A vendor security questionnaire (VSQ) is the standardized set of questions an in-house team sends a SaaS or AI vendor to confirm, in writing, what the vendor does with company data, where it lives, who can touch it, and what happens when something breaks. A working one fits on two pages, covers seven areas (data, access, infrastructure, compliance, AI, incident response, sub-processors), and gets answered in ten business days. The copy-pasteable 47-question template is at the bottom of this post.
TL;DR
Part of our in-house counsel guide series.
- A working vendor security questionnaire template is the moment where legal, security, and procurement actually have to agree on what risk the company is buying. Without one that fits on a page, every onboarding becomes a custom debate.
- The two industry standards (SIG from Shared Assessments and CAIQ from the Cloud Security Alliance) cover the universe but bloat past 400 questions in their full forms. Most vendors stall on them. Most in-house teams never finish reading the answers.
- The 47-question template below covers about 80 percent of the real risk with about 20 percent of the friction, structured around seven sections: data classification, access controls, infrastructure, compliance certifications, AI-specific risks, incident response, and sub-processors.
- The full copy-pasteable template is at the bottom of this post. Wire it into the procurement intake form, set a 10-business-day response SLA, and escalate anything that comes back evasive on the AI and sub-processor sections.
How many questions does this template contain?
Why VSQs are the place legal and security actually meet
For most in-house teams, vendor onboarding is the only recurring workflow where legal, security, and procurement have to ship a joint deliverable on a clock. Procurement wants the contract signed. The business sponsor wants the tool deployed.
Security wants attestations. Legal wants the DPA, the BAA if applicable, the indemnification, and the audit-rights language. None of those four conversations resolves until someone produces a written record of what the vendor actually does with company data, where, and under what controls. That record is the VSQ.
The intake path most law departments run, even if no one drew it on a whiteboard, looks like this: business sponsor submits a request, procurement opens a vendor record, legal sends the VSQ and the DPA, security reviews the VSQ answers, legal negotiates the MSA and any BAA, and final sign-off lands when the three internal stakeholders agree the risk is acceptable.
The choke point is almost always the VSQ stage, because every other step depends on the answers. A vendor that takes six weeks to return a 400-question SIG Core has burned the deal timeline before legal ever sees the redlines on the MSA.
The cost of getting this wrong is not theoretical. The Verizon 2024 Data Breach Investigations Report attributed 15 percent of breaches to a third-party vector, up from 9 percent the year prior.
The IBM Cost of a Data Breach Report 2024 put the average breach cost at $4.88 million, with breaches involving a third-party data sharing chain running materially higher. The 2023 MOVEit compromise (Progress Software's managed file transfer product) hit more than 2,700 organizations through a single vendor.
None of those companies got the question wrong; many of them did not ask in the first place, or asked with a 200-question form the vendor's CISO filled out at speed.
A VSQ that fits on two pages, gets answered in ten business days, and gets re-reviewed at renewal is a control. A 400-question form that gets returned half-completed once at onboarding is paperwork.
The industry standards, honestly
Before throwing out the long-form questionnaires, it helps to know what is actually in them and where each one fits.
| Framework | Size | Cost | Best for | Has AI section? |
|---|---|---|---|---|
| SIG Lite (Shared Assessments) | ~150 questions | Licensed | Regulated-data vendors, financial services | No |
| SIG Core (Shared Assessments) | ~825 questions | Licensed | Deep audit-grade evidence | No |
| CAIQ v4 (Cloud Security Alliance) | ~261 questions | Free, public | Cloud-native SaaS, first read | No |
| VSA (Vendor Security Alliance) | ~80 questions | Free | Fast practical screen | Partial |
| HECVAT (higher ed) | Full and Lite tiers | Free | Vendors selling to universities | No |
| This 47-question template | 47 questions | Free, below | In-house teams buying SaaS/AI | Yes, 8 questions |
The thing every framework above shares: none ships a current AI section that asks about training on data, LLM sub-processors, and zero-data-retention agreements. That gap is the reason this template exists.
SIG (Shared Assessments Group). The Standardized Information Gathering Questionnaire is the workhorse of vendor risk assessment in financial services and any regulated industry. The Shared Assessments Program publishes it annually.
SIG Lite runs roughly 150 questions covering the high-risk domains. SIG Core sits closer to 825 questions in the current release, covering the same domains in operational depth. Both are spreadsheet-format, both are licensed to subscribers, and both come with a published mapping to ISO 27001, NIST CSF, HIPAA, and PCI-DSS.
SIG is the right call when the vendor will touch regulated data and the company is itself audited against a framework that expects SIG-grade evidence. It is the wrong call for a Series B SaaS tool that the marketing team wants to deploy by Friday.
