ISO/IEC 27001

⌘K
  1. Home
  2. Docs
  3. ISO/IEC 27001
  4. Other Doc
  5. Supplier Due Diligence Questionnaire

Supplier Due Diligence Questionnaire

1. Purpose

The Supplier Due Diligence Questionnaire is used to collect information from suppliers, vendors, contractors, consultants, service providers, cloud providers, SaaS providers, and other third parties before or during a business relationship.

The questionnaire helps the organization understand:

  • Who the supplier is
  • What service it provides
  • What information it handles
  • What systems it accesses
  • What security controls it has
  • What privacy risks exist
  • Whether subprocessors are involved
  • Where data is processed
  • How incidents are managed
  • How business continuity is maintained
  • What security assurance is available
  • What risks require further assessment or treatment

Core Principle

Supplier → Service → Information → Access → Dependency → Security Controls → Evidence → Risk → Approval → Monitoring → Reassessment


2. Instructions to Supplier

Please answer each applicable question using:

  • Yes – Requirement is implemented
  • No – Requirement is not implemented
  • Partially – Requirement is partially implemented
  • N/A – Requirement does not apply

Where appropriate, provide supporting evidence or a short explanation.

Important

Do not provide:

  • Passwords
  • API keys
  • Access tokens
  • Encryption keys
  • Production credentials
  • Other confidential authentication secrets

Evidence should be shared through an approved secure channel.


3. Supplier Information

FieldSupplier Response
Legal Entity Name
Trading Name
Registered Address
Website
Primary Contact
Security Contact
Privacy Contact
Country of Registration
Countries of Operation
Year Established
Number of Employees
Service/Product
Business Owner
Proposed Start Date
Existing SupplierYes / No

4. Supplier Ownership and Organization

#QuestionResponseEvidence / Comments
1Provide a brief description of your organization.
2Identify the legal entity providing the service.
3Identify the parent company, if applicable.
4Identify any material ownership or control changes in the last 12 months.
5Identify the countries where the service is delivered.
6Identify key security/privacy contacts.
7Is information security formally assigned to responsible personnel?

5. Service and Business Scope

#QuestionResponseEvidence / Comments
8Describe the service being provided.
9What business processes does the service support?
10Is the service hosted by your organization or a third party?
11Is the service business-critical?
12What would happen if the service became unavailable?
13Are alternative service arrangements available?
14What is the expected service availability?
15Are service-level commitments documented?

6. Information and Data

#QuestionResponseEvidence / Comments
16What information will you receive from the organization?
17What information will you store?
18What information will you process?
19Will you process customer information?
20Will you process employee information?
21Will you process personal data?
22Will you process confidential information?
23Will you process restricted or highly sensitive information?
24Will you access source code?
25Will you access security-related information?
26Will you process financial or payment information?

7. Data Classification and Handling

#QuestionResponseEvidence / Comments
27Do you have a formal information-classification process?
28Are customer and confidential information handling requirements documented?
29Is access to sensitive information restricted based on business need?
30Are information-handling procedures provided to employees?
31Are secure disposal procedures implemented?
32Are removable media and data exports controlled where appropriate?

8. Information Security Governance

#QuestionResponseEvidence / Comments
33Do you maintain a formal information-security program?
34Is an information-security policy established?
35Is information security assigned to responsible management?
36Do you conduct periodic security risk assessments?
37Do you maintain a security risk register?
38Are security policies reviewed periodically?
39Are security responsibilities formally defined?
40Is security performance reported to management?

9. Security Certifications and Assurance

#QuestionResponseEvidence / Comments
41Do you hold ISO/IEC 27001 certification?
42Do you have a SOC 2 report?
43Do you have other relevant certifications?
44Have you undergone an independent security assessment?
45Do you conduct penetration testing?
46Can appropriate security assurance evidence be provided?
47Are identified audit findings tracked to closure?

Provide certificate/report details where applicable.

Note: A certification or independent report supports due diligence but does not automatically eliminate supplier-specific risks.


10. Risk Management

#QuestionResponseEvidence / Comments
48Is information-security risk formally assessed?
49Are risks assigned to responsible owners?
50Are risk-treatment actions tracked?
51Are residual risks formally reviewed?
52Are security risks reassessed after major changes or incidents?

