What they ask
Questions usually cover policies and governance, certifications, access control and MFA, encryption, backups and business continuity, incident response, vulnerability management and penetration testing, employee training, sub processors and data location. They range from a dozen questions to several hundred.
Common formats
Many customers use their own spreadsheets or portals. Standard formats also exist, such as the SIG questionnaire from Shared Assessments and the CAIQ from the Cloud Security Alliance. In some sectors a shared assessment replaces individual questionnaires, as TISAX does in automotive.
Answering efficiently
Companies that receive many questionnaires keep a library of approved answers, a set of evidence ready to share (policies, certificates, pentest summaries) and often a trust center page where customers can find it. Certifications such as ISO 27001 or a SOC 2 report answer many questions at once. Answers must be accurate, because they often become contractual commitments.
The buyer's side
For the company sending them, questionnaires are a core tool of third party risk management. Questions should be proportionate to the supplier's risk, and answers should be checked against evidence, not just filed.




