- › Vendor security questionnaires are usually completed by whoever is closest to the deal, often by copying last quarter's answers for a different customer.
- › On the buying side, the reviewer is typically measured on how many reviews clear, which rewards checking that every row has an answer.
- › Yes and no answers to broad questions leave no room for the honest answer, which is usually partly, so people pick the answer that keeps the deal moving.
- › Fewer sharper questions, evidence for the ones that matter, and answers that become contract terms change who answers and how carefully.
- › Tier the process, so the depth goes to the vendors who can actually reach your data.
It is a Tuesday afternoon at a software company, and a salesperson has a deal that needs to close by Friday. The prospect’s security team has sent over a spreadsheet with three hundred questions. The engineer who could answer most of them properly is on another project, so the salesperson opens the completed questionnaire from a different customer last quarter and starts copying rows across.
Where the old answers do not quite fit, they choose the one that is closest to true and least likely to start a follow-up thread. Nobody is lying, exactly. Everybody involved would describe themselves as trying to be helpful.
Across town, a procurement analyst has forty vendor reviews in the queue. The spreadsheet comes back complete, every row answered, and she checks that every row has something in it and files it. The deal closes on Friday.
I have sat on both sides of that exchange, and the thing worth saying first is that neither of those people is doing anything wrong by the standards their organizations set for them. Each one is following the incentives in front of them with real care.
Both Sides Are Doing Their Jobs
The salesperson is measured on closed deals. A security questionnaire that sits unanswered for two weeks while an engineer is found is a deal that slips into next quarter, and they will hear about that from their manager. Answering quickly and favorably is exactly the behavior their compensation plan asks for.
The procurement analyst is often measured on throughput, meaning how many vendor reviews clear, how fast, and how few get escalated. A questionnaire with every row filled in looks like a completed review. Reading each answer skeptically, chasing the vague ones, and asking for proof would make her slower than her colleagues, and nobody gives out awards for the vendor review that took three weeks.
So the questionnaire becomes a ritual that both sides perform, and it looks like diligence from every angle except the one that matters. The vendor learns that answers are rarely checked, and the buyer learns that answers are rarely reliable. Both keep doing it, because stopping would be the expensive choice for whoever stopped first.
The Questions Invite the Answer
The format does a lot of the damage on its own. A typical questionnaire asks something like whether the vendor encrypts data at rest, with a yes or no box. The honest answer at many companies is partly: the main database is encrypted, the backups are, a reporting replica somebody set up two years ago is not. There is no box for partly, and a salesperson under a deadline is not going to write a paragraph when a checkbox is offered.
Length makes it worse. Three hundred questions of equal weight bury the ten that actually decide whether this vendor is a risk to you. Somebody filling it out gives the same attention to whether there is a clean desk policy as to whether administrative access requires multi-factor authentication, which means both get very little.
The people answering are responding sensibly to a document we designed to reward speed and tidy answers, and then we act surprised when it collects speedy, tidy answers.
What Regulators Now Expect
The expectations around vendor risk are moving away from the questionnaire as proof. When Labcorp settled with 44 states last week over its collection agency’s breach, the terms required it to make its debt collectors run risk assessments and penetration tests and obtain annual SOC 2 Type 2 audits, and to use outside assessors on its vendor risk program, as we covered in Friday’s compliance briefing. That is a regulator describing what it expects diligence to look like, and a completed spreadsheet is not on the list.
What Changes the Behavior
The fixes that work all change the incentives on one side of the table or the other, so that the careful answer stops being the costly one. None of them needs new software, and most can start with the next vendor review in your queue.
Ask fewer questions, and make them open
Replace most of the questionnaire with ten or so questions that genuinely decide the risk, written as “describe how” instead of yes or no. Ask how administrative access to production is controlled, how they would know if a customer’s data left their environment, and what happened in their last incident. Open questions are harder to copy from another customer’s answers, and they tend to reach somebody who actually knows.
Ask for evidence on the questions that matter
For the handful of controls you truly depend on, ask to see something. The multi-factor authentication policy setting, the summary page of the last penetration test, the date of the last restore test. A vendor with a real control can produce evidence in an afternoon, and one without it will tell you something useful by how they respond.
Talk to somebody technical
For vendors who will hold your sensitive data, a thirty minute call with their security or engineering lead teaches you more than any spreadsheet. People describe their environment more honestly in conversation, partly because it is hard to improvise a convincing answer about a system you do not understand.
Put the answers in the contract
When a vendor’s material answers become representations in the agreement, the questionnaire suddenly gets routed to legal and engineering instead of sales. Nothing changes the care taken over an answer as quickly as somebody realizing they will be held to it.
Spend the depth where the access is
Not every vendor needs the same review. The office catering company and the firm processing your customer records should not get the same three hundred questions, and sending them both a long form is how reviewers end up skimming everything. We made a related point about vendors that quietly depend on the same few providers, where the risk concentrates somewhere the questionnaire never asks about.
A Kinder Process Gets Better Answers
The salesperson copying last quarter’s answers and the analyst filing them without reading are both people trying to do right by their teams inside a process that asks for the wrong thing. Give the vendor fewer questions they can answer honestly, give your reviewer the time and the mandate to push on the answers that matter, and make the answers count for something. Both of those people will do better work, and you will finally learn something true about the companies holding your data.
Marie Welch is Director of Behavioral Security Operations at Grab The Axe.
With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.
View Author Page →