Supplier security questionnaire template
Sending a 200-question spreadsheet to a five-person supplier gets you nothing back. This template tiers suppliers by risk and asks proportionate questions you can actually assess — and it produces the evidence ISO 27001 A.5.19 to A.5.22 expect.
Every field, explained
| Field | What to put in it |
|---|---|
| Question ref | Stable reference so answers can be compared year on year. |
| Question | One clear question. Avoid compound questions — they produce unscoreable answers. |
| Tier (1/2/3) | Tier 1 = critical supplier with access to personal or production data. Tier 3 = low-impact tooling. Only send the tier-appropriate subset. |
| Supplier answer | The supplier's own words, kept verbatim. |
| Evidence provided | Certificate, report or screenshot reference. An answer with no evidence scores lower. |
| Assessor comment | Your judgement, including anything you accepted on risk. |
| Score (0-3) | 0 not met, 1 partial, 2 met, 3 met with independent assurance. |
| Follow-up action | Owner and due date where the answer is not acceptable. |
Worked examples
- Question ref
- SEC-04
- Question
- Is multi-factor authentication enforced for all administrative access?
- Tier (1/2/3)
- 1
- Supplier answer
- Yes, enforced for all staff via SSO with conditional access.
- Evidence provided
- Screenshot of conditional access policy; SOC 2 Type II §CC6.1
- Assessor comment
- Independently assured. No action.
- Score (0-3)
- 3
- Follow-up action
- —
- Question ref
- DP-02
- Question
- Where is our data stored and processed?
- Tier (1/2/3)
- 1
- Supplier answer
- UK region primary, EU secondary for disaster recovery.
- Evidence provided
- Contract schedule 2; DPA clause 7
- Assessor comment
- Acceptable. EU transfer covered by the UK addendum.
- Score (0-3)
- 2
- Follow-up action
- Re-confirm at annual review
- Question ref
- BC-01
- Question
- Do you test restoration from backup at least annually?
- Tier (1/2/3)
- 2
- Supplier answer
- Backups run daily; restore testing is ad hoc.
- Evidence provided
- None
- Assessor comment
- Gap. Untested backups are not a recovery capability.
- Score (0-3)
- 1
- Follow-up action
- Supplier to provide restore test evidence by 30 Sep 2026 (Ops Manager)
How to use it
- Tier the supplier before you send anything — impact if they fail, plus the data they touch.
- Send only the tier-appropriate question set; a shorter questionnaire gets a faster, better answer.
- Accept existing assurance (ISO 27001 certificate scope, SOC 2 report, Cyber Essentials) in place of re-answering.
- Score consistently so you can compare suppliers and track improvement.
- Convert every gap into an owned action with a due date — that is what closes the loop for the auditor.
- Re-run tier 1 suppliers annually and on contract renewal.
What auditors pick up
- Questionnaires sent but never assessed — answers filed with no scoring or comment.
- Certificate collected once at onboarding and long expired.
- No supplier tiering, so the same effort is spent on the payroll provider and the stock photo site.
- Identified gaps with no corrective action or owner.
FAQ
How many questions should a supplier security questionnaire have?
For a tier 1 supplier, 25–40 well-chosen questions is plenty for an SME. Tier 2 typically needs 10–15 and tier 3 can often be satisfied by a certificate check alone.
Can we accept a SOC 2 report instead of a completed questionnaire?
Usually yes for the areas the report covers, provided you read the scope, the period and the exceptions. Record that you reviewed it and note anything the report does not cover.
Which ISO 27001 controls does this evidence?
A.5.19 supplier relationships, A.5.20 supplier agreements, A.5.21 ICT supply chain and A.5.22 monitoring and review of supplier services — plus A.5.23 where the supplier is a cloud service.
Related
Stop maintaining spreadsheets
Every template here exists as a live module inside ISO-STANDARD.app — owners, review dates, evidence links and audit trail included, with AI-generated remediation plans when something fails.
- Pre-loaded ISO 27001, 9001, 42001 and SOC 2 content
- Evidence vault with versioning
- Named owners and review reminders
- Export back to CSV any time
