BLOG

What Security Questionnaires Miss and Why a Full Vendor Risk Program Fills the Gaps

Vendor security questionnaire and third-party risk: what a self-reported questionnaire cannot verify on its own.

By David Chernitzky, Co-Founder and CEO, Armour Cybersecurity  |  Serving organizations across Canada, the US, and beyond  |  Last updated August 18, 2026

Quick answer: Vendor security questionnaires are the most widely used third-party risk assessment tool and one of the least reliable when used in isolation. A questionnaire captures the vendor’s self-reported view of its security posture at a point in time. It cannot verify the accuracy of the responses, detect changes after the assessment, identify risks that the vendor did not disclose, or replace the contractual and monitoring controls that a complete third-party risk management program provides. Organizations that rely on questionnaires alone have assessed their vendors without actually managing their vendor risk.

Key Takeaways

  • Security questionnaires are self-reported documents. Vendors have an incentive to present their security posture favorably, and without evidence review or control testing, there is no mechanism for verifying that responses are accurate or complete.
  • A questionnaire captures a point-in-time snapshot. A vendor that completes a questionnaire today may experience a significant security incident, a leadership change, a technology migration, or a certification lapse before the next assessment cycle. Questionnaires with no ongoing monitoring between cycles miss these changes entirely.
  • Questionnaires do not cover contractual safeguards. A vendor can complete a questionnaire demonstrating adequate security practices and still have a contract with the organization that contains no breach notification obligations, no audit rights, and no minimum security requirements that the organization can enforce.
  • Evidence review, the process of confirming that the vendor’s responses are supported by documentation such as SOC 2 reports, ISO 27001 certificates, and policy samples, is the step that transforms a self-reported questionnaire into a substantiated assessment. Without evidence review, questionnaire responses are unverified claims.
  • The SIG (Standardized Information Gathering) questionnaire framework, maintained by Shared Assessments, provides a structured, tiered questionnaire approach that currently covers 21 risk domains and is widely recognized by vendors, auditors, and regulators as an industry standard for third-party security assessment.

What a Security Questionnaire Actually Captures

A security questionnaire is a structured set of questions sent to a vendor asking about its security controls, policies, certifications, and practices. The vendor completes the questionnaire by providing yes or no responses, narrative descriptions, and references to certifications or documents. The completed questionnaire is returned to the organization, reviewed, and either accepted as demonstrating adequate security or used to identify gaps that require follow-up.

The questionnaire captures the vendor’s self-reported view of its own security posture. This is valuable information: a well-designed questionnaire covering all relevant risk domains provides a structured baseline of what the vendor believes its security controls to be. But it is also inherently limited information. Self-reported questionnaires are not audits. They do not test whether the controls described are actually implemented. They do not review the evidence behind the responses. They do not assess whether the policies described are followed in practice or whether the certifications cited are current and cover the scope relevant to the relationship. And once the questionnaire is returned and accepted, the organization has no visibility into how the vendor’s posture evolves until the next assessment cycle. Which questionnaire depth a given vendor even warrants is itself a function of vendor risk tiering, so the questionnaire is a step inside a larger process, not the process itself.

The Five Gaps That Questionnaires Cannot Close

Verification of responses

The most fundamental limitation of questionnaire-only assessment is the absence of verification. A vendor that answers “yes” to a question about whether it has implemented multi-factor authentication for all administrative accounts may be accurately describing its current practice, partially describing it (MFA is deployed on some accounts but not all), or misrepresenting it entirely. Without reviewing supporting evidence, such as configuration screenshots, audit logs, or a SOC 2 report that independently attests to the control, the organization cannot distinguish an accurate response from an inaccurate one. Controls like MFA and privileged access are exactly where identity and privileged access management evidence separates a real answer from an aspirational one. Evidence review, in which the assessor requests and reviews documentation supporting key responses, is the step that transforms self-assessment into substantiated assessment.