11. Identity and Access Management

#QuestionResponseEvidence / Comments
53Is user access formally approved?
54Is access based on least privilege?
55Are individual user accounts used?
56Are shared accounts restricted or controlled?
57Is access reviewed periodically?
58Is access removed promptly when no longer required?
59Are administrator accounts separately controlled?
60Are privileged activities logged?

12. Multi-Factor Authentication

#QuestionResponseEvidence / Comments
61Is MFA implemented for administrative access?
62Is MFA implemented for remote access?
63Is MFA implemented for systems containing sensitive information?
64Are MFA exceptions formally controlled?

13. Privileged Access

#QuestionResponseEvidence / Comments
65Is privileged access formally approved?
66Is privileged access limited to authorized personnel?
67Is privileged access periodically reviewed?
68Are privileged activities logged and monitored?
69Is emergency/break-glass access controlled?
70Are unnecessary privileged permissions removed?

14. Personnel Security

#QuestionResponseEvidence / Comments
71Are personnel security responsibilities defined?
72Are appropriate background checks performed where legally permitted and appropriate?
73Are confidentiality obligations established?
74Do employees receive security awareness training?
75Is security training repeated periodically?
76Are disciplinary processes defined for security violations?
77Are access rights removed when personnel leave?

15. Physical Security

#QuestionResponseEvidence / Comments
78Are facilities protected against unauthorized access?
79Is physical access controlled?
80Are visitors controlled?
81Are critical systems hosted in appropriately secured facilities?
82Are environmental risks addressed?
83Is physical security monitored where appropriate?

16. Endpoint Security

#QuestionResponseEvidence / Comments
84Are company-managed endpoints protected?
85Is endpoint security software implemented?
86Are security patches applied within defined timelines?
87Is disk encryption implemented where appropriate?
88Are unauthorized applications restricted?
89Is remote-device security managed?

17. Network Security

#QuestionResponseEvidence / Comments
90Are networks appropriately segmented?
91Are firewalls implemented where appropriate?
92Is network traffic monitored?
93Are insecure network protocols restricted?
94Is remote access securely controlled?
95Are network security rules periodically reviewed?

18. Cloud Security

Complete this section where cloud services are used.

#QuestionResponseEvidence / Comments
96Do you use public cloud infrastructure?
97Identify cloud providers used.
98Is cloud access controlled through IAM?
99Is MFA enabled for privileged cloud access?
100Are cloud configurations periodically reviewed?
101Is cloud activity logged?
102Is sensitive data encrypted in the cloud?
103Are cloud backups implemented?
104Are cloud security incidents monitored?

19. Application Security

#QuestionResponseEvidence / Comments
105Is secure software development practiced?
106Are security requirements considered during development?
107Is code reviewed before release?
108Are dependencies monitored for vulnerabilities?
109Is application security testing performed?
110Are security defects tracked to remediation?
111Are production and development environments appropriately separated?

20. Vulnerability Management

#QuestionResponseEvidence / Comments
112Is vulnerability scanning performed?
113Are critical vulnerabilities prioritized?
114Are remediation timelines defined?
115Is penetration testing performed where appropriate?
116Are vulnerabilities tracked through closure?
117Are exceptions formally documented?

21. Malware Protection

#QuestionResponseEvidence / Comments
118Is malware protection implemented?
119Are malware events monitored?
120Are endpoints regularly updated?
121Are suspicious activities investigated?

22. Logging and Monitoring

#QuestionResponseEvidence / Comments
122Are security-relevant events logged?
123Are privileged activities logged?
124Are logs protected against unauthorized modification?
125Is security monitoring performed?
126Are alerts investigated?
127Is log retention defined?

23. Security Incident Management

#QuestionResponseEvidence / Comments
128Is an incident-response process documented?
129Are security incidents formally recorded?
130Are incident responsibilities defined?
131Are incidents classified based on severity?
132Are incidents investigated and contained?
133Are corrective actions tracked?
134Are lessons learned incorporated into security improvements?

24. Security Incident Notification

#QuestionResponseEvidence / Comments
135Do you have a formal customer incident-notification process?
136Are customers notified within agreed contractual timeframes?
137Does notification include relevant incident information?
138Is evidence preserved during investigations?
139Is post-incident reporting available where appropriate?

