Why Security Questionnaires Are Not Enough — and what to do instead

What questionnaires can and cannot prove, the failure modes, and how to combine them with evidence.

Vendor Due Diligence 7 min read

Security questionnaires are the default mechanism most organisations use to assess vendors. They are also one of the weakest. This article explains why, what questionnaires are actually useful for, and how to combine them with evidence so the assessment can survive an auditor's scrutiny.

What a questionnaire actually captures

A questionnaire is a list of statements ("we encrypt data at rest", "we have an incident response plan", "we perform annual penetration tests") with a vendor's self-attested answer. The output is the vendor's claim — not proof.

That is fine as long as the claim is treated as a claim. The failure mode is treating it as the assessment.

Why questionnaires fail as a stand-alone control

  • No verification. A "yes" answer is identical whether the control exists, whether it works, or whether the vendor genuinely believes it should be a "yes". There is no independent test.
  • Whoever filled it in defines the truth. The accuracy of the response depends on the knowledge of one person on the vendor's side — often a salesperson or account manager, not a security engineer.
  • Inconsistent semantics. "Yes, we encrypt data at rest" can mean AES-256 across all storage tiers — or it can mean the database disks. Without evidence, you cannot tell which.
  • Stale by construction. A questionnaire reflects the state when it was filled in. Six months later, the answer may no longer be true.
  • Not comparable. Different vendors interpret the same question differently. You cannot rank vendors on questionnaire answers without significant normalisation.
  • Weak audit defensibility. "We accepted the vendor's questionnaire" is a much weaker answer to a regulator than "we mapped each requirement to a clause of the SOC 2 report and the DPA".

What questionnaires are genuinely useful for

Questionnaires have real value, in three roles:

  • Gap-filling. When published evidence does not cover a requirement, a questionnaire response is a documented vendor commitment you can rely on.
  • Contractual anchor. Questionnaire answers can be referenced in the contract, turning a claim into a representation the vendor is bound by.
  • Triage. A first-pass questionnaire can quickly disqualify vendors whose self-attested baseline does not even match your minimum requirements.

In each of these roles, the questionnaire becomes a piece of evidence in its own right — recorded, dated, attributed and traceable.

The pattern that actually works

  1. Start with the published evidence — SOC 2, ISO 27001, DPA, security white paper, architecture, sub-processor list.
  2. Map your requirements against that evidence and identify the genuine gaps.
  3. Send a short questionnaire that targets only the gaps, not 300 generic questions.
  4. Treat the questionnaire responses as evidence: store them, cite them, and require contractual representation for anything material.

This is the pattern behind evidence-based vendor assessments: published evidence first, questionnaires second, and only for what the evidence does not cover.

The wrong question and the right one

The wrong question is "did the vendor return a complete questionnaire?". The right question is "for each of our requirements, what evidence supports the conclusion that this vendor meets it?" The first can be answered without reading the documents. The second cannot — and that is exactly why it is the question worth asking.

For the broader framing, see What is Vendor Due Diligence?.

Put this into practice

Governly applies the Requirements-to-Evidence Mapping methodology to your own vendors. Start from the Recommended Enterprise Baseline, upload your own requirements, or build from scratch — then add the vendor documents and receive a traceable due diligence report.