1. Purpose
The Supplier Due Diligence Questionnaire is used to collect information from suppliers, vendors, contractors, consultants, service providers, cloud providers, SaaS providers, and other third parties before or during a business relationship.
The questionnaire helps the organization understand:
- Who the supplier is
- What service it provides
- What information it handles
- What systems it accesses
- What security controls it has
- What privacy risks exist
- Whether subprocessors are involved
- Where data is processed
- How incidents are managed
- How business continuity is maintained
- What security assurance is available
- What risks require further assessment or treatment
Core Principle
Supplier → Service → Information → Access → Dependency → Security Controls → Evidence → Risk → Approval → Monitoring → Reassessment
2. Instructions to Supplier
Please answer each applicable question using:
- Yes – Requirement is implemented
- No – Requirement is not implemented
- Partially – Requirement is partially implemented
- N/A – Requirement does not apply
Where appropriate, provide supporting evidence or a short explanation.
Important
Do not provide:
- Passwords
- API keys
- Access tokens
- Encryption keys
- Production credentials
- Other confidential authentication secrets
Evidence should be shared through an approved secure channel.
3. Supplier Information
| Field | Supplier Response |
|---|---|
| Legal Entity Name | |
| Trading Name | |
| Registered Address | |
| Website | |
| Primary Contact | |
| Security Contact | |
| Privacy Contact | |
| Country of Registration | |
| Countries of Operation | |
| Year Established | |
| Number of Employees | |
| Service/Product | |
| Business Owner | |
| Proposed Start Date | |
| Existing Supplier | Yes / No |
4. Supplier Ownership and Organization
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 1 | Provide a brief description of your organization. | ||
| 2 | Identify the legal entity providing the service. | ||
| 3 | Identify the parent company, if applicable. | ||
| 4 | Identify any material ownership or control changes in the last 12 months. | ||
| 5 | Identify the countries where the service is delivered. | ||
| 6 | Identify key security/privacy contacts. | ||
| 7 | Is information security formally assigned to responsible personnel? |
5. Service and Business Scope
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 8 | Describe the service being provided. | ||
| 9 | What business processes does the service support? | ||
| 10 | Is the service hosted by your organization or a third party? | ||
| 11 | Is the service business-critical? | ||
| 12 | What would happen if the service became unavailable? | ||
| 13 | Are alternative service arrangements available? | ||
| 14 | What is the expected service availability? | ||
| 15 | Are service-level commitments documented? |
6. Information and Data
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 16 | What information will you receive from the organization? | ||
| 17 | What information will you store? | ||
| 18 | What information will you process? | ||
| 19 | Will you process customer information? | ||
| 20 | Will you process employee information? | ||
| 21 | Will you process personal data? | ||
| 22 | Will you process confidential information? | ||
| 23 | Will you process restricted or highly sensitive information? | ||
| 24 | Will you access source code? | ||
| 25 | Will you access security-related information? | ||
| 26 | Will you process financial or payment information? |
7. Data Classification and Handling
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 27 | Do you have a formal information-classification process? | ||
| 28 | Are customer and confidential information handling requirements documented? | ||
| 29 | Is access to sensitive information restricted based on business need? | ||
| 30 | Are information-handling procedures provided to employees? | ||
| 31 | Are secure disposal procedures implemented? | ||
| 32 | Are removable media and data exports controlled where appropriate? |
8. Information Security Governance
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 33 | Do you maintain a formal information-security program? | ||
| 34 | Is an information-security policy established? | ||
| 35 | Is information security assigned to responsible management? | ||
| 36 | Do you conduct periodic security risk assessments? | ||
| 37 | Do you maintain a security risk register? | ||
| 38 | Are security policies reviewed periodically? | ||
| 39 | Are security responsibilities formally defined? | ||
| 40 | Is security performance reported to management? |
9. Security Certifications and Assurance
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 41 | Do you hold ISO/IEC 27001 certification? | ||
| 42 | Do you have a SOC 2 report? | ||
| 43 | Do you have other relevant certifications? | ||
| 44 | Have you undergone an independent security assessment? | ||
| 45 | Do you conduct penetration testing? | ||
| 46 | Can appropriate security assurance evidence be provided? | ||
| 47 | Are identified audit findings tracked to closure? |
Provide certificate/report details where applicable.
