Someone in procurement has sent you a spreadsheet. Forty rows, maybe two hundred, a deadline, and a contract that does not move until it comes back. Paste the questions or upload the file and you get every row sorted into data protection, security, commercial and other, a count of what a record could answer, and one line per data protection row on what a good answer contains. No account. Then the guide below says how to answer the rest.
The checker and the guide need no account. The file is read once and not kept.
Paste the questions or upload the spreadsheet. You get every row sorted into data protection, security, commercial and other, how many a Rowpa record could draft with citations, and what a good data protection answer contains. Free, no account, and the file is not kept.
Whatever it is called, and it will be called a vendor security assessment, a supplier assurance questionnaire, a third-party risk questionnaire, a due diligence form or somebody's initials followed by the word Lite, the sheet is four things stacked on top of each other.
Company and contract facts. Legal entity, registered address, who signs, insurance, where you operate. Twenty seconds each, and you know all of them.
Data protection. What personal data you touch on their behalf, who else touches it, where it goes, how long you keep it, what happens in a breach, how a person exercises their rights. Usually a tenth of the sheet, sometimes half if the sender is a public body or a data protection officer rather than a security team.
Security controls. Multi-factor authentication, device encryption, patching, backups, access reviews, malware protection, staff screening, penetration testing. The bulk of a general assessment, and the part that worries small suppliers most.
Evidence requests. Attach your policy. Attach the pen test summary. Attach the certificate. These are not questions, they are file requests, and they are usually the ones that stall the sheet for a week.
The four groups need four different approaches, and treating the whole sheet as one long homework exercise is why it takes people a fortnight. The checker above does the sorting; the rest of this page is the approach for each group.
Ten rows from a sample review, drafted from a fictional company's record, its security profile and the certificates it has uploaded. The blank row is the point. Nothing is claimed that the record does not hold.
Every questionnaire you will be sent has the same skeleton, whether it is a 30-row sheet from a marketing agency or a 600-row SIG from a bank. There is a cover block that asks who you are. There are sections, each with a heading and a run of numbered rows. Each row has a question, an answer cell that is either free text or a dropdown of Yes, No and N/A, and usually a comments or evidence column beside it. Some rows are parents with sub-questions a, b and c underneath. Some rows are hidden until you answer the row above.
Read the whole thing once before you answer anything. Ten minutes. You are looking for three things: the answer format each section expects, the rows that ask for a file rather than a sentence, and the rows that repeat a question already asked in another section under a different name. Hosting location, sub-processors and international transfers are the same fact asked three ways, and the sheet will be read as one document, so the three answers have to agree.
Then sort the rows into the four groups above. The checker on this page does the first pass for you. On a general vendor security questionnaire the split is usually company facts 10 percent, data protection 10 percent, security controls 70 percent, evidence requests 10 percent. On a questionnaire from a data protection officer or a public body, the data protection share climbs to half.
The section names vary. The sections do not. Here they are in the order they usually appear, with the person in a small company who actually holds the answer.
Give each section to its owner as a short list of rows, not as the whole file. Nobody needs a 200-row spreadsheet to answer the six rows about laptops, and sending it to them guarantees it comes back late.
The person reading your answers is a security analyst or a procurement officer with a stack of these. They are not reading for elegance. They read for four things, in this order.
Consistency. The first thing a reviewer does with a returned sheet is compare rows that ask the same fact in different sections. If your hosting row says London, your sub-processor list says a US provider, and your transfers row says no data leaves the UK, the sheet is read sceptically from that point on. Before you send it, read your own answers for the same fact and make them agree.
Specifics. A number, a date, a name, a system. "Daily, to a separate provider, retained 30 days, restore tested in June" is an answer to the backup row. "Yes" is not; it will come back as a follow-up question, and the follow-up costs you a week. Reviewers spot-check a handful of specific claims against evidence, and mark a vague one as a gap.
Scope. Buyers assess suppliers in proportion to what the supplier touches. A design agency that receives one contact list is not held to the standard of a payroll provider. Say what your service does with their data and answer for that service, not for the whole company and not for the roadmap. Answering beyond scope creates commitments you did not mean to make.
Honesty about gaps. Every reviewer has read a hundred sheets where every row says Yes, and they know most of them were not true. A sheet that says "no external penetration test; dependency scanning on every build and code review before merge" gets a note in a risk register. A sheet that says Yes to a pen test and cannot produce the summary gets the contract paused. You fail for being caught out, not for being small.
Here is the number that shapes how you should spend your time. On a general vendor security questionnaire, the data protection rows are about a tenth of the sheet. The other nine tenths are security controls: MFA, patching, backups, endpoint protection, access reviews, screening, incident response, and whether anything has gone wrong in the last three years.
The tenth is the part with a legal shape. It is answered from documents you are supposed to hold anyway: a record of processing activities, a list of the suppliers that touch personal data and their agreements, a note of where data leaves the country and on what basis, a breach procedure with a number of hours in it, a route for requests and complaints, a privacy notice. If you have those, the tenth takes an hour and every answer carries a source. That is the part Rowpa builds from your website and your answers, and the part it drafts with a citation beside each row. That is also why the checker counts those rows separately.
The nine tenths is not legal. It is an inventory of facts about your IT: which devices, which accounts, which settings, which provider, which date. There is no document to derive it from, so somebody has to answer each fact once. The good news is that once is enough. The facts do not change between questionnaires, and a security profile answered once, honestly, with "no" and "not sure" allowed as answers, covers most of the nine tenths on every sheet after it. Rowpa holds that profile beside the record so that the second questionnaire is a review rather than a rewrite.
The rows neither covers are the ones only you can answer on the day: the date of the last pen test, the insurance limit, a customer reference, whether a named person has done their training this year. Split them out first, send each one to the person who knows, and let them run in parallel while you do the rest.
The second questionnaire should take an hour. It only will if you kept the first one. An answer library is not software; it is a habit with four rules.
With a filled library, firms that answer questionnaires for a living report most rows filled from existing content and the drafting time falling from a day or two to an hour or two of review. Those numbers are for a full library. For a small supplier, the point is simpler: the first questionnaire is the work, and every one after it is a check.
Rowpa's version of this is the answer bank: approved answers kept beside the record they came from, matched on the question when the next sheet arrives, and regenerated when the record changes. If you would rather keep the spreadsheet, keep the spreadsheet. The habit matters more than the tool.
For a supplier with a record and a security profile: an afternoon for a forty-row sheet, a day for two hundred, most of which is chasing the handful of rows that need someone else. Without either, budget a week for the first one and expect to write the same answers again in six months. The point of doing it once properly is that the second buyer costs an hour.
If you have nothing written down yet, the minimum useful set is: a record of what personal data you process and why, a list of the tools and services that touch it with their agreements, a note of where data leaves the country and on what basis, a short breach procedure with a number of hours in it, a way for people to make a request or a complaint, and the security profile answered once. That set answers most of any sheet, and it is a day of work, not a project.
The checker and this guide are free and need no account. If you would rather not hand-write the sheet: build your record in Rowpa, upload the questionnaire, and it drafts every row it can evidence from your record and a security profile you answer once, shows the source beside each answer, marks the rows only you can answer, and writes the approved answers back into the buyer's file in their own layout. Free to build the record, upload, confirm the layout and read every draft. £79 once (a Questionnaire Pass) to draft the rest and export, up to 300 questions, no card kept on file. Or from Starter £34/mo for three a year. All prices ex VAT.
Free to build the record, upload the sheet, confirm the layout and read every draft. £79 once to draft the rest and export into their file.
Build your record free