Platform · Smart assessments

Assessments that pre-populate themselves.

ARIA reads the vendor's evidence — SOC 2, ISO 27001, trust centre, policies — and pre-fills 70%+ of the questionnaire from what's already there. Your team reviews structured output instead of chasing answers.

What is an automated security questionnaire?

A security questionnaire is the structured set of questions a buyer sends a vendor to establish how that vendor protects data and runs its security programme. Standard formats exist — the SIG, the Cloud Security Alliance's CAIQ, and increasingly framework-specific sets — though many organisations still send their own.

The process is famously slow on both sides: buyers wait weeks for answers, vendors answer materially the same questions repeatedly in different formats, and the returned document is a point-in-time self-report that ages from the day it arrives.

Automating it means pre-population, not elimination. Evidence the vendor has already produced — a SOC 2 report, an ISO 27001 certificate and Statement of Applicability, security policies, a trust centre — contains the answers to most questions. Reading those documents, mapping their contents to a control framework, and filling in the questionnaire from them turns the vendor's task from writing into reviewing, and the buyer's task from chasing into checking. The questions that remain are the ones evidence cannot answer, which are usually the ones worth a human.

The numbers your team already knows.

Vendor assessments are the single biggest time-sink in TPRM, and the answers — when you finally get them — are usually re-keyed from documents the vendor already had.

4-6 weeks
Average time to complete a vendor security questionnaire
Industry average
~62%
Of analyst time spent on questionnaire chasing and review
Industry estimate
157
Universal Controls every vendor is mapped against

ARIA pre-fills. NOVA chases. REX cross-checks.

Smart Assessments is the combined-signal model — document intelligence from ARIA, the vendor relationship from NOVA, and external scan evidence from REX, all on the same questionnaire.

ARIA avatar
ARIA
Assessment & Risk Intelligence

The questionnaire is mostly written before the vendor sees it. ARIA reads SOC 2 reports, ISO certs, trust centres and policies — then pre-fills 70%+ of every questionnaire against the 157 Universal Controls.

What you get
  • Questionnaire Pre-Populator — auto-fills from existing evidence
  • Document Classifier — routes uploads to the right control
  • Trust Centre Parser — vendor portals mapped to the RX framework
NOVA avatar
NOVA
Vendor Relationship Manager

The chase is automated, on three channels. NOVA owns vendor outreach across email, WhatsApp and in-app chat — chasing outstanding answers, redirecting when contacts leave, escalating when they're late.

What you get
  • Vendor Chaser — automated nudges across three channels
  • Detects contact churn and re-routes onboarding
  • Customer can join any conversation — multi-party model
REX avatar
REX
Risk & Breach Intelligence

What the vendor says, checked against what we can see. REX cross-validates self-attested answers against external scan data and public records — so vendor contradictions surface before you sign.

What you get
  • Outside-in scan evidence joined to questionnaire answers
  • Vendor Business Risk Analyst — Companies House, sanctions, court records
  • Combined-signal analysis with ARIA on every assessment

From questionnaire chase to evidence review.

The work shifts from collection to interpretation. Your analysts review structured output and judge edge cases — they stop being mail-merge.

Pre-fill before the vendor types

ARIA pre-populates from documents the vendor has already shared. The vendor confirms or amends, instead of starting from blank.

NOVA owns the follow-up

Your team stops writing chase emails. NOVA tracks who replied, who went silent, and who left the company — and acts accordingly.

Contradictions surface automatically

When a vendor's answer disagrees with their SOC 2 or with REX's external scan, ARIA's Response Validator flags it before you read the response.

Audit-ready evidence by default

Every answer links to its source — the document, the scan, the trust centre. When auditors arrive, the trail is composed.

We retired our questionnaire-chasing analyst function entirely. ARIA pre-fills, NOVA chases, REX cross-checks. The team is finally judging risk instead of formatting it.

SC
Director of TPRM
Top-10 European insurer

What teams ask about assessments.

Pre-population, validation, and how much of this should be automatic.

How can a questionnaire be pre-populated from documents?
Because the evidence already contains the answers, just not in the requested shape. A SOC 2 Type II describes controls and the auditor's testing of them; an ISO 27001 Statement of Applicability lists which Annex A controls apply and why; policies state what the organisation requires. Classifying those documents, extracting their assertions and mapping each to a control lets any questionnaire be answered from the same underlying evidence set — with each answer carrying a citation back to the source document and page, so a reviewer can check rather than trust.
Does this mean nobody reads the questionnaire?
No, and a system that claimed otherwise would be selling the wrong thing. What changes is where the human attention goes. Pre-population handles the substantial fraction of questions that are answerable from evidence, leaving your team the exceptions: questions with no supporting evidence, answers that conflict with other sources, and controls where the vendor's position is a considered risk acceptance that needs a judgement rather than a tick.
How do you know a vendor's answers are true?
By checking them against sources the vendor does not control. Where a questionnaire answer has an externally observable counterpart, it can be validated: an assertion about enforcing TLS or email authentication is checkable, a claim of prompt patching can be compared against observed software versions on internet-facing systems, and claims about encryption in transit are visible from the outside. Most answers have no such counterpart and remain self-reported — the useful discipline is knowing which answers were verified and which were taken on trust, rather than pretending the whole document carries equal weight.
What is the difference between SIG and CAIQ?
The SIG — Standardized Information Gathering questionnaire, from Shared Assessments — is broad, covering the full third-party risk domain across many control areas, and comes in a fuller version and a shorter SIG Lite. The CAIQ — Consensus Assessments Initiative Questionnaire, from the Cloud Security Alliance — is cloud-specific and maps to the CSA Cloud Controls Matrix, with completed CAIQs published in the CSA STAR registry. SIG is more common in financial services and general enterprise TPRM; CAIQ is the usual ask for a cloud service provider.

See it on your vendors.

Book a 30-minute call and we'll have NOVA, ARIA and REX produce a complete posture report on one of your live vendors inside 24 hours.