25. Personal Data and Privacy

#QuestionResponseEvidence / Comments
140Do you process personal data on behalf of customers?
141Do you maintain a privacy program?
142Are privacy responsibilities assigned?
143Is a DPA available where required?
144Are processing purposes documented?
145Are data-subject rights supported?
146Are privacy incidents managed?
147Are personal-data retention requirements defined?
148Is personal data securely deleted when no longer required?

26. Data Breach Management

#QuestionResponseEvidence / Comments
149Is there a personal-data breach response process?
150Are breaches investigated promptly?
151Are affected customers notified as contractually required?
152Are regulatory notification responsibilities understood?
153Are breach records maintained?

27. Encryption

#QuestionResponseEvidence / Comments
154Is sensitive information encrypted in transit?
155Is sensitive information encrypted at rest?
156Are encryption keys appropriately protected?
157Are cryptographic mechanisms reviewed periodically?
158Are encryption exceptions controlled?

28. Secrets and Credentials

#QuestionResponseEvidence / Comments
159Are passwords securely managed?
160Are API keys securely stored?
161Are secrets stored in an appropriate secrets-management mechanism?
162Are credentials rotated where appropriate?
163Are credentials prohibited from being stored in source code?

29. Backup and Recovery

#QuestionResponseEvidence / Comments
164Are business-critical data backed up?
165Is backup frequency defined?
166Are backups protected from unauthorized access?
167Are backups tested periodically?
168Are restoration procedures documented?
169Are recovery objectives defined where appropriate?

30. Business Continuity and Disaster Recovery

#QuestionResponseEvidence / Comments
170Is a business continuity plan maintained?
171Is disaster recovery documented?
172Are critical services identified?
173Are recovery objectives defined?
174Are continuity plans tested periodically?
175Are lessons from tests tracked to improvement?

31. Information Transfer

#QuestionResponseEvidence / Comments
176Are secure methods used to transfer sensitive information?
177Is unauthorized data transfer restricted?
178Are file-sharing mechanisms controlled?
179Are data-transfer activities monitored where appropriate?

32. Subcontractors and Subprocessors

#QuestionResponseEvidence / Comments
180Do you use subcontractors or subprocessors?
181Provide a list of relevant subprocessors.
182Are subprocessors subject to security requirements?
183Are subprocessors subject to privacy requirements?
184Are changes to subprocessors communicated?
185Are subprocessors periodically reviewed?

33. Data Location

#QuestionResponseEvidence / Comments
186Identify countries where data is stored.
187Identify countries where data is processed.
188Identify countries from which support personnel can access data.
189Are international data transfers involved?
190Are applicable transfer requirements addressed?

34. Physical Data Handling

#QuestionResponseEvidence / Comments
191Is physical media containing sensitive data controlled?
192Is physical media securely disposed of?
193Are printed confidential records controlled?
194Are physical assets securely transported where applicable?

35. AI and Generative AI

Complete this section where AI/ML or generative AI is used.

#QuestionResponseEvidence / Comments
195Does the service use AI/ML?
196Is customer data provided to an AI model?
197Is customer data used for model training?
198Are AI subprocessors used?
199Is AI data retention defined?
200Are AI-related security/privacy risks assessed?
201Are customer restrictions on AI use supported?

36. Regulatory and Legal Requirements

#QuestionResponseEvidence / Comments
202Identify regulations relevant to the service.
203Are regulatory requirements formally tracked?
204Have you experienced material regulatory actions relevant to this service?
205Are legal requirements incorporated into security/privacy processes?
206Are regulatory or legal changes monitored?

37. Contractual Security Requirements

#QuestionResponseEvidence / Comments
207Can security requirements be incorporated into the contract?
208Can privacy requirements be incorporated into a DPA where applicable?
209Are incident-notification obligations contractually defined?
210Are data-return/deletion requirements contractually defined?
211Are subcontractor requirements contractually addressed?
212Are audit/assurance rights addressed?
213Are security responsibilities clearly allocated?

38. Security Testing and Assurance

#QuestionResponseEvidence / Comments
214Is vulnerability scanning performed regularly?
215Is penetration testing performed?
216Is application security testing performed?
217Are remediation actions tracked?
218Can appropriate testing evidence be provided?
219Are security findings reported to management?

39. Security Incidents and History

Provide information about material security incidents relevant to the service.

