these rows are answered by naming the provider and linking their published controls.
  • Data protection. Record of processing, lawful basis, retention, sub-processors, transfers, data subject requests, breach procedure, DPO or contact, privacy notice, AI tools. Owner: whoever you have named as responsible for data protection. This is the section Rowpa drafts from your record.
  • Incident management and continuity. Incident response process, notification commitment, backups, restore testing, continuity plan, recovery objectives. Owner: split between the data protection contact and whoever runs the systems.
  • Software development, only if you build software. Code review, dependency scanning, separate environments, secrets management, penetration testing. Owner: your lead developer.
  • Certifications and evidence. ISO 27001, SOC 2, Cyber Essentials, insurance certificates, pen test summary. Owner: whoever keeps the documents folder.

Give each section to its owner as a short list of rows, not as the whole file. Nobody needs a 200-row spreadsheet to answer the six rows about laptops, and sending it to them guarantees it comes back late.

What buyers actually check

The person reading your answers is a security analyst or a procurement officer with a stack of these. They are not reading for elegance. They read for four things, in this order.

Consistency. The first thing a reviewer does with a returned sheet is compare rows that ask the same fact in different sections. If your hosting row says London, your sub-processor list says a US provider, and your transfers row says no data leaves the UK, the sheet is read sceptically from that point on. Before you send it, read your own answers for the same fact and make them agree.

Specifics. A number, a date, a name, a system. "Daily, to a separate provider, retained 30 days, restore tested in June" is an answer to the backup row. "Yes" is not; it will come back as a follow-up question, and the follow-up costs you a week. Reviewers spot-check a handful of specific claims against evidence, and mark a vague one as a gap.

Scope. Buyers assess suppliers in proportion to what the supplier touches. A design agency that receives one contact list is not held to the standard of a payroll provider. Say what your service does with their data and answer for that service, not for the whole company and not for the roadmap. Answering beyond scope creates commitments you did not mean to make.

Honesty about gaps. Every reviewer has read a hundred sheets where every row says Yes, and they know most of them were not true. A sheet that says "no external penetration test; dependency scanning on every build and code review before merge" gets a note in a risk register. A sheet that says Yes to a pen test and cannot produce the summary gets the contract paused. You fail for being caught out, not for being small.

Common mistakes

  • Answering Yes to everything. The fastest way to fail, for the reason above. Answer per system, and let a partly be a partly.
  • Attaching the privacy policy as the answer to everything. A privacy policy is written for the public about what you do with their data. A questionnaire is asking about your operations as a supplier. Different documents, different readers.
  • Writing prose into a dropdown cell. If the answer cell only accepts Yes, No or N/A, the file will reject anything else when the buyer opens it, or the reviewer will have to re-key it. Put the explanation in the comments column.
  • Answering the hidden rows. Rows hidden in the original are usually conditional on a parent answer. Answer the parent first, and only answer the children the parent opens.
  • Promising a notification window you cannot keep. 24 hours wins the row and becomes a contractual term. Say what you can actually do, and say what starts the clock.
  • Waiting until every row is perfect. Nothing is more expensive than silence. Return the sheet on time with the rows you can answer, the rows marked in progress, and a date for the rest.
  • Answering it from scratch again next time. Most suppliers are asked more than once a year, and most rewrite the same answers each time. This is the mistake the last section is about.
  • Answering straight into a portal. If the buyer sent a link rather than a file, copy the questions out, answer them in a document where you can think and keep them, then paste in. The checker above takes pasted questions for exactly this reason.

The GDPR tenth and the security nine tenths

Here is the number that shapes how you should spend your time. On a general vendor security questionnaire, the data protection rows are about a tenth of the sheet. The other nine tenths are security controls: MFA, patching, backups, endpoint protection, access reviews, screening, incident response, and whether anything has gone wrong in the last three years.

The tenth is the part with a legal shape. It is answered from documents you are supposed to hold anyway: a record of processing activities, a list of the suppliers that touch personal data and their agreements, a note of where data leaves the country and on what basis, a breach procedure with a number of hours in it, a route for requests and complaints, a privacy notice. If you have those, the tenth takes an hour and every answer carries a source. That is the part Rowpa builds from your website and your answers, and the part it drafts with a citation beside each row. That is also why the checker counts those rows separately.

The nine tenths is not legal. It is an inventory of facts about your IT: which devices, which accounts, which settings, which provider, which date. There is no document to derive it from, so somebody has to answer each fact once. The good news is that once is enough. The facts do not change between questionnaires, and a security profile answered once, honestly, with "no" and "not sure" allowed as answers, covers most of the nine tenths on every sheet after it. Rowpa holds that profile beside the record so that the second questionnaire is a review rather than a rewrite.

The rows neither covers are the ones only you can answer on the day: the date of the last pen test, the insurance limit, a customer reference, whether a named person has done their training this year. Split them out first, send each one to the person who knows, and let them run in parallel while you do the rest.

How to keep an answer library

The second questionnaire should take an hour. It only will if you kept the first one. An answer library is not software; it is a habit with four rules.

