Security questionnaire answer library

The 25 questions SMEs get asked most in SIG-Lite, CAIQ and bespoke buyer questionnaires — with a model answer you can adapt, the evidence to attach, and the framework each one maps to. Fill in the bracketed values with your own facts; never claim a control you cannot evidence.

27 answers

Do you hold ISO 27001 certification or an equivalent independent assurance?

State the exact position and the scope. Example: 'We hold ISO 27001:2022 certification issued by [UKAS-accredited body], certificate number [X], covering [scope statement]. The certificate and current Statement of Applicability summary are available in our Trust Center.' If you are pre-certification, say so with a date: 'Our ISMS is operating against ISO 27001:2022; Stage 1 is scheduled for [month]. Independent penetration testing and a completed gap assessment are available now.' Never imply certification you do not hold — buyers verify with the certification body.

Category
Governance
Evidence
Certificate PDF, scope statement, SoA summary, or gap assessment report
Maps to
ISO 27001 clause 4.3 · SIG-Lite A · CAIQ GRC-01

Do you have a documented information security policy, and who approves it?

'Yes. Our information security policy is approved by [role, e.g. the Managing Director] and reviewed at least annually and after material change. It is supported by [n] topic-specific policies covering access control, acceptable use, cryptography, supplier security, incident response and data protection. All staff acknowledge the policy set at induction and annually, and acknowledgement is tracked centrally.'

Category
Governance
Evidence
Policy pack index with version, approval date and acknowledgement report
Maps to
ISO 27001 A.5.1, A.5.4 · SOC 2 CC5

Who is accountable for information security in your organisation?

Name a role, not a committee. 'Overall accountability sits with [role]. Day-to-day management of the ISMS is owned by [role], who reports security performance to the leadership team at least quarterly and formally at management review.' Small teams should say so plainly rather than inventing an org chart — buyers accept a named owner in a 12-person company; they do not accept 'everyone is responsible'.

Category
Governance
Evidence
Roles and responsibilities matrix; management review minutes
Maps to
ISO 27001 clause 5.3, A.5.2

How often do you perform a risk assessment?

'We maintain a live risk register scored on likelihood and impact with inherent and residual ratings. Risks are reviewed continuously as they change, with a full formal review at least annually and after significant change to systems, suppliers or scope. Treatment plans have named owners and due dates, and progress is reported at management review.'

Category
Governance
Evidence
Risk register export (redacted), risk methodology, last review date
Maps to
ISO 27001 clauses 6.1.2, 8.2 · SIG-Lite B

Do you conduct internal audits of your security programme?

'Yes. We run an internal audit programme covering the full management system across a rolling 12-month cycle, performed by [internal auditor / independent consultant] who is independent of the area audited. Findings are logged as nonconformities with root cause, corrective action, owner and verification of effectiveness.'

Category
Governance
Evidence
Audit programme, latest audit report, corrective action log
Maps to
ISO 27001 clause 9.2, A.5.35 · SOC 2 CC4

Is multi-factor authentication enforced?

'Yes. MFA is enforced for all users on all business systems through [identity provider] single sign-on, with conditional access policies blocking legacy authentication. Administrative accounts additionally require [phishing-resistant method / separate admin identity]. Exceptions require documented approval and are time-limited.'

Category
Access & identity
Evidence
Conditional access policy export; MFA registration report
Maps to
ISO 27001 A.5.17, A.8.5 · Cyber Essentials · CAIQ IAM-02

How do you manage joiners, movers and leavers?

'Access is provisioned from a documented role-based access matrix on the first day and removed within [4 working hours / same business day] of departure, triggered by an HR-initiated ticket. Role changes trigger a re-review of entitlements rather than additive access. Leaver actions include account disablement, session and token revocation, MFA de-registration and device return.'

Category
Access & identity
Evidence
JML procedure, sample leaver ticket showing timestamps
Maps to
ISO 27001 A.5.18, A.6.5 · SOC 2 CC6.2/6.3

How often do you review user access rights?

'We perform documented access reviews at least quarterly for privileged and production access, and at least annually for all other systems. Each review is certified by the system owner, and revocations are actioned and evidenced within the review record.'

Category
Access & identity
Evidence
Access review record with reviewer, date and actions taken
Maps to
ISO 27001 A.5.18, A.8.2 · SIG-Lite H

How is privileged access controlled?

