Menu
← Guides

A security questionnaire from your client's customer: the first hour

Before answering a single question — which standard it is, what is in scope, which of the client's documents answer which section, and how to handle the controls the client does not have.

Updated 2026-09-22

The email you get

A client forwards a spreadsheet with a one-line note: "Our new customer needs this back by Friday." Two hundred rows, a column for the answer, a column for comments, and a tab of instructions nobody has read. Some cells are already filled with the customer's assumptions. The client expects you to take it from here.

What you do in the first hour decides whether the rest takes an afternoon or a week, and whether the answers survive the customer's follow-up call. None of it is answering questions. It is working out what is being asked, of whom, and from what.

1. Identify the questionnaire

Most arrive in one of three forms.

CAIQ or CAIQ Lite, from the Cloud Security Alliance. Question ids look like DSP-07.1; the answer column takes Yes, No or N/A; a second column asks who owns the control. It assesses a cloud service.

SIG or SIG Lite, from Shared Assessments. Questions are grouped by risk domain, and there is often a scoping tab the customer has already filled. It assesses the supplier as an organisation, not only the service.

The customer's own list. Usually derived from one of the above, or from ISO 27001 Annex A, with its own numbering and wording. Sometimes it is a questionnaire the customer received from its own customer and passed down the chain.

A standard questionnaire comes with definitions of what each answer means. Use them. In CAIQ, Yes means the control is implemented — not that a policy mentions it. If the customer's own list has no definitions, write the standard you are using into the first comment and apply it consistently.

2. Read the instructions tab

Five minutes here prevents most rework. Look for:

  • The deadline and the return format — their spreadsheet, a portal upload, a PDF.
  • What they want attached — policies, a penetration test summary, certificates, insurance. Attachments are often the real test.
  • Whether comments are required for every No, or for every answer.
  • Scoping instructions — sections marked not applicable to this supplier.
  • Who to contact with questions. A two-line email clarifying scope is usually welcome and saves both sides time.

3. Agree the scope with the client

Three questions before any answer:

Which service? A company with two products answers for the one the customer is buying. Encryption, hosting and access controls can differ between them.

Which entity? The legal entity in the contract, which may not be the brand on the website. It matters for anything about certifications, insurance and registered addresses.

Who knows what you cannot see? Engineering for backups, logging and access; HR for background checks and training; the founder for insurance and governance. Name the person for each area now, not on Thursday.

4. Map sections to documents

A client with a documentation pack already has most answers written down. A rough map:

Questionnaire sectionWhere the answer usually is
Governance, policies, rolesInformation security policies, the DPA
Access control, identityAccess control policy
Data protection, encryption, retentionSecurity overview, retention schedule, records of processing
Incident managementIncident response policy
Business continuity, backupsBusiness continuity and disaster recovery policy
Suppliers, sub-processorsVendor management policy, sub-processor list
Secure development, changeSecure development policy
Privacy, data subject rightsPrivacy policy, DSAR procedure
People, acceptable useAcceptable use policy, offboarding procedure

Everything outside this table — physical office security, background checks, insurance, certifications — needs the client, not the documents.

If the client has no documentation pack, this is the moment to say so. A questionnaire answered from memory will contradict itself, and the customer will ask for the documents anyway.

5. Decide how to answer what the client does not have

Every questionnaire has rows where the honest answer is no: no penetration test yet, a second factor on email but not on every system, no formal awareness training. Settle the approach with the client before drafting, so the same standard applies to every row.

The options, from best to worst:

  • No, with the plan. "Not in place. A first external test is planned; the date is not set." Credible, and it does not create a promise nobody agreed.
  • Partial, stated precisely. "Required on email, source code hosting and the admin console; not yet on the cloud provider account." A reviewer can work with that.
  • N/A — only where it truly does not apply. A company with staff cannot answer N/A to HR security.
  • A Yes the documents do not support. The answer that comes back as a contractual warranty in the master agreement, or as an audit finding a year later.

Clients often worry that No answers lose the deal. For a small or growing supplier, the customer's risk team expects some. What loses trust is an answer the follow-up call disproves.

Some rows are not security questions at all:

  • "Will you notify us of a breach within 24 hours?" is a contractual commitment. The DPA sets the notification term; the answer should match it.
  • "Do you process data outside the EEA?" depends on the sub-processors and the transfer mechanisms — answer from the sub-processor list, not from where the client's own office is.
  • "Do you act as controller or processor?" is a legal qualification. Answer as the DPA says, and flag it to the client if the DPA is silent.

These are where a privacy consultant adds the most value, and where a quick Yes causes the most trouble.

7. Draft, then check consistency

Draft domain by domain. Then read the answers against each other: the same question often appears twice in different words — "is access reviewed" and "how often are user rights recertified" — and the answers must agree. Read them against the documents the customer asked to see as well: a questionnaire that says quarterly next to a policy that says annually is the row the reviewer will pick.

8. Keep the answers

The next questionnaire will ask most of the same questions in different words. Keep each approved answer with its source — the document section or the confirmed fact — so the next one starts from what the client already confirmed, not from the last spreadsheet someone can find in their email. When a fact changes, the answers that rest on it can be found and updated before the next customer reads them.

A realistic first hour

  • 0–10 minutes: identify the standard, read the instructions tab, note the attachments requested.
  • 10–25 minutes: agree service, entity and owners with the client.
  • 25–45 minutes: map sections to documents; list the rows that need a person.
  • 45–60 minutes: agree the approach to No answers; send the owners their questions.

Drafting then becomes filling in, not investigating.

Attachments: what to send and what to hold back

Customers often ask for supporting documents with the questionnaire. Decide per document:

  • Send freely: the privacy policy, the sub-processor list, the security overview, the DPA — they were written for customers.
  • Send under the NDA or on request: the full information security policy set, the incident response policy and the business continuity plan. They describe how the client works in detail; a customer evaluating a supplier is a reasonable reader, the whole internet is not.
  • Summarise instead of sending: penetration test reports and vulnerability scan results. An executive summary with findings by severity and their status is the norm; the full report is an attack map.
  • Do not send: internal access lists, architecture diagrams with hostnames, credentials, anything with customer data in it.

Whatever is sent should match the answers. A questionnaire that says the incident plan is tested yearly, attached to a plan dated two years ago, invites exactly the question you want to avoid.

When the deadline is impossible

Friday deadlines are often a procurement default rather than a hard limit. If the questionnaire cannot be answered accurately in the time, a short note to the customer — "we will return it complete by Tuesday" — is almost always accepted. An incomplete or inaccurate questionnaire returned on time is not better than an accurate one returned three days later.

After it is returned

Expect a follow-up: a call, a list of clarifying questions, or a request for one of the documents you held back. Keep a note of what was sent, in which version and to whom, so the next answer to the same customer is consistent with the last.

In clausebench

Upload the file, choose the question column, and each answer is drafted from the client's confirmed facts and documents and marked confirmed, to check or gap. A confirmed answer names the document section it rests on; a gap is written as an honest "not in place". You review, the export fills the customer's own file, and approved answers go to the library for the next questionnaire.

See what changed since your clients' policies were written

Enter up to ten client websites. Free, no sign-up, the first report in about a minute.