Vendor Questionnaire
A vendor questionnaire is a structured set of questions that an organization sends to a supplier or partner to understand how that vendor handles security, compliance, and day-to-day operations. It helps the organization evaluate the risk of doing business with the vendor before or during a relationship. It is one common tool used during due diligence, not the entire risk evaluation on its own.
A vendor questionnaire is a standardized instrument used within third-party risk management to collect self-reported information from vendors, partners, or suppliers about their security controls, compliance posture, and operational maturity. It typically forms a central input to due diligence and broader vendor risk assessment processes, though practitioners distinguish the questionnaire (the set of questions and responses) from the assessment (the analysis and risk determination derived from those responses and supporting evidence). Because responses are generally vendor-attested, the value of a questionnaire often depends on validation through supporting documentation, and its usefulness may vary by the specificity of the questions and the vendor's cooperation. In many programs, questionnaires cover areas such as data handling, hosting arrangements, software release and roadmap practices, and adherence to relevant frameworks or regulatory obligations.
Why it matters
Third-party relationships extend an organization's risk surface beyond its own controls, and a vendor questionnaire is one of the most common instruments for gathering the information needed to evaluate that exposure. Before onboarding a supplier or partner, an organization needs a structured way to understand how the vendor handles data, hosting, software practices, and compliance obligations. The questionnaire provides that structure, giving the organization a repeatable basis for comparing vendors and for documenting the due diligence it performed.
A critical distinction that experienced practitioners insist on is that the questionnaire is not the assessment. The questionnaire is the set of questions and the vendor's responses; the assessment is the analysis and risk determination derived from those responses together with supporting evidence. Because responses are generally vendor-attested, treating a completed questionnaire as proof of a vendor's security posture is a common and consequential mistake. Its value often depends on validation through supporting documentation, the specificity of the questions asked, and the vendor's willingness to cooperate. A questionnaire that goes unverified may create a false sense of assurance rather than reducing risk.
Questionnaires also serve a governance and accountability function. Regulated and public-sector environments may require formal vendor questionnaires as part of contracting; for example, New York State uses a Vendor Responsibility Questionnaire that vendors file with State contracting entities. Even outside such mandates, a well-run questionnaire process creates a documented record supporting decisions about which third parties an organization is willing to trust, which matters when those decisions are later scrutinized.
Who it's relevant to
Inside VRAQ
Common questions
Answers to the questions practitioners most commonly ask about VRAQ.