'Privileged access is granted on least privilege, using separate administrative identities, protected by phishing-resistant MFA, and where the platform supports it, granted just-in-time with approval and automatic expiry. All privileged activity is logged to a tamper-resistant store and monitored for anomalies.'

Category
Access & identity
Evidence
Privileged role assignment report; PIM/JIT configuration
Maps to
ISO 27001 A.8.2, A.8.18 · CAIQ IAM-05

Is customer data encrypted in transit and at rest?

'Yes. All data in transit is encrypted with TLS 1.2 or above, with TLS 1.3 preferred and weak ciphers disabled. Data at rest is encrypted using AES-256 through [platform] managed keys. Key management, rotation and access are documented in our cryptographic controls policy.'

Category
Data protection
Evidence
SSL Labs report, platform encryption settings, cryptography policy
Maps to
ISO 27001 A.8.24 · SOC 2 CC6.7 · CAIQ EKM

Where is our data stored and are there international transfers?

State regions explicitly. 'Customer data is stored in [UK/EU region]. Backups remain in the same region. Sub-processors that may access data outside the UK are listed in our sub-processor register with the transfer mechanism relied on (adequacy decision, UK IDTA or SCCs). We notify customers of new sub-processors [n] days in advance.'

Category
Data protection
Evidence
Sub-processor list, DPA, transfer risk assessment
Maps to
UK GDPR Art 28/44-49 · ISO 27001 A.5.34

What are your data retention and deletion practices?

'Retention periods are defined per data category in our retention schedule and enforced in the platform. On contract termination customer data is deleted within [n] days of the end of the agreed retrieval window, and backup copies age out within the backup retention period of [n] days. Written confirmation of deletion is provided on request.'

Category
Data protection
Evidence
Retention schedule, deletion procedure, sample deletion confirmation
Maps to
ISO 27001 A.8.10, A.5.33 · UK GDPR Art 5(1)(e)

Do you have a data processing agreement and named DPO?

'Yes. Our standard DPA incorporates UK GDPR Article 28 terms, the UK International Data Transfer Addendum where relevant, and our current sub-processor list. We are registered with the ICO (registration [X]). We are not required to appoint a statutory DPO; the accountable privacy role is [title], contactable at [address].'

Category
Data protection
Evidence
DPA template, ICO registration, privacy role definition
Maps to
UK GDPR Art 28, 30, 37

How do you separate customer data in a multi-tenant environment?

'Tenant data is logically separated and enforced at the database layer with row-level security tied to the authenticated tenant context, so a query cannot return another tenant's rows even in the event of an application bug. Separation is covered by automated regression tests and reviewed during penetration testing.'

Category
Data protection
Evidence
Architecture description, RLS policy summary, pen test scope
Maps to
ISO 27001 A.8.22 · CAIQ IVS-09

How do you manage vulnerabilities and patching?

'We scan infrastructure and dependencies continuously and remediate to documented SLAs: critical within [7] days, high within [30], medium within [90]. Operating systems and endpoints receive vendor security updates automatically within [14] days. Exceptions are risk-assessed, approved and time-limited.'

Category
Infrastructure
Evidence
Scan reports, patch compliance report, exception register
Maps to
ISO 27001 A.8.8 · Cyber Essentials · SOC 2 CC7.1

Do you perform penetration testing?

'Yes. An independent [CREST/CHECK-accredited] third party performs an application and infrastructure penetration test at least annually and after significant architectural change. Findings are tracked to closure with remediation SLAs by severity, and a summary letter is available under NDA.'

Category
Infrastructure
Evidence
Pen test summary letter, remediation tracker
Maps to
ISO 27001 A.8.29 · SIG-Lite I

What logging and monitoring do you have in place?

'Security-relevant events — authentication, privilege change, configuration change and data access — are logged centrally with [n] months' retention and protection against alteration. Alerts for anomalous behaviour are routed to a named owner with a documented triage path into our incident process, including out-of-hours cover for critical alerts.'

Category
Infrastructure
Evidence
Log retention configuration, sample alert triage record
Maps to
ISO 27001 A.8.15, A.8.16 · SOC 2 CC7.2

Are endpoints managed and protected?

'All endpoints are enrolled in [MDM], enforce full-disk encryption, screen lock, automatic updates and EDR (next-generation anti-malware). Compliance is monitored continuously and non-compliant devices are blocked from accessing corporate resources through conditional access.'

Category
Infrastructure
Evidence
Device compliance report, encryption report, EDR coverage
Maps to
ISO 27001 A.8.1, A.8.7 · Cyber Essentials

Do you follow a secure development lifecycle?

