Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Category: Third-Party Risk Management

Vendor Assessment Questionnaire

Also known as: VRAQ, Vendor Risk Assessment Questionnaire, Vendor Security Questionnaire, Vendor Questionnaire
Simply put

A vendor assessment questionnaire is a standardized set of questions an organization sends to a third-party vendor to evaluate how that vendor handles matters such as security, data protection, and compliance. It is commonly used as part of due diligence to help an organization understand and assess the risks associated with working with a particular vendor. The questionnaire typically gathers information and evidence directly from the vendor rather than making a final risk decision on its own.

Formal definition

A Vendor Assessment Questionnaire is a structured, standardized instrument used within third-party risk management to evaluate a vendor's security posture, data handling practices, and compliance with applicable requirements. In practice it functions as a central component of vendor due diligence, providing self-reported information and supporting evidence that feeds into a broader risk assessment rather than constituting the assessment in full; sources distinguish the questionnaire (the set of questions) from the assessment (the overall evaluation of risk). Scope and content vary by vendor type and context, for example, questionnaires directed at AI vendors typically seek evidence about how the vendor's AI system operates and what data it processes. As a self-attestation tool, its outputs generally warrant corroboration, and specific control requirements, applicable regulations, and evidentiary expectations depend on jurisdiction, sector, and organizational risk criteria not detailed in the available evidence.

Why it matters

Organizations increasingly depend on third parties for critical services, and the risks those vendors carry, weak security controls, poor data handling, or gaps in compliance, can flow directly into the contracting organization. A vendor assessment questionnaire gives an organization a standardized way to surface this information during due diligence, before or during a relationship, so that risk decisions rest on documented evidence rather than assumption. Because the questionnaire is standardized, it also allows comparison across vendors and helps establish a consistent basis for evaluating whether a vendor meets the organization's risk criteria.

It is important to recognize what the questionnaire is and is not. Sources distinguish the questionnaire, the set of questions, from the assessment, which is the broader evaluation of risk that the questionnaire feeds into. Treating a completed questionnaire as a finished risk determination can create a false sense of assurance, because the instrument relies on vendor self-attestation. Its outputs generally warrant corroboration through supporting evidence and, where warranted, independent verification, since a vendor's own responses may not fully reflect operating reality.

The stakes and content vary with the vendor and the context. For example, questionnaires directed at AI vendors typically seek evidence about how the vendor's AI system operates and what data it processes, reflecting concerns specific to that category of service. Applicable regulations, evidentiary expectations, and the specific control requirements an organization sets depend on jurisdiction, sector, and its own risk criteria, none of which are detailed in the available evidence and all of which should be confirmed against primary sources and, where relevant, professional advice.

Who it's relevant to

Third-Party / Vendor Risk Managers
Those responsible for evaluating vendors use the questionnaire as a central component of due diligence to gather standardized information on a vendor's security posture, data handling, and compliance, and to feed that information into a broader risk assessment. They should treat responses as self-attested inputs that generally require corroboration rather than as final risk determinations.
Compliance Officers
Compliance professionals rely on questionnaires to help evaluate whether vendors meet applicable requirements. Because applicable regulations and evidentiary expectations vary by jurisdiction and sector and are not detailed here, they should map questionnaire content to the specific obligations relevant to their organization and verify against primary sources.
Information Security Teams
Security teams often design or review questions covering a vendor's security posture and data handling, and interpret the supporting evidence provided. For specialized vendors, such as those supplying AI systems, they may seek evidence about how the system operates and what data it processes.
Procurement and Vendor Onboarding Functions
Teams managing vendor selection and onboarding use the standardized questionnaire to collect comparable information across vendors during due diligence, supporting consistent evaluation before a relationship is established or renewed.

Inside VRAQ

Company and Ownership Information
Baseline identifying details about the vendor, such as legal entity name, corporate structure, ownership, locations, and points of contact, used to establish who the organization is contracting with and to support downstream due diligence.
Financial and Operational Viability
Questions intended to gauge the vendor's financial stability and operational capacity to deliver on obligations, often informing an assessment of the risk of service disruption. The depth of such inquiry typically varies with the criticality of the vendor.
Information Security and Data Protection Controls
Inquiries into the vendor's security measures, such as access controls, encryption practices, and handling of confidential or personal data. These questions often map to recognized frameworks and standards, though the specific references vary by organization and sector.
Regulatory and Legal Compliance
Questions addressing the vendor's adherence to applicable laws, regulations, and industry obligations relevant to the engagement. Applicability of specific requirements varies by jurisdiction and sector, and legal interpretation may require professional advice.
Certifications and Attestations
Requests for evidence of independent certifications, audit reports, or attestations that corroborate the vendor's self-reported controls. The evidentiary value depends on the scope, currency, and independence of the underlying assessment.
Business Continuity and Resilience
Questions covering the vendor's continuity planning, disaster recovery, and incident response arrangements, used to assess the risk of interruption to services on which the organization depends.
Subcontractor and Fourth-Party Reliance
Inquiries into the vendor's own use of subcontractors or downstream service providers, recognizing that risk can extend beyond the immediate contracting party.
Attestation and Sign-off
A section in which an authorized vendor representative confirms the accuracy of responses, supporting accountability for the information provided, though it does not by itself verify the underlying facts.

