Skip to main content
Category: Third-Party & Supply Chain Risk

Vendor Questionnaire

Also known as: VRAQ, Vendor Security Questionnaire, Vendor Risk Assessment Questionnaire, Vendor Assessment Questionnaire, Vendor Responsibility Questionnaire
Simply put

A vendor questionnaire is a structured set of questions that an organization sends to a supplier or partner to understand how that vendor handles security, compliance, and day-to-day operations. It helps the organization evaluate the risk of doing business with the vendor before or during a relationship. It is one common tool used during due diligence, not the entire risk evaluation on its own.

Formal definition

A vendor questionnaire is a standardized instrument used within third-party risk management to collect self-reported information from vendors, partners, or suppliers about their security controls, compliance posture, and operational maturity. It typically forms a central input to due diligence and broader vendor risk assessment processes, though practitioners distinguish the questionnaire (the set of questions and responses) from the assessment (the analysis and risk determination derived from those responses and supporting evidence). Because responses are generally vendor-attested, the value of a questionnaire often depends on validation through supporting documentation, and its usefulness may vary by the specificity of the questions and the vendor's cooperation. In many programs, questionnaires cover areas such as data handling, hosting arrangements, software release and roadmap practices, and adherence to relevant frameworks or regulatory obligations.

Why it matters

Third-party relationships extend an organization's risk surface beyond its own controls, and a vendor questionnaire is one of the most common instruments for gathering the information needed to evaluate that exposure. Before onboarding a supplier or partner, an organization needs a structured way to understand how the vendor handles data, hosting, software practices, and compliance obligations. The questionnaire provides that structure, giving the organization a repeatable basis for comparing vendors and for documenting the due diligence it performed.

A critical distinction that experienced practitioners insist on is that the questionnaire is not the assessment. The questionnaire is the set of questions and the vendor's responses; the assessment is the analysis and risk determination derived from those responses together with supporting evidence. Because responses are generally vendor-attested, treating a completed questionnaire as proof of a vendor's security posture is a common and consequential mistake. Its value often depends on validation through supporting documentation, the specificity of the questions asked, and the vendor's willingness to cooperate. A questionnaire that goes unverified may create a false sense of assurance rather than reducing risk.

Questionnaires also serve a governance and accountability function. Regulated and public-sector environments may require formal vendor questionnaires as part of contracting; for example, New York State uses a Vendor Responsibility Questionnaire that vendors file with State contracting entities. Even outside such mandates, a well-run questionnaire process creates a documented record supporting decisions about which third parties an organization is willing to trust, which matters when those decisions are later scrutinized.

Who it's relevant to

Security and Risk Leaders Building Third-Party Risk Programs
For those responsible for third-party risk management, the questionnaire is a foundational tool for standardizing how vendors are evaluated. Their focus is typically on designing questions that elicit specific, verifiable answers and on distinguishing the questionnaire itself from the assessment and risk determination it supports. Because responses are vendor-attested, these leaders generally treat validation through supporting documentation as part of the process rather than accepting self-reported answers at face value.
Virtual and Fractional CISOs
A virtual or fractional CISO often helps client organizations establish or refine vendor questionnaire processes as part of governance and risk management. In this advisory role, the vCISO typically directs how questionnaires are structured and how responses are analyzed, while accountability for accepting or rejecting a given vendor remains with the client organization. This is a governance and business-risk function, not merely a technical one, and its value depends heavily on the client's organizational maturity and access to the relevant stakeholders and vendor relationships.
Procurement and Contracting Teams
Procurement functions frequently administer or require vendor questionnaires as a step in onboarding and contracting, particularly in regulated or public-sector settings such as the New York State Vendor Responsibility Questionnaire filing. These teams benefit from understanding that the questionnaire supports due diligence and documentation but does not by itself constitute a completed risk evaluation, which requires analysis of the responses alongside supporting evidence.
Vendors and Suppliers Responding to Questionnaires
Vendors on the receiving end use questionnaires to communicate their security, compliance, and operational practices to prospective and current customers, including data handling, hosting arrangements, and software release and roadmap practices. Because their answers are self-attested and may be validated against supporting documentation, accuracy and the ability to substantiate claims are important to sustaining the relationship.

Inside VRAQ

Security Governance and Policy Questions
Requests for information about the vendor's documented security policies, governance structure, and how security responsibilities are assigned and overseen within their organization.
Access Control and Identity Management
Questions covering how the vendor manages user access, authentication, privileged accounts, and offboarding, intended to assess controls around who can reach systems and data.
Data Handling and Protection
Inquiries about how the vendor stores, transmits, encrypts, and disposes of data, including where data resides and how it is segregated, relevant to obligations under frameworks such as GDPR or HIPAA where applicable.
Compliance and Certification Status
Requests for evidence of alignment with standards such as SOC 2, ISO 27001, PCI DSS, or similar. This typically documents attestations or certifications the vendor holds; it does not by itself guarantee the vendor's ongoing compliance.
Incident Response and Breach Notification
Questions about the vendor's incident response capabilities, historical incidents where disclosed, and contractual notification timelines in the event of a breach.
Business Continuity and Resilience
Elements covering disaster recovery planning, backup practices, and continuity arrangements that address the vendor's ability to maintain or restore service.
Subcontractor and Fourth-Party Risk
Questions identifying downstream vendors or subprocessors the vendor relies on, since risk can extend beyond the direct relationship.