Note: A certification or independent report supports due diligence but does not automatically eliminate supplier-specific risks.
10. Risk Management
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 48 | Is information-security risk formally assessed? | ||
| 49 | Are risks assigned to responsible owners? | ||
| 50 | Are risk-treatment actions tracked? | ||
| 51 | Are residual risks formally reviewed? | ||
| 52 | Are security risks reassessed after major changes or incidents? |
11. Identity and Access Management
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 53 | Is user access formally approved? | ||
| 54 | Is access based on least privilege? | ||
| 55 | Are individual user accounts used? | ||
| 56 | Are shared accounts restricted or controlled? | ||
| 57 | Is access reviewed periodically? | ||
| 58 | Is access removed promptly when no longer required? | ||
| 59 | Are administrator accounts separately controlled? | ||
| 60 | Are privileged activities logged? |
12. Multi-Factor Authentication
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 61 | Is MFA implemented for administrative access? | ||
| 62 | Is MFA implemented for remote access? | ||
| 63 | Is MFA implemented for systems containing sensitive information? | ||
| 64 | Are MFA exceptions formally controlled? |
13. Privileged Access
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 65 | Is privileged access formally approved? | ||
| 66 | Is privileged access limited to authorized personnel? | ||
| 67 | Is privileged access periodically reviewed? | ||
| 68 | Are privileged activities logged and monitored? | ||
| 69 | Is emergency/break-glass access controlled? | ||
| 70 | Are unnecessary privileged permissions removed? |
14. Personnel Security
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 71 | Are personnel security responsibilities defined? | ||
| 72 | Are appropriate background checks performed where legally permitted and appropriate? | ||
| 73 | Are confidentiality obligations established? | ||
| 74 | Do employees receive security awareness training? | ||
| 75 | Is security training repeated periodically? | ||
| 76 | Are disciplinary processes defined for security violations? | ||
| 77 | Are access rights removed when personnel leave? |
15. Physical Security
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 78 | Are facilities protected against unauthorized access? | ||
| 79 | Is physical access controlled? | ||
| 80 | Are visitors controlled? | ||
| 81 | Are critical systems hosted in appropriately secured facilities? | ||
| 82 | Are environmental risks addressed? | ||
| 83 | Is physical security monitored where appropriate? |
16. Endpoint Security
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 84 | Are company-managed endpoints protected? | ||
| 85 | Is endpoint security software implemented? | ||
| 86 | Are security patches applied within defined timelines? | ||
| 87 | Is disk encryption implemented where appropriate? | ||
| 88 | Are unauthorized applications restricted? | ||
| 89 | Is remote-device security managed? |
17. Network Security
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 90 | Are networks appropriately segmented? | ||
| 91 | Are firewalls implemented where appropriate? | ||
| 92 | Is network traffic monitored? | ||
| 93 | Are insecure network protocols restricted? | ||
| 94 | Is remote access securely controlled? | ||
| 95 | Are network security rules periodically reviewed? |
18. Cloud Security
Complete this section where cloud services are used.
