Enterprise compliance questionnaires — also called vendor due diligence questionnaires (DDQs), security questionnaires, third-party risk assessments (TPRAs), or information security questionnaires (ISQs) — arrive before the contract is signed, often before serious commercial discussions begin. They are the enterprise customer's first attempt to understand your compliance posture. How you respond shapes their perception of your organisation.
What Enterprise Questionnaires Are Checking
The goal of an enterprise compliance questionnaire is to assess vendor risk across three broad dimensions:
Security risk: Can this vendor protect our data? Common topics: encryption, access control, penetration testing, incident response, BCP/DR.
Regulatory risk: Will using this vendor create compliance problems for us? Common topics: GDPR, DORA, NIS2, data residency, international transfers, AI Act.
Operational risk: Will this vendor be there when we need them? Common topics: financial stability, key-person dependency, BCP, uptime history, sub-contractor exposure.
Most questionnaires weight security and regulatory compliance heavily. Operational risk questions are often lighter unless the service is mission-critical.
The Major Questionnaire Frameworks
Enterprise customers use one or more standard frameworks plus their own additions:
SIG (Standardised Information Gathering): The most comprehensive standard questionnaire — over 800 questions across 18 domain areas. Published by Shared Assessments. Financial services companies use this most frequently.
SIG Lite: A shorter version (~170 questions) for lower-risk vendor assessments.
CAIQ (Consensus Assessments Initiative Questionnaire): Cloud Security Alliance framework focused on cloud security. Common for cloud providers and cloud-based SaaS.
VSA (Vendor Security Alliance questionnaire): Mid-size questionnaire used by tech companies. Covers key security, privacy, and compliance topics.
Bank-specific DDQs: Every major bank has its own DDQ, often longer than the standard frameworks and with sector-specific DORA and EBA sections.
DORA-specific questionnaires: Post-January 2025, financial entities are beginning to issue DORA-specific supplementary questionnaires covering ICT risk, Register of Information disclosure, and Article 30 contract compliance.
How to Prepare for Questionnaires Before They Arrive
The companies that complete questionnaires fastest maintain a master response library — a structured document covering answers to all major questionnaire domains. This is updated annually and can be adapted for each questionnaire received.
Core content to maintain:
| Domain | Key questions to pre-answer |
|---|---|
| Governance | CISO or security lead, security policy, audit schedule, certifications |
| Access control | MFA policy, RBAC approach, access review frequency, privileged access management |
| Data handling | Data classification, encryption standards (at rest, in transit), key management |
| Network security | IDS/IPS, network segmentation, firewall approach, DDoS protection |
| Vulnerability management | Scanning frequency, penetration test schedule, patch SLAs |
| Incident response | IR procedure, classification tiers, notification timelines |
| Business continuity | BCP, DR, RTO/RPO, testing frequency |
| Sub-processors | Complete sub-processor list, assessment process, contractual chain |
| Data residency | Where data is stored, transfer mechanisms, residency options |
| Privacy/GDPR | DPA available, DPF certification, SCCs for non-EEA transfers, sub-processor notification |
| Regulatory compliance | Certifications (ISO 27001, SOC 2), DORA compliance statement, NIS2 supplier statement |
Answering Questionnaires Well
Be Specific
"We implement appropriate security controls" fails every questionnaire review. "All production systems require MFA; we use CrowdStrike for endpoint protection; annual penetration tests are conducted by NCC Group" passes.
Don't Over-Promise
If you do not conduct quarterly penetration testing, do not claim you do. Questionnaire responses become part of the contractual record. Enterprise legal teams revisit them when incidents occur.
Attach Evidence
For key claims, attach supporting evidence:
- ISO 27001 certificate (current, with scope)
- SOC 2 report availability confirmation (NDA required for full report)
- Penetration test confirmation letter (not the full report — just confirmation that testing occurred and critical findings are remediated)
- Sub-processor list link
Flag What You Don't Cover
If a questionnaire asks about a control you do not have (e.g., annual TLPT for a smaller company), be honest. Explain what compensating control you use. Enterprise risk teams are accustomed to compensating controls at appropriate vendor tiers. Misrepresentation creates more risk than honest gaps.
Use Your Compliance Pack
A well-prepared compliance pack (DPA, Security Annex, certifications, BCP summary) allows you to answer most questionnaire sections by reference: "See attached Security Annex (Exhibit A) for our complete access control and encryption standards." This saves time and ensures consistency.
When Questionnaires Create Deal Delays
The most common cause of questionnaire-related deal delay is not compliance gaps — it is missing documentation. Procurement teams block deals when they cannot find the answer to a specific question.
Prepare:
- A published, current DPA (accessible online without NDA)
- A published sub-processor list (accessible online, updated with dates)
- ISO 27001 certificate as a PDF (current, in-scope)
- SOC 2 Type II report summary or availability confirmation
- Security Annex as a standalone document
- Penetration test confirmation letter from the testing firm
Having these documents ready to send in a single email response to a questionnaire request compresses the procurement timeline from weeks to days.