QuestionResponse
Have you experienced a material security incident in the relevant review period?
Have you experienced a material personal-data breach?
Were customers affected?
Were regulators notified where required?
Were corrective actions completed?
Are there unresolved material security findings?

Where disclosure is legally or contractually restricted, provide an appropriate summary.


40. Supplier Security Evidence

Identify evidence available for review.

EvidenceAvailable?DateNotes
ISO 27001 Certificate
SOC 2 Report
Penetration-Test Summary
Security Policy
BCP/DR Evidence
Incident Response Policy
Privacy Policy
DPA
Subprocessor List
Security Architecture
Vulnerability Assessment
Other

41. Supplier Declaration

The supplier confirms that the information provided in this questionnaire is accurate to the best of its knowledge and that material changes affecting the security or privacy of the service will be communicated in accordance with the applicable agreement.

FieldDetails
Supplier Name
Authorized Representative
Title
Signature / Electronic Approval
Date

42. Internal Review

The organization should review the completed questionnaire rather than simply filing the supplier’s responses.

Review AreaResultComments
Service Risk
Information Risk
Access Risk
Privacy Risk
Security Controls
Subprocessor Risk
Data Location
Business Continuity
Security Assurance
Contractual Requirements
Overall Supplier Risk

43. Findings and Exceptions

Document areas requiring clarification, remediation, or additional controls.

Finding IDQuestionFindingRiskRequired ActionOwnerDue Date
SDQ-001
SDQ-002

44. Supplier Risk Assessment

The questionnaire is an input to the supplier risk assessment, not a substitute for it.

The organization should consider:

Threat + Vulnerability + Likelihood + Impact + Existing Controls = Supplier Risk

The final assessment should consider:

  • Information handled
  • Access provided
  • Business dependency
  • Supplier criticality
  • Security controls
  • Privacy implications
  • Subprocessors
  • Data location
  • Security assurance
  • Business continuity
  • Contractual protections
  • Identified findings

45. Risk Treatment

For significant findings, document the required action.

Risk IDRiskTreatmentActionOwnerDue DateStatus
SR-001Mitigate / Accept / Avoid / Transfer
SR-002

Risk acceptance should be approved by the appropriate risk owner.


46. Supplier Approval

Based on the questionnaire and risk assessment:

  • ☐ Approved
  • ☐ Approved with Conditions
  • ☐ Remediation Required
  • ☐ Risk Acceptance Required
  • ☐ Additional Evidence Required
  • ☐ Not Approved

Approval Rationale

Document why the supplier is approved or what conditions must be satisfied before approval.


47. Periodic Review

The questionnaire should be reviewed again based on supplier risk and organizational requirements.

Reassessment may be triggered by:

  • Material service changes
  • New personal-data processing
  • New subprocessors
  • Security incidents
  • Data breaches
  • New production access
  • New privileged access
  • Data-location changes
  • Ownership changes
  • Major vulnerabilities
  • Contract renewal
  • Significant regulatory changes
  • Supplier performance concerns

48. Risk-Based Questionnaire Model

A startup should avoid sending the same questionnaire to every supplier.

Low-Risk Supplier

Ask primarily about:

  • Supplier identity
  • Service
  • Information handled
  • Basic security
  • Incident management
  • Contract
  • Data handling
  • Termination

Medium-Risk Supplier

Add:

  • IAM
  • MFA
  • Encryption
  • Vulnerability management
  • Backup
  • BCP/DR
  • Privacy
  • Subprocessors
  • Data location
  • Security assurance

High/Critical Supplier

Add:

  • Privileged access
  • Production access
  • Cloud security
  • Application security
  • Security testing
  • Detailed incident management
  • Privacy assessment
  • International transfers
  • Subprocessor management
  • Independent assurance
  • BCP/DR testing
  • Exit/migration capability
  • Enhanced monitoring

49. AWS SaaS Startup Example

Consider a startup using a third-party SaaS provider for customer support.

Supplier

Customer-support SaaS platform

Information

  • Customer names
  • Email addresses
  • Support tickets
  • Customer communications

Key Questionnaire Areas

The startup should focus on:

  • Data processing
  • Access control
  • MFA
  • Encryption
  • Data location
  • Subprocessors
  • DPA
  • Security incidents
  • Data retention
  • Data deletion
  • SOC 2/ISO 27001 assurance
  • Backup and availability

If the supplier also receives production credentials or privileged AWS access, the risk profile changes significantly and additional technical-security questions should be completed.