Changes after the assessment

A questionnaire completed today reflects the vendor’s security posture as of today. Tomorrow the vendor may experience a significant security incident. Next month a key security leader may depart. Six months from now the vendor may migrate to a new cloud infrastructure with a different security configuration. A year from now the vendor’s SOC 2 certification may lapse. None of these changes are captured by the questionnaire because the questionnaire is a point-in-time document. Ongoing monitoring, whether through security ratings services that track observable indicators of vendor security health, certification tracking that confirms certifications remain current, or threat intelligence feeds that flag vendor mentions in breach reports, closes this gap.

Undisclosed risks

Questionnaires capture what the vendor is willing to disclose. They do not capture what the vendor does not know about its own security posture, does not consider relevant to the question asked, or prefers not to disclose. A vendor may not be aware of a vulnerability in its infrastructure. It may not consider its use of a specific subprocessor to be in scope for the questionnaire. It may not disclose that a prior security incident occurred because it was classified internally as an operational event rather than a security breach. Supplementing questionnaire responses with independent research, including public breach disclosures, news monitoring, and subprocessor review, identifies risks that self-reported questionnaires do not surface. This is the same dynamic behind the reminder that your vendors are your attack surface: the risk that reaches you is often the one the vendor never put on the form.

Contractual enforceability

A completed questionnaire has no contractual weight. It documents what the vendor said its security practices were at the time of completion. It does not create an obligation for the vendor to maintain those practices, to notify the organization if they change, or to permit the organization to verify them through an audit or assessment. Contractual security provisions, including minimum control requirements, breach notification timelines, audit and assessment rights, and data return and deletion obligations, are the mechanism through which the organization can hold vendors accountable for the security posture they represent. A vendor whose questionnaire demonstrates excellent security practices and whose contract contains no security provisions is a vendor the organization cannot hold accountable when those practices fall short.

Concentration and dependency risk

Security questionnaires assess individual vendors in isolation. They do not reveal concentration risk: the degree to which the organization is dependent on a small number of vendors for critical services, creating single points of failure that a security incident at any one of them could exploit. A vendor that passes a security assessment may still represent an unacceptable concentration risk if it is the sole provider of a critical service with no viable alternative. Concentration risk analysis, which identifies the vendors whose failure or compromise would have the most significant business impact and evaluates whether that dependency is appropriate, requires a portfolio view of the vendor ecosystem that questionnaires do not provide.

What a Complete Third-Party Risk Management Program Adds

A complete supplier risk management program uses questionnaires as one component within a broader framework. The questionnaire is supported by evidence review that verifies key responses against documentation. Ongoing monitoring detects changes in vendor security posture between assessment cycles. Contractual provisions create enforceable obligations that the questionnaire alone cannot establish. Concentration risk analysis identifies dependency vulnerabilities that individual vendor assessments cannot see. And vendor incident response protocols define the coordination procedures that activate when a vendor breach occurs, rather than inventing them under crisis conditions.

The program is also tiered: the depth of the questionnaire, the frequency of assessment, the intensity of monitoring, and the specificity of contractual requirements are all calibrated to the risk tier of each vendor. Critical vendors receive the full program depth. Low-risk vendors receive a proportionately lighter process that does not waste resources or create unnecessary friction. Armour Cybersecurity designs and implements the complete supplier risk management program as a coordinated engagement, ensuring that the questionnaire process is embedded in the broader framework rather than standing alone as the entirety of the vendor risk effort. Where these obligations intersect with certification and regulatory requirements, they are managed within a broader governance, risk and compliance function.

Frequently Asked Questions

What is the SIG questionnaire and how does it compare to building our own?