CAIQ (Cloud Security Alliance). The Consensus Assessments Initiative Questionnaire is the cloud-specific complement. CAIQ v4 ships with roughly 261 questions mapped to the Cloud Controls Matrix, which itself maps to ISO 27017, ISO 27018, NIST 800-53, and HIPAA.
CAIQ is free, public, and increasingly the first form a cloud-native vendor will hand back unprompted. If a vendor publishes a CAIQ on the CSA STAR registry, that is a reasonable first read and saves a round trip.
Vanta, Drata, and OneTrust. The trust-platform vendors all ship prebuilt questionnaire libraries. Vanta's Trust Center product lets a vendor publish a SOC 2 Type II report, the CAIQ, and a pre-answered SIG behind an NDA gate. Drata Trust Center and OneTrust's vendor risk management module do the same.
The practical effect for in-house teams is that a competent SaaS vendor in 2026 will hand back a link to a trust center inside an hour. If the vendor cannot, that is signal.
Industry-specific frameworks. HITRUST CSF for healthcare (the CSF v11 maps to HIPAA, HITECH, NIST, ISO, and PCI). PCI-DSS v4.0 for any vendor handling payment card data. FedRAMP Moderate or High for vendors selling to federal customers. IRAP for Australian government. ISMAP for Japan.
These are not interchangeable, and a vendor that has SOC 2 Type II does not have HITRUST, and the reverse.
The position to take in 2026: never start from a blank SIG. Start from the vendor's trust center, layer the 47-question template below for the questions a trust center will not answer (especially the AI and sub-processor sections), and escalate to a full SIG Lite only when the vendor will process regulated data and the trust center evidence is not enough.

A vendor security questionnaire: 47 questions across seven sections.
What the 47 questions are actually doing
The structure trades comprehensive coverage for forced specificity. Each section asks the questions a vendor cannot answer with "yes, we have a policy for that."
Section 1: Data classification (5 questions). Forces the vendor to say, in writing, what categories of data they will hold. The most common failure mode in vendor onboarding is the contract describing the service generically while the actual deployment processes PII, PHI, or trade secrets the legal team did not budget for.
Deletion guarantee on termination is the one question every legal team should hard-code, because it is the answer that determines whether the company is buying a service or buying a permanent training liability.
Section 2: Access controls (7 questions). SSO and SCIM support is not a security question, it is an operations question that becomes a security question at offboarding. A vendor without SCIM means the IT team will, eventually, miss a departing employee.
Personnel background check policy and privileged access management for engineering are the two clauses most vendors hand-wave and most law departments do not push on.
Section 3: Infrastructure (8 questions). Cloud provider, US-only data residency, and tenant isolation are the three answers that determine whether the company can credibly tell a customer or a regulator where the data lives.
RPO and RTO are the answers that determine whether the vendor's incident becomes the company's incident. BAA-compliance infrastructure is the question that determines whether HIPAA is even possible.
Section 4: Compliance certifications (6 questions). SOC 2 Type II is the floor for any vendor processing more than a trivial volume of company data. SOC 2 Type I is a snapshot and does not get the company through a customer audit. ISO 27001 is the international equivalent and matters when the customer base is global.
The question to ask is not "do you have SOC 2," it is "may we see the most recent SOC 2 Type II report under NDA, and what was the auditor's opinion."
Section 5: AI-specific (8 questions). This is the section that did not exist in a 2022 VSQ template and is now the most important section in the whole document.
The five questions to never skip: whether the vendor trains on customer data, which LLM sub-processors are in the call chain, whether the vendor has zero-data-retention agreements with those LLMs, whether PII and PHI are scrubbed before the LLM call, and whether the customer can opt out of AI features entirely.
OpenAI, Anthropic, and Google all publish zero-data-retention terms for their API products. A vendor processing PHI through a generic LLM endpoint without a ZDR agreement is a HIPAA violation waiting for an auditor. The "we do not train on your data" line is the one most worth pressure-testing; our guide on how to verify the no-training claim shows what to ask for beyond the marketing page. For the sub-processor chain itself, where your legal AI data actually goes maps which infrastructure the major vendors route through.
Section 6: Incident response (7 questions). Breach notification SLA is the answer that determines whether the company can meet its own regulatory obligations. The HIPAA Breach Notification Rule requires notice within 60 days of discovery. The GDPR requires 72 hours.
The SEC cybersecurity incident disclosure rule (Item 1.05 of Form 8-K) requires four business days. A vendor offering "notify you within a reasonable time" is offering the company a regulatory violation.
Cyber insurance coverage matters because indemnification language is only as good as the insurance behind it; a vendor with $1M of coverage is not standing behind a $50M data set.
Section 7: Sub-processors (6 questions). The MOVEit story is a sub-processor story. So is the SolarWinds story, and the Kaseya story.
