TPRM glossary

Security questionnaire, evidence, or a spreadsheet of assertions

A security questionnaire is a structured set of control questions sent to a vendor to establish how it protects the data and systems it will handle. Standardised formats such as SIG, CAIQ and the Vendor Security Alliance questionnaire exist so that vendors can answer once rather than answering every customer differently. Also called Vendor security assessment questionnaire, VSAQ.

The standard formats

SIG, from Shared Assessments, is the broadest — a large question library issued in scoped subsets, common in financial services. CAIQ, from the Cloud Security Alliance, maps to the Cloud Controls Matrix and is the usual format for cloud providers, many of whom publish a completed copy rather than answering individually. The VSA questionnaire is shorter and popular with smaller technology suppliers.

Alongside them sit bespoke internal questionnaires, which is where most of the pain in the ecosystem originates: a vendor selling to forty customers answers forty differently-worded versions of the same forty questions. Accepting a standard format, or a recent completed one, costs you very little and buys goodwill and speed.

What a questionnaire is and is not

A questionnaire is a set of assertions by the party with the least interest in disclosing a weakness. That is not a reason to abandon it — much of what matters is invisible from outside and only the vendor can tell you — but it is a reason to treat the returned document as the beginning of the assessment rather than the end of it.

Three things convert assertions into evidence: documents that corroborate them (SOC 2, ISO 27001 with its statement of applicability, test summaries), outside-in observation that can contradict them, and validation of the answers against both. Answers that conflict with the vendor's own documents are the highest-value finding in the whole exercise, and they are also the finding least likely to be spotted by a human reading their nineteenth questionnaire of the month.

Common questions

What is the difference between SIG and CAIQ?
SIG is a broad, tiered question library from Shared Assessments, widely used in financial services and scoped per vendor. CAIQ comes from the Cloud Security Alliance and maps directly to the Cloud Controls Matrix, so it is cloud-specific and frequently published pre-completed by providers.
How long should a vendor security questionnaire be?
As long as the tier justifies. A low-risk supplier with no data access does not need several hundred questions; a critical vendor processing customer data does. Sending the same maximum-length questionnaire to everyone is the main reason response rates and answer quality both fall.
Can questionnaire answers be trusted?
They are self-assertions and should be corroborated: against the vendor’s own documents, against independent audit reports, and against what their external estate actually shows. Contradictions between a questionnaire and a document the same vendor supplied are among the most useful findings an assessment produces.

Definitions are the easy part. Evidence is not.

See what your vendors actually expose — scored, monitored and evidenced in one place.