50. Common Mistakes

1. Sending the full questionnaire to every supplier

A low-risk office supplier may not need the same assessment as a cloud provider handling customer data.

2. Treating the questionnaire as the risk assessment

The questionnaire collects information. The organization must still analyze the answers and determine supplier risk.

3. Accepting “Yes” without evidence

Important controls should be supported by appropriate evidence where risk warrants it.

4. Focusing only on certifications

A supplier can hold ISO 27001 or SOC 2 and still introduce risks specific to the organization’s service.

5. Ignoring subprocessors

Fourth-party dependencies can materially affect supplier risk.

6. Ignoring data location

Where information is processed and accessed can affect contractual, privacy, and regulatory requirements.

7. Ignoring supplier access

A supplier with privileged production access presents a different risk from a supplier that receives only public information.

8. Not tracking findings

Identified gaps should result in documented treatment, acceptance, or another appropriate decision.

9. Never reassessing the supplier

Supplier risk can change as services, access, technology, ownership, and business dependency change.


51. Relationship With Other Supplier Documents

DocumentPurpose
Supplier RegisterAll suppliers
Critical Supplier RegisterCritical suppliers
Third-Party Due Diligence ChecklistInitial supplier evaluation
Supplier Due Diligence QuestionnaireSupplier-provided information
Supplier Risk AssessmentFormal risk evaluation
Supplier Security RequirementsRequired security controls
Supplier Contract Security ChecklistContract security review
DPA ChecklistPrivacy/data-processing review
Supplier Onboarding ChecklistSecure onboarding
Supplier Security ReviewPeriodic review
Supplier Access ReviewSupplier access verification
Supplier Offboarding ChecklistSecure termination

The questionnaire therefore sits within a broader supplier lifecycle rather than operating as a standalone document.


52. ISO 27001 Connection

The questionnaire supports the organization’s supplier-management and information-security risk processes, including areas relating to:

  • Supplier relationships
  • Security requirements in supplier agreements
  • ICT supply-chain security
  • Access control
  • Information transfer
  • Incident management
  • Business continuity
  • Protection of information
  • Risk assessment and treatment
  • Supplier monitoring and review

The questionnaire itself is not a universally mandatory ISO 27001 form. The organization should determine which questions are applicable based on its risk assessment, supplier criticality, information handled, access provided, contractual requirements, and applicable legal/regulatory obligations.


53. Quick Audit Checklist

An auditor should be able to verify:

  • ☐ Supplier identified
  • ☐ Service identified
  • ☐ Business dependency assessed
  • ☐ Information handled identified
  • ☐ Personal data considered
  • ☐ Access requirements identified
  • ☐ Supplier security governance assessed
  • ☐ Security certifications/assurance reviewed
  • ☐ IAM assessed
  • ☐ MFA assessed
  • ☐ Privileged access assessed
  • ☐ Vulnerability management assessed
  • ☐ Logging/monitoring assessed
  • ☐ Incident management assessed
  • ☐ Data breach process assessed
  • ☐ Encryption assessed
  • ☐ Backup/DR assessed
  • ☐ Privacy assessed
  • ☐ Subprocessors identified
  • ☐ Data locations identified
  • ☐ AI use considered where applicable
  • ☐ Security evidence reviewed
  • ☐ Findings documented
  • ☐ Risk assessment completed
  • ☐ Risk treatment documented
  • ☐ Approval recorded
  • ☐ Periodic review defined

54. Final Audit Trail

The completed questionnaire should support a traceable supplier-management chain:

Supplier → Service → Information → Access → Criticality → Questionnaire → Evidence → Findings → Supplier Risk Assessment → Risk Treatment → Contract/DPA → Approval → Onboarding → Monitoring → Periodic Review → Reassessment → Offboarding

Final Principle

A supplier due diligence questionnaire should not become a checkbox exercise. Its purpose is to obtain enough reliable information to understand the supplier’s security, privacy, operational, and business risks and to make an evidence-based supplier-management decision.

The depth of the questionnaire should always be proportionate to the supplier’s risk, criticality, information handled, access, and business dependency.

How can we help?

Leave a Reply

Your email address will not be published. Required fields are marked *