Common questions

Answers to the questions practitioners most commonly ask about VRAQ.

Does a virtual CISO fill out my vendor security questionnaires for me?
Not necessarily as a hands-on task, and it should not be assumed as a default part of the engagement. A virtual CISO typically provides strategy, governance, and executive-level guidance around how your organization responds to vendor questionnaires, including establishing consistent, defensible answers and reviewing risky responses. The actual completion of questionnaires is often an operational activity that may sit with internal staff, a GRC team, or a designated coordinator unless explicitly contracted to the vCISO. Whether the vCISO drafts, reviews, or merely advises on questionnaire responses varies by provider and by the scope defined in the agreement.
If a virtual CISO signs off on our vendor questionnaire responses, are they accountable for the answers?
Generally no. A virtual CISO advises and directs, but legal and organizational accountability for the accuracy of questionnaire responses and the security decisions they represent typically remains with the client organization and its officers. Attesting to a customer or auditor that certain controls exist is an organizational assertion, and the accountability for that assertion usually stays with the company signing it. A vCISO can help ensure responses are accurate and supportable, but they do not assume liability or regulatory accountability unless a contract specifically provides for it.
How does a virtual CISO help our organization respond to vendor security questionnaires?
In many engagements, a virtual CISO helps by establishing a repeatable process for responding, maintaining a library of consistent and accurate answers, mapping responses to frameworks such as NIST CSF, ISO 27001, or SOC 2 where relevant, and reviewing responses to flag gaps or overstated claims. The vCISO can also translate technical control details into governance and business-risk language for reviewers. The degree of hands-on involvement depends on the defined scope, and value tends to depend on access to accurate internal information and stakeholder cooperation.
Can a virtual CISO help us respond to inbound questionnaires from our customers and to questionnaires we send our own vendors?
Both directions may fall within an engagement, but they are distinct activities that should be scoped explicitly. On the inbound side, a vCISO can help your organization answer prospective and existing customers accurately and consistently. On the outbound side, they can help design vendor questionnaires and evaluate third-party responses as part of a broader third-party risk program. Which of these is included, and to what depth, varies by provider and by the terms of the agreement, so neither should be assumed without confirmation.
What information does a virtual CISO need from us to support questionnaire responses effectively?
Effective support typically depends on access to accurate documentation and stakeholders, since a vCISO advises rather than independently generating facts about your environment. This often includes existing policies, control documentation, prior questionnaire responses, relevant compliance artifacts, and access to the people who own the underlying systems and processes. Where organizational maturity is low or documentation is incomplete, the vCISO may first need to help build that foundation, which can affect timelines and the depth of what can be truthfully asserted.
Does a virtual CISO handling our questionnaires mean we are compliant or certified?
No. Responding to a vendor questionnaire is a point-in-time representation of stated controls and is not the same as achieving certification or attested compliance. A virtual CISO can support readiness and help ensure responses accurately reflect your posture against frameworks such as ISO 27001, SOC 2, or PCI DSS, but a completed questionnaire does not by itself guarantee compliance, certification, or a particular audit outcome. Certification and formal attestation involve separate processes, often including independent assessors, that fall outside the questionnaire itself.

Common misconceptions

A completed vendor questionnaire proves the vendor is secure or compliant.
A questionnaire captures self-reported attestations at a point in time. It supports risk assessment and readiness evaluation but does not independently verify controls or guarantee ongoing security or compliance; corroborating evidence such as audit reports or certifications is typically needed.
The vendor questionnaire transfers accountability for security risk to the vendor.
Completing a questionnaire does not shift legal or organizational accountability. Responsibility for third-party risk decisions generally remains with the client organization and its officers, and a virtual CISO advising on the process directs and interprets it rather than assuming that accountability.
A virtual CISO involved in vendor questionnaires performs the vendor's security testing or ongoing monitoring.
A vCISO typically provides governance, guides the assessment process, and interprets responses at an executive level. Hands-on operational tasks such as technical testing or continuous monitoring of the vendor are generally out of scope unless explicitly contracted.

Best practices

Tailor questionnaire depth to the vendor's risk tier, applying more rigorous questions to vendors that handle sensitive data or critical systems and lighter questionnaires to lower-risk relationships.
Request supporting evidence such as SOC 2 reports, ISO 27001 certificates, or penetration test summaries rather than relying solely on self-reported answers.
Map questionnaire content to relevant frameworks and regulatory obligations, such as NIST CSF, HIPAA, or PCI DSS, so that responses can be evaluated against defined expectations rather than ad hoc criteria.
Define clear scope and accountability up front, clarifying that the vCISO advises on and interprets responses while decision-making authority and risk acceptance remain with the client organization.
Include questions on subcontractors and fourth-party dependencies to surface risk that extends beyond the direct vendor relationship.
Establish a cadence for reassessment, since a questionnaire reflects a point in time and its value depends on periodic refresh and continued client cooperation and stakeholder access.