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 96 | Do you use public cloud infrastructure? | ||
| 97 | Identify cloud providers used. | ||
| 98 | Is cloud access controlled through IAM? | ||
| 99 | Is MFA enabled for privileged cloud access? | ||
| 100 | Are cloud configurations periodically reviewed? | ||
| 101 | Is cloud activity logged? | ||
| 102 | Is sensitive data encrypted in the cloud? | ||
| 103 | Are cloud backups implemented? | ||
| 104 | Are cloud security incidents monitored? |
19. Application Security
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 105 | Is secure software development practiced? | ||
| 106 | Are security requirements considered during development? | ||
| 107 | Is code reviewed before release? | ||
| 108 | Are dependencies monitored for vulnerabilities? | ||
| 109 | Is application security testing performed? | ||
| 110 | Are security defects tracked to remediation? | ||
| 111 | Are production and development environments appropriately separated? |
20. Vulnerability Management
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 112 | Is vulnerability scanning performed? | ||
| 113 | Are critical vulnerabilities prioritized? | ||
| 114 | Are remediation timelines defined? | ||
| 115 | Is penetration testing performed where appropriate? | ||
| 116 | Are vulnerabilities tracked through closure? | ||
| 117 | Are exceptions formally documented? |
21. Malware Protection
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 118 | Is malware protection implemented? | ||
| 119 | Are malware events monitored? | ||
| 120 | Are endpoints regularly updated? | ||
| 121 | Are suspicious activities investigated? |
22. Logging and Monitoring
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 122 | Are security-relevant events logged? | ||
| 123 | Are privileged activities logged? | ||
| 124 | Are logs protected against unauthorized modification? | ||
| 125 | Is security monitoring performed? | ||
| 126 | Are alerts investigated? | ||
| 127 | Is log retention defined? |
23. Security Incident Management
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 128 | Is an incident-response process documented? | ||
| 129 | Are security incidents formally recorded? | ||
| 130 | Are incident responsibilities defined? | ||
| 131 | Are incidents classified based on severity? | ||
| 132 | Are incidents investigated and contained? | ||
| 133 | Are corrective actions tracked? | ||
| 134 | Are lessons learned incorporated into security improvements? |
24. Security Incident Notification
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 135 | Do you have a formal customer incident-notification process? | ||
| 136 | Are customers notified within agreed contractual timeframes? | ||
| 137 | Does notification include relevant incident information? | ||
| 138 | Is evidence preserved during investigations? | ||
| 139 | Is post-incident reporting available where appropriate? |
25. Personal Data and Privacy
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 140 | Do you process personal data on behalf of customers? | ||
| 141 | Do you maintain a privacy program? | ||
| 142 | Are privacy responsibilities assigned? | ||
| 143 | Is a DPA available where required? | ||
| 144 | Are processing purposes documented? | ||
| 145 | Are data-subject rights supported? | ||
| 146 | Are privacy incidents managed? | ||
| 147 | Are personal-data retention requirements defined? | ||
| 148 | Is personal data securely deleted when no longer required? |
26. Data Breach Management
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 149 | Is there a personal-data breach response process? | ||
| 150 | Are breaches investigated promptly? | ||
| 151 | Are affected customers notified as contractually required? | ||
| 152 | Are regulatory notification responsibilities understood? | ||
| 153 | Are breach records maintained? |
27. Encryption
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 154 | Is sensitive information encrypted in transit? | ||
| 155 | Is sensitive information encrypted at rest? | ||
| 156 | Are encryption keys appropriately protected? | ||
| 157 | Are cryptographic mechanisms reviewed periodically? | ||
| 158 | Are encryption exceptions controlled? |
28. Secrets and Credentials
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 159 | Are passwords securely managed? | ||
| 160 | Are API keys securely stored? | ||
| 161 | Are secrets stored in an appropriate secrets-management mechanism? | ||
| 162 | Are credentials rotated where appropriate? | ||
| 163 | Are credentials prohibited from being stored in source code? |
29. Backup and Recovery
