Skip to content
Contract Review

How to Handle Enterprise Compliance Questionnaires

4 min readUpdated 19 August 2026

Enterprise compliance questionnaires — also called vendor due diligence questionnaires (DDQs), security questionnaires, third-party risk assessments (TPRAs), or information security questionnaires (ISQs) — arrive before the contract is signed, often before serious commercial discussions begin. They are the enterprise customer's first attempt to understand your compliance posture. How you respond shapes their perception of your organisation.


What Enterprise Questionnaires Are Checking

The goal of an enterprise compliance questionnaire is to assess vendor risk across three broad dimensions:

Security risk: Can this vendor protect our data? Common topics: encryption, access control, penetration testing, incident response, BCP/DR.

Regulatory risk: Will using this vendor create compliance problems for us? Common topics: GDPR, DORA, NIS2, data residency, international transfers, AI Act.

Operational risk: Will this vendor be there when we need them? Common topics: financial stability, key-person dependency, BCP, uptime history, sub-contractor exposure.

Most questionnaires weight security and regulatory compliance heavily. Operational risk questions are often lighter unless the service is mission-critical.


The Major Questionnaire Frameworks

Enterprise customers use one or more standard frameworks plus their own additions:

SIG (Standardised Information Gathering): The most comprehensive standard questionnaire — over 800 questions across 18 domain areas. Published by Shared Assessments. Financial services companies use this most frequently.

SIG Lite: A shorter version (~170 questions) for lower-risk vendor assessments.

CAIQ (Consensus Assessments Initiative Questionnaire): Cloud Security Alliance framework focused on cloud security. Common for cloud providers and cloud-based SaaS.

VSA (Vendor Security Alliance questionnaire): Mid-size questionnaire used by tech companies. Covers key security, privacy, and compliance topics.

Bank-specific DDQs: Every major bank has its own DDQ, often longer than the standard frameworks and with sector-specific DORA and EBA sections.

DORA-specific questionnaires: Post-January 2025, financial entities are beginning to issue DORA-specific supplementary questionnaires covering ICT risk, Register of Information disclosure, and Article 30 contract compliance.


How to Prepare for Questionnaires Before They Arrive

The companies that complete questionnaires fastest maintain a master response library — a structured document covering answers to all major questionnaire domains. This is updated annually and can be adapted for each questionnaire received.

Core content to maintain:

DomainKey questions to pre-answer
GovernanceCISO or security lead, security policy, audit schedule, certifications
Access controlMFA policy, RBAC approach, access review frequency, privileged access management
Data handlingData classification, encryption standards (at rest, in transit), key management
Network securityIDS/IPS, network segmentation, firewall approach, DDoS protection
Vulnerability managementScanning frequency, penetration test schedule, patch SLAs
Incident responseIR procedure, classification tiers, notification timelines
Business continuityBCP, DR, RTO/RPO, testing frequency
Sub-processorsComplete sub-processor list, assessment process, contractual chain
Data residencyWhere data is stored, transfer mechanisms, residency options
Privacy/GDPRDPA available, DPF certification, SCCs for non-EEA transfers, sub-processor notification
Regulatory complianceCertifications (ISO 27001, SOC 2), DORA compliance statement, NIS2 supplier statement

Answering Questionnaires Well

Be Specific

"We implement appropriate security controls" fails every questionnaire review. "All production systems require MFA; we use CrowdStrike for endpoint protection; annual penetration tests are conducted by NCC Group" passes.

Don't Over-Promise

If you do not conduct quarterly penetration testing, do not claim you do. Questionnaire responses become part of the contractual record. Enterprise legal teams revisit them when incidents occur.

Attach Evidence

For key claims, attach supporting evidence:

  • ISO 27001 certificate (current, with scope)
  • SOC 2 report availability confirmation (NDA required for full report)
  • Penetration test confirmation letter (not the full report — just confirmation that testing occurred and critical findings are remediated)
  • Sub-processor list link

Flag What You Don't Cover

If a questionnaire asks about a control you do not have (e.g., annual TLPT for a smaller company), be honest. Explain what compensating control you use. Enterprise risk teams are accustomed to compensating controls at appropriate vendor tiers. Misrepresentation creates more risk than honest gaps.

Use Your Compliance Pack

A well-prepared compliance pack (DPA, Security Annex, certifications, BCP summary) allows you to answer most questionnaire sections by reference: "See attached Security Annex (Exhibit A) for our complete access control and encryption standards." This saves time and ensures consistency.


When Questionnaires Create Deal Delays

The most common cause of questionnaire-related deal delay is not compliance gaps — it is missing documentation. Procurement teams block deals when they cannot find the answer to a specific question.

Prepare:

  • A published, current DPA (accessible online without NDA)
  • A published sub-processor list (accessible online, updated with dates)
  • ISO 27001 certificate as a PDF (current, in-scope)
  • SOC 2 Type II report summary or availability confirmation
  • Security Annex as a standalone document
  • Penetration test confirmation letter from the testing firm

Having these documents ready to send in a single email response to a questionnaire request compresses the procurement timeline from weeks to days.

ComplyOne identifies every EU regulation that applies to your business in 5 minutes — free, no credit card.

See which regulations apply to you →