  • Keep the question and the answer together, in the buyer's words, with the date you wrote it and the evidence you relied on. A spreadsheet with four columns is enough to start: question, answer, source, date.
  • Give every answer an owner and an expiry. Twelve months is the usual review interval. An answer about backups written before you changed provider is worse than no answer, because it is confident and wrong.
  • Match on the question, not the section. Buyers phrase the same question twenty ways. When the new sheet arrives, search the library for the fact, not for the wording, and reuse the answer with the specifics checked.
  • Regenerate the answers that come from a record. Sub-processors, retention, transfers and contacts change when the record changes. Do not copy last year's list; derive this year's from what is current.

With a filled library, firms that answer questionnaires for a living report most rows filled from existing content and the drafting time falling from a day or two to an hour or two of review. Those numbers are for a full library. For a small supplier, the point is simpler: the first questionnaire is the work, and every one after it is a check.

Rowpa's version of this is the answer bank: approved answers kept beside the record they came from, matched on the question when the next sheet arrives, and regenerated when the record changes. If you would rather keep the spreadsheet, keep the spreadsheet. The habit matters more than the tool.

How long it should take

For a supplier with a record and a security profile: an afternoon for a forty-row sheet, a day for two hundred, most of which is chasing the handful of rows that need someone else. Without either, budget a week for the first one and expect to write the same answers again in six months. The point of doing it once properly is that the second buyer costs an hour.

If you have nothing written down yet, the minimum useful set is: a record of what personal data you process and why, a list of the tools and services that touch it with their agreements, a note of where data leaves the country and on what basis, a short breach procedure with a number of hours in it, a way for people to make a request or a complaint, and the security profile answered once. That set answers most of any sheet, and it is a day of work, not a project.

Pricing

The checker and this guide are free and need no account. If you would rather not hand-write the sheet: build your record in Rowpa, upload the questionnaire, and it drafts every row it can evidence from your record and a security profile you answer once, shows the source beside each answer, marks the rows only you can answer, and writes the approved answers back into the buyer's file in their own layout. Free to build the record, upload, confirm the layout and read every draft. £79 once (a Questionnaire Pass) to draft the rest and export, up to 300 questions, no card kept on file. Or from Starter £34/mo for three a year. All prices ex VAT.

Start free See all plans

Common questions

What is a security questionnaire, and why has a customer sent me one?
It is the buyer's way of checking what happens to their data and their systems when they use your service. Their procurement or security team sends the same sheet to every supplier above a certain size or risk, and the contract waits until it comes back. It is not an accusation and it is not a test you pass or fail; it is an inventory of your controls, read in proportion to what you touch.
What is a supplier assurance questionnaire?
The same document under a different name. Supplier assurance, vendor security assessment, third-party risk questionnaire, due diligence questionnaire and vendor security questionnaire all describe a sheet of questions about your company, your data handling and your security controls. Public bodies in the UK tend to say supplier assurance; private buyers say vendor security.
Is there a security questionnaire template I can use?
Yes. Rowpa publishes a free 30-row vendor security questionnaire template as a spreadsheet, with no signup, linked below. It is useful in both directions: to see what a typical buyer asks before your first one arrives, and to send to your own suppliers. The free checker on this page reads it like any other sheet.
The buyer wants it back in three days and I have never done one. What do I do first?
Run it through the checker, then split the sheet into the four groups. Answer the company facts and the data protection rows yourself, send the two or three rows that need someone else out immediately so they run in parallel, and return the sheet on time with the remaining rows marked as in progress with a date. On time and partly complete beats late and perfect, every time.
What do buyers ask vendors in a security questionnaire?
The same forty things, phrased differently. Who you are and who is accountable. Whether MFA, disk encryption, endpoint protection and automatic updates are in place. How access is granted, reviewed and removed. Where data is hosted, which sub-processors touch it, whether it leaves the country. How long you keep it and how a person exercises their rights. What happens in an incident and how fast you tell them. Backups and whether a restore has been tested. Certifications, insurance, penetration testing, and since 2025, which AI tools you use and whether they train on customer data.
Can I refuse to answer a row?
Yes, and sometimes you should. If a row asks for something that would itself be a security risk to disclose, say so and offer an alternative: a summary instead of a full penetration test report, an attestation instead of a network diagram. Reviewers accept this routinely. What they do not accept is a blank.
We are a five-person company. Are we going to fail this?
Not for being small. Buyers assess suppliers in proportion to what the supplier touches, and a reviewer who sees consistent, specific, honest answers from a five-person firm is looking at less risk than one who sees vague answers from a fifty-person one. You fail for being caught out, not for being small.
Do I need ISO 27001 or SOC 2 to pass?
For most small suppliers, no. Certifications answer a handful of rows at once and shorten the conversation, but the questionnaire exists because the buyer wants specifics about your service. Answer the specifics well and the absence of a certificate is a line in a risk register, not a rejection.
What does the free checker do with my file?
It reads the file in memory to find the question column, sorts the rows, and returns the result. The file is not stored, not logged and not sent to anyone. If you choose to carry the questions into a Rowpa account, the questions and their section titles travel with you; the file itself never does.

Further reading

Build the record. Rowpa drafts the rows it can prove.

Free to build the record, upload the sheet, confirm the layout and read every draft. £79 once to draft the rest and export into their file.

Build your record free