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 164 | Are business-critical data backed up? | ||
| 165 | Is backup frequency defined? | ||
| 166 | Are backups protected from unauthorized access? | ||
| 167 | Are backups tested periodically? | ||
| 168 | Are restoration procedures documented? | ||
| 169 | Are recovery objectives defined where appropriate? |
30. Business Continuity and Disaster Recovery
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 170 | Is a business continuity plan maintained? | ||
| 171 | Is disaster recovery documented? | ||
| 172 | Are critical services identified? | ||
| 173 | Are recovery objectives defined? | ||
| 174 | Are continuity plans tested periodically? | ||
| 175 | Are lessons from tests tracked to improvement? |
31. Information Transfer
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 176 | Are secure methods used to transfer sensitive information? | ||
| 177 | Is unauthorized data transfer restricted? | ||
| 178 | Are file-sharing mechanisms controlled? | ||
| 179 | Are data-transfer activities monitored where appropriate? |
32. Subcontractors and Subprocessors
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 180 | Do you use subcontractors or subprocessors? | ||
| 181 | Provide a list of relevant subprocessors. | ||
| 182 | Are subprocessors subject to security requirements? | ||
| 183 | Are subprocessors subject to privacy requirements? | ||
| 184 | Are changes to subprocessors communicated? | ||
| 185 | Are subprocessors periodically reviewed? |
33. Data Location
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 186 | Identify countries where data is stored. | ||
| 187 | Identify countries where data is processed. | ||
| 188 | Identify countries from which support personnel can access data. | ||
| 189 | Are international data transfers involved? | ||
| 190 | Are applicable transfer requirements addressed? |
34. Physical Data Handling
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 191 | Is physical media containing sensitive data controlled? | ||
| 192 | Is physical media securely disposed of? | ||
| 193 | Are printed confidential records controlled? | ||
| 194 | Are physical assets securely transported where applicable? |
35. AI and Generative AI
Complete this section where AI/ML or generative AI is used.
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 195 | Does the service use AI/ML? | ||
| 196 | Is customer data provided to an AI model? | ||
| 197 | Is customer data used for model training? | ||
| 198 | Are AI subprocessors used? | ||
| 199 | Is AI data retention defined? | ||
| 200 | Are AI-related security/privacy risks assessed? | ||
| 201 | Are customer restrictions on AI use supported? |
36. Regulatory and Legal Requirements
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 202 | Identify regulations relevant to the service. | ||
| 203 | Are regulatory requirements formally tracked? | ||
| 204 | Have you experienced material regulatory actions relevant to this service? | ||
| 205 | Are legal requirements incorporated into security/privacy processes? | ||
| 206 | Are regulatory or legal changes monitored? |
37. Contractual Security Requirements
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 207 | Can security requirements be incorporated into the contract? | ||
| 208 | Can privacy requirements be incorporated into a DPA where applicable? | ||
| 209 | Are incident-notification obligations contractually defined? | ||
| 210 | Are data-return/deletion requirements contractually defined? | ||
| 211 | Are subcontractor requirements contractually addressed? | ||
| 212 | Are audit/assurance rights addressed? | ||
| 213 | Are security responsibilities clearly allocated? |
38. Security Testing and Assurance
| # | Question | Response | Evidence / Comments |
|---|---|---|---|
| 214 | Is vulnerability scanning performed regularly? | ||
| 215 | Is penetration testing performed? | ||
| 216 | Is application security testing performed? | ||
| 217 | Are remediation actions tracked? | ||
| 218 | Can appropriate testing evidence be provided? | ||
| 219 | Are security findings reported to management? |
39. Security Incidents and History
Provide information about material security incidents relevant to the service.
| Question | Response |
|---|---|
| Have you experienced a material security incident in the relevant review period? | |
| Have you experienced a material personal-data breach? | |
| Were customers affected? | |
| Were regulators notified where required? | |
| Were corrective actions completed? | |
| Are there unresolved material security findings? |
Where disclosure is legally or contractually restricted, provide an appropriate summary.