Full published sub-processor list with prior consent on new additions is the standard a 2026 DPA should require, and the VSQ is where the question first surfaces. Sub-processor data residency is the question that catches vendors who claim US-only residency while routing through an offshore support center. For how the strongest legal AI vendors actually word their sub-processor notice and hosting commitments, see our roundup of legal AI vendors with signed DPAs and US/EU hosting.
The answers that pass and the answers that fail
A questionnaire only works if the reviewer knows what a good answer sounds like before the vendor sends one. For the ten questions that carry the most risk, here is the answer that should clear the vendor and the answer that should stop the deal.
| Question | Passing answer | Failing answer |
|---|---|---|
| SOC 2 | "Type II report, audit period ended within the last 12 months, unqualified opinion, available under NDA" | "Type I," "SOC 2 in progress," or a report whose period ended more than 14 months ago |
| Encryption at rest | "AES-256, customer-managed or vendor-managed keys with documented rotation" | "Industry-standard encryption" with no algorithm named |
| Encryption in transit | "TLS 1.2 minimum, TLS 1.3 default" | "We use HTTPS" with no version floor |
| Data residency | "US-only, contractually committed, including all sub-processors" | "Primarily US" or residency that excludes the support and sub-processor layer |
| Data retention | "Deleted within 30 days of termination, production and backup, with written certification" | "Retained per our standard policy" with no deletion commitment |
| Trains on your data | "No, contractually, with the clause cited in the DPA" | "No" only in marketing, or "anonymized data may improve the service" |
| LLM sub-processors | "Named list: OpenAI, Anthropic, etc., each under a zero-data-retention agreement" | "We use leading AI providers" with no names and no ZDR |
| Full sub-processor list | "Published, current, with prior written consent on new additions" | "Available on request," login-gated, or stops at the first layer |
| Breach notification | "72 hours from detection, in hours, contractually" | "Without undue delay" or "within a reasonable time" with no number |
| Breach history | "Disclosed, with the post-incident report and remediation summary" | "We have never had an incident" stated flatly, with no detail and no IR program |
The pattern across the failing column: a noun with no number, a marketing line with no contract, or a control that stops at the first layer. When an answer is vague where the question was specific, the vagueness is the finding.
How to operationalize this
The questionnaire is the document. The control is the workflow around it.
Run the VSQ as part of the procurement intake form, not as a separate process. The business sponsor submits a request; the intake form auto-routes a vendor-facing version of the 47-question template to the vendor's listed security contact within one business day.
Vendors that publish a Vanta or Drata trust center get the questionnaire pre-filled from the trust center, with the in-house team reviewing only the gaps and the AI section.
Set a 10-business-day response SLA in the intake form. Vendors that miss it twice get escalated to the deal sponsor at the vendor. Vendors that miss it three times get a written note in the procurement record, which becomes material at the renewal review.
The signal in a slow response is almost never "we are busy"; it is "we cannot answer the question."
Wire the review to a two-person rule: a named in-house lawyer for the legal review, a named security engineer for the security review. Both sign off in the procurement record before the MSA goes to redlines.
Neither one alone closes the loop. This is the single highest-leverage process change for law departments that currently route VSQ review through a single legal-ops associate.
Re-review at renewal. The vendor's sub-processor list will have changed. The AI features will have shipped. The SOC 2 report will be from a different audit period. A renewal where the VSQ does not get refreshed is a renewal where the company has lost the audit trail.
For documentation, the entire VSQ exchange (questionnaire, answers, sub-processor list, SOC 2 report, DPA, BAA if applicable) belongs in the matter record for that vendor relationship.
When the auditor or the regulator asks where the company assessed risk on a specific sub-processor in 2024, the answer is the matter folder, not an inbox search. A matter-centric record system is the part of vendor management that scales; the same matter workbench that holds the deal documents holds the security evidence.
Red flags worth escalating on the first read
Six patterns show up across vendor responses often enough to be worth memorizing.
The vendor refuses to sign a BAA when the deployment involves PHI. The vendor's sales team will explain that BAAs are reserved for "enterprise tier." HIPAA does not care about pricing tiers. If the vendor will not sign, the vendor cannot process PHI, and the project does not move forward.
The published sub-processor list is missing, hidden behind login, or stops at the first layer. The relevant question is the sub-sub-processor chain, and a vendor that will not disclose past the first layer is one that does not know.
The SOC 2 attestation is Type I only, or the most recent Type II audit period ended more than 14 months ago. Type II audit periods are typically 6 to 12 months; gaps past a year suggest the vendor either failed an audit or stopped paying for one.
"We don't train on customer data" appears in the marketing materials but not in the DPA. The contractual commitment is the only one that matters. The marketing commitment is a press release.
The breach notification SLA is "without undue delay" or "within a reasonable time" with no number. Replace with a number in negotiation: 72 hours mirroring GDPR is a defensible standard. Vendors that refuse to commit to a number are not committing