The Standardized Information Gathering questionnaire is published by Shared Assessments and currently covers 21 security risk domains across hundreds of questions, structured in a tiered format that allows shorter SIG Lite assessments for lower-risk vendors and fuller SIG Core assessments for higher-risk vendors. Because Shared Assessments updates the SIG annually, the exact domain and question counts change from year to year, so the working assumption should be to use the version in the current release. Using the SIG rather than building a proprietary questionnaire from scratch has several advantages: it covers all relevant risk domains comprehensively, it is recognized by vendors who may have completed it for other customers and can provide existing responses, and it aligns to regulatory and certification frameworks including SOC 2, ISO 27001, and NIST 800-53. Building a proprietary questionnaire risks missing coverage areas, takes significant time to develop and validate, and may not be recognized as a standard by vendors or auditors.

How do security ratings services work and are they reliable?

Security ratings services, such as BitSight, SecurityScorecard, and similar platforms, provide automated assessments of an organization’s security posture based on externally observable data: open ports and services, SSL certificate configurations, domain reputation, indicators of compromised infrastructure, and similar signals that can be observed without any access to the organization’s internal systems. These ratings are useful as continuous monitoring indicators: a vendor whose security rating deteriorates significantly between annual assessment cycles may have experienced a security incident or allowed controls to lapse. They are not substitutes for assessment: they observe only what is externally visible and miss the internal controls that determine most of the vendor’s actual security posture. Their most appropriate use in a supplier risk program is as a between-cycle monitoring signal that triggers a more detailed assessment when it indicates a material change.

How should we handle a vendor that provides a SOC 2 report instead of completing our questionnaire?

A current SOC 2 Type II report is a reasonable substitute for questionnaire completion for the controls covered by the report, provided the report covers the relevant trust services criteria and the observation period is recent. The assessor should review the SOC 2 report rather than simply accepting it: examining the scope to confirm it covers the systems and services relevant to the relationship, reviewing any qualified opinions or exceptions noted by the auditor, checking the observation period end date to confirm the report is current, and identifying any complementary user entity controls the organization is expected to implement. A SOC 2 report does not cover all questionnaire domains; areas not addressed by the SOC 2 report still require questionnaire responses or other evidence.

What contractual provisions should every vendor contract include?

The minimum set of security provisions that vendor contracts should include are: a requirement that the vendor maintains reasonable and appropriate security controls, with a definition of what reasonable means in terms of specific standards or certifications; a breach notification obligation requiring the vendor to notify the organization within a defined timeframe (typically 24 to 72 hours) of discovering a security incident that may affect the organization’s data or systems; an audit and assessment right allowing the organization or its designee to assess the vendor’s security controls; a minimum security standard requirement tied to the vendor’s tier, such as requiring critical vendors to maintain an active SOC 2 Type II or ISO 27001 certification; and data return and deletion obligations requiring the vendor to return or delete the organization’s data upon contract termination within a defined period. For vendors handling personal information, data processing agreement provisions under applicable privacy law are additional requirements.

How often should security questionnaires be repeated?

Assessment frequency should match vendor tier. Critical vendors with broad system access and high data sensitivity warrant annual assessment at minimum, with more frequent reviews triggered by material changes in the vendor relationship or the vendor’s security posture. High-tier vendors should be assessed annually. Medium-tier vendors should be assessed every one to two years, with monitoring between cycles. Low-tier vendors may only require an initial onboarding screen with no recurring formal assessment, provided ongoing monitoring does not surface changes that warrant reassessment. Regardless of the scheduled cadence, any vendor should be reassessed promptly when a material event occurs: a reported security incident, a significant change in the vendor’s ownership or technology platform, or a notable deterioration in monitoring signals.

The Bottom Line

A returned security questionnaire feels like vendor risk management, but on its own it is just a vendor’s word for its own security, frozen at a single moment, with nothing behind it you can verify or enforce. The five gaps are consistent: no verification of the answers, no visibility into changes after the assessment, no view of what the vendor did not disclose, no contractual teeth, and no portfolio-level read on concentration risk. Closing them takes evidence review, ongoing monitoring, real contract provisions, and concentration analysis, all tiered to how much each vendor can actually hurt you. A complete supplier risk management program puts the questionnaire in its place, as one input inside a framework that actually manages the risk.

Leave the first comment