40. Supplier Security Evidence
Identify evidence available for review.
| Evidence | Available? | Date | Notes |
|---|---|---|---|
| ISO 27001 Certificate | |||
| SOC 2 Report | |||
| Penetration-Test Summary | |||
| Security Policy | |||
| BCP/DR Evidence | |||
| Incident Response Policy | |||
| Privacy Policy | |||
| DPA | |||
| Subprocessor List | |||
| Security Architecture | |||
| Vulnerability Assessment | |||
| Other |
41. Supplier Declaration
The supplier confirms that the information provided in this questionnaire is accurate to the best of its knowledge and that material changes affecting the security or privacy of the service will be communicated in accordance with the applicable agreement.
| Field | Details |
|---|---|
| Supplier Name | |
| Authorized Representative | |
| Title | |
| Signature / Electronic Approval | |
| Date |
42. Internal Review
The organization should review the completed questionnaire rather than simply filing the supplier’s responses.
| Review Area | Result | Comments |
|---|---|---|
| Service Risk | ||
| Information Risk | ||
| Access Risk | ||
| Privacy Risk | ||
| Security Controls | ||
| Subprocessor Risk | ||
| Data Location | ||
| Business Continuity | ||
| Security Assurance | ||
| Contractual Requirements | ||
| Overall Supplier Risk |
43. Findings and Exceptions
Document areas requiring clarification, remediation, or additional controls.
| Finding ID | Question | Finding | Risk | Required Action | Owner | Due Date |
|---|---|---|---|---|---|---|
| SDQ-001 | ||||||
| SDQ-002 |
44. Supplier Risk Assessment
The questionnaire is an input to the supplier risk assessment, not a substitute for it.
The organization should consider:
Threat + Vulnerability + Likelihood + Impact + Existing Controls = Supplier Risk
The final assessment should consider:
- Information handled
- Access provided
- Business dependency
- Supplier criticality
- Security controls
- Privacy implications
- Subprocessors
- Data location
- Security assurance
- Business continuity
- Contractual protections
- Identified findings
45. Risk Treatment
For significant findings, document the required action.
| Risk ID | Risk | Treatment | Action | Owner | Due Date | Status |
|---|---|---|---|---|---|---|
| SR-001 | Mitigate / Accept / Avoid / Transfer | |||||
| SR-002 |
Risk acceptance should be approved by the appropriate risk owner.
46. Supplier Approval
Based on the questionnaire and risk assessment:
- ☐ Approved
- ☐ Approved with Conditions
- ☐ Remediation Required
- ☐ Risk Acceptance Required
- ☐ Additional Evidence Required
- ☐ Not Approved
Approval Rationale
Document why the supplier is approved or what conditions must be satisfied before approval.
47. Periodic Review
The questionnaire should be reviewed again based on supplier risk and organizational requirements.
Reassessment may be triggered by:
- Material service changes
- New personal-data processing
- New subprocessors
- Security incidents
- Data breaches
- New production access
- New privileged access
- Data-location changes
- Ownership changes
- Major vulnerabilities
- Contract renewal
- Significant regulatory changes
- Supplier performance concerns
48. Risk-Based Questionnaire Model
A startup should avoid sending the same questionnaire to every supplier.
Low-Risk Supplier
Ask primarily about:
- Supplier identity
- Service
- Information handled
- Basic security
- Incident management
- Contract
- Data handling
- Termination
Medium-Risk Supplier
Add:
- IAM
- MFA
- Encryption
- Vulnerability management
- Backup
- BCP/DR
- Privacy
- Subprocessors
- Data location
- Security assurance
High/Critical Supplier
Add:
- Privileged access
- Production access
- Cloud security
- Application security
- Security testing
- Detailed incident management
- Privacy assessment
- International transfers
- Subprocessor management
- Independent assurance
- BCP/DR testing
- Exit/migration capability
- Enhanced monitoring
49. AWS SaaS Startup Example
Consider a startup using a third-party SaaS provider for customer support.
Supplier
Customer-support SaaS platform
Information
- Customer names
- Email addresses
- Support tickets
- Customer communications
Key Questionnaire Areas
The startup should focus on:
- Data processing
- Access control
- MFA
- Encryption
- Data location
- Subprocessors
- DPA
- Security incidents
- Data retention
- Data deletion
- SOC 2/ISO 27001 assurance
- Backup and availability
If the supplier also receives production credentials or privileged AWS access, the risk profile changes significantly and additional technical-security questions should be completed.
50. Common Mistakes
1. Sending the full questionnaire to every supplier
A low-risk office supplier may not need the same assessment as a cloud provider handling customer data.
2. Treating the questionnaire as the risk assessment
The questionnaire collects information. The organization must still analyze the answers and determine supplier risk.
3. Accepting “Yes” without evidence
Important controls should be supported by appropriate evidence where risk warrants it.
4. Focusing only on certifications
A supplier can hold ISO 27001 or SOC 2 and still introduce risks specific to the organization’s service.
5. Ignoring subprocessors
Fourth-party dependencies can materially affect supplier risk.
6. Ignoring data location
Where information is processed and accessed can affect contractual, privacy, and regulatory requirements.
7. Ignoring supplier access
A supplier with privileged production access presents a different risk from a supplier that receives only public information.
8. Not tracking findings
Identified gaps should result in documented treatment, acceptance, or another appropriate decision.
9. Never reassessing the supplier
Supplier risk can change as services, access, technology, ownership, and business dependency change.
51. Relationship With Other Supplier Documents
| Document | Purpose |
|---|---|
| Supplier Register | All suppliers |
| Critical Supplier Register | Critical suppliers |
| Third-Party Due Diligence Checklist | Initial supplier evaluation |
| Supplier Due Diligence Questionnaire | Supplier-provided information |
| Supplier Risk Assessment | Formal risk evaluation |
| Supplier Security Requirements | Required security controls |
| Supplier Contract Security Checklist | Contract security review |
| DPA Checklist | Privacy/data-processing review |
| Supplier Onboarding Checklist | Secure onboarding |
| Supplier Security Review | Periodic review |
| Supplier Access Review | Supplier access verification |
| Supplier Offboarding Checklist | Secure termination |
The questionnaire therefore sits within a broader supplier lifecycle rather than operating as a standalone document.
52. ISO 27001 Connection
The questionnaire supports the organization’s supplier-management and information-security risk processes, including areas relating to:
- Supplier relationships
- Security requirements in supplier agreements
- ICT supply-chain security
- Access control
- Information transfer
- Incident management
- Business continuity
- Protection of information
- Risk assessment and treatment
- Supplier monitoring and review
The questionnaire itself is not a universally mandatory ISO 27001 form. The organization should determine which questions are applicable based on its risk assessment, supplier criticality, information handled, access provided, contractual requirements, and applicable legal/regulatory obligations.
53. Quick Audit Checklist
An auditor should be able to verify:
- ☐ Supplier identified
- ☐ Service identified
- ☐ Business dependency assessed
- ☐ Information handled identified
- ☐ Personal data considered
- ☐ Access requirements identified
- ☐ Supplier security governance assessed
- ☐ Security certifications/assurance reviewed
- ☐ IAM assessed
- ☐ MFA assessed
- ☐ Privileged access assessed
- ☐ Vulnerability management assessed
- ☐ Logging/monitoring assessed
- ☐ Incident management assessed
- ☐ Data breach process assessed
- ☐ Encryption assessed
- ☐ Backup/DR assessed
- ☐ Privacy assessed
- ☐ Subprocessors identified
- ☐ Data locations identified
- ☐ AI use considered where applicable
- ☐ Security evidence reviewed
- ☐ Findings documented
- ☐ Risk assessment completed
- ☐ Risk treatment documented
- ☐ Approval recorded
- ☐ Periodic review defined
54. Final Audit Trail
The completed questionnaire should support a traceable supplier-management chain:
Supplier → Service → Information → Access → Criticality → Questionnaire → Evidence → Findings → Supplier Risk Assessment → Risk Treatment → Contract/DPA → Approval → Onboarding → Monitoring → Periodic Review → Reassessment → Offboarding
Final Principle
A supplier due diligence questionnaire should not become a checkbox exercise. Its purpose is to obtain enough reliable information to understand the supplier’s security, privacy, operational, and business risks and to make an evidence-based supplier-management decision.
The depth of the questionnaire should always be proportionate to the supplier’s risk, criticality, information handled, access, and business dependency.