'Yes. Security requirements are defined at design, all changes require peer review through protected branches, and CI runs static analysis, dependency (SCA) and secret scanning on every pull request. Findings are triaged to severity-based SLAs. Developers receive secure coding training annually, referenced to the OWASP Top 10.'

Category
Software development
Evidence
Branch protection settings, CI configuration, training records
Maps to
ISO 27001 A.8.25, A.8.28 · SOC 2 CC8.1

How do you separate development, test and production?

'Environments are fully separated with distinct credentials and no shared administrative access. Production data is not used in development or test; where realistic data is required it is masked or synthetically generated. Deployment to production requires review and is fully logged.'

Category
Software development
Evidence
Environment diagram, change records, masking procedure
Maps to
ISO 27001 A.8.31, A.8.33, A.8.11

What are your backup arrangements and have they been tested?

'Backups run [daily] with [n] days' retention, are encrypted and held in a separate location/account with restricted, separately credentialed access to resist ransomware. Restoration is tested at least [annually / quarterly] with documented results, and the last successful restore test was [date].'

Category
Resilience
Evidence
Backup configuration, dated restore test record
Maps to
ISO 27001 A.8.13, A.5.30 · SIG-Lite K

What are your RTO and RPO commitments?

Give numbers you can meet. 'Our target recovery time objective is [n] hours and recovery point objective [n] hours for the production service. These are derived from a business impact analysis and validated during our annual continuity exercise. Contractual availability commitments are set out in our SLA.'

Category
Resilience
Evidence
BIA summary, continuity test report, SLA
Maps to
ISO 27001 A.5.29, A.5.30 · ISO 22301

How would you notify us of a security incident affecting our data?

'Our incident response plan defines severity levels, roles and escalation. Where an incident affects customer data we notify the named customer contact without undue delay and in any event within [24/48] hours of confirming impact, followed by regular updates and a post-incident report. Where the incident is a personal data breach we support the customer's regulatory obligations, including the UK GDPR 72-hour timeline.'

Category
Resilience
Evidence
Incident response plan, notification procedure, tabletop record
Maps to
ISO 27001 A.5.24-A.5.26 · UK GDPR Art 33

How do you assess the security of your suppliers and sub-processors?

'Suppliers are tiered by the data they access and the impact of their failure. Tier 1 suppliers are assessed before onboarding and annually thereafter, using their independent assurance (ISO 27001, SOC 2) where available and a proportionate questionnaire where not. Security requirements, breach notification and audit rights are written into contracts, and gaps become tracked actions.'

Category
Third parties
Evidence
Supplier register with tiers, assessment records, contract clauses
Maps to
ISO 27001 A.5.19-A.5.23 · SIG-Lite J

What background checks and training do staff receive?

'All staff are subject to pre-employment screening appropriate to their role, including identity, right to work, employment history and, where justified, criminal record checks. All staff complete security and data protection awareness training at induction and at least annually, plus periodic phishing simulations; completion is tracked and followed up.'

Category
People
Evidence
Screening procedure, training completion report, phishing results
Maps to
ISO 27001 A.6.1, A.6.3 · SOC 2 CC1.4

Do staff work remotely, and how is that secured?

'Yes. Remote work is covered by policy and secured through managed, encrypted devices, SSO with MFA and conditional access that restricts access from non-compliant devices. Home working requirements including clear screen, physical security and prohibited use of personal devices for customer data are set out in the remote working policy.'

Category
People
Evidence
Remote working policy, conditional access configuration
Maps to
ISO 27001 A.6.7, A.7.9

Do you use AI, and is our data used to train models?

This is now one of the most common questions and a strong differentiator when answered clearly. 'We use AI features for [specific purposes]. Customer data is not used to train third-party or public models; our AI providers process data under contractual terms that prohibit training on customer content and prohibit retention beyond the request. AI use cases are recorded in an AI use-case register with a risk assessment and a human review step for any output affecting a decision, governed under ISO 42001 principles.'

Category
AI
Evidence
AI policy, AI use-case register, provider terms extract
Maps to
ISO 42001 · EU AI Act Art 4 · ISO 27001 A.5.23

Answer once, reuse on every questionnaire

ISO-STANDARD.app keeps your approved answers and evidence in one Q&A library, and publishes the safe subset to a public Trust Center so most buyers never send you a spreadsheet at all.