Common questions

Answers to the questions practitioners most commonly ask about VRAQ.

Does a completed vendor assessment questionnaire mean a vendor is compliant or low-risk?
No. A completed questionnaire typically documents a vendor's self-reported assertions about its controls and practices; it is not, by itself, independent verification that those controls exist or operate effectively. In many third-party risk management programs, questionnaire responses are treated as one input that often requires corroboration through evidence such as independent audit reports, certifications, or on-site review before a risk conclusion is drawn. A returned questionnaire also does not eliminate risk or guarantee the vendor's ongoing compliance, which can change over time.
Is a vendor assessment questionnaire the same as due diligence?
Not exactly. A questionnaire is generally one tool within a broader due diligence process rather than a substitute for it. Due diligence in many frameworks may also encompass financial review, reputational and adverse-media checks, review of independent assurance reports, contractual analysis, and ongoing monitoring. Treating the questionnaire as the entirety of due diligence can leave material aspects of third-party risk unexamined.
How should questions be tailored to the risk posed by a particular vendor?
A common practice is to scope or tier the questionnaire based on factors such as the nature of the service, the sensitivity of data accessed or processed, criticality to operations, and applicable regulatory obligations. Higher-risk relationships often warrant more detailed questions and deeper verification, while lower-risk engagements may use a shorter set. Applying a single uniform questionnaire regardless of risk can create both assessment gaps and unnecessary burden. Scoping choices should be documented so the rationale is defensible.
What evidence should accompany questionnaire responses?
Because responses are typically self-attested, many programs request supporting documentation to corroborate key answers, examples often include independent assurance reports, relevant certifications, policy documents, or summaries of test results. The appropriate evidence depends on the risk level and the specific control being assessed. Where evidence cannot be obtained, that limitation is often noted in the risk conclusion. Requirements vary by organization, sector, and jurisdiction.
How often should a vendor be reassessed?
Reassessment frequency is generally driven by the vendor's risk tier and by triggering events rather than a single fixed interval. Higher-risk or critical vendors are often reviewed more frequently, and many programs also reassess upon events such as a significant change in the service, a control failure, a security incident, or a change in regulatory requirements. Reassessment cadence should be defined in policy, and specific expectations may differ across jurisdictions and regulated sectors.
Who should be responsible for reviewing and challenging questionnaire responses?
Responsibility often involves collaboration between the business owner of the relationship and specialist functions such as information security, privacy, procurement, legal, or compliance, depending on the subject matter of the questions. A common expectation is that responses are critically reviewed and, where warranted, challenged rather than simply accepted. Clear ownership for reviewing responses, escalating concerns, and approving the resulting risk decision helps make the process auditable, though specific roles and decision rights vary by organizational structure.

Common misconceptions

Completing a vendor assessment questionnaire eliminates third-party risk.
A questionnaire is a control that helps identify and assess risk; it does not eliminate it. Residual risk typically remains after assessment, and self-reported responses may require independent corroboration through evidence, testing, or ongoing monitoring.
A questionnaire is a one-time, point-in-time exercise sufficient for the life of the relationship.
Vendor risk profiles change over time as services, ownership, controls, and regulatory obligations evolve. Many programs treat the questionnaire as part of an ongoing due diligence cycle rather than a single onboarding step.
The questionnaire is purely a compliance formality.
While it can support compliance obligations, the tool often spans multiple GRC pillars, informing risk management decisions and governance oversight of third parties, rather than serving only to demonstrate adherence to a rule.

Best practices

Scale the depth and scope of the questionnaire to the criticality and inherent risk of the vendor, rather than applying an identical questionnaire to all relationships.
Where feasible, corroborate self-reported responses with supporting evidence such as certifications, audit reports, or attestations, recognizing that their value depends on scope and currency.
Extend inquiry to subcontractors and downstream providers so that fourth-party reliance is considered as part of the overall risk picture.
Treat the questionnaire as part of an ongoing due diligence cycle, refreshing responses periodically and upon material changes to the vendor or the engagement.
Require an attestation and sign-off from an authorized vendor representative to support accountability for the accuracy of responses.
Map security, compliance, and continuity questions to the frameworks and obligations relevant to your jurisdiction and sector, and consult legal or subject-matter expertise where interpretation is required.
Promotional banner for the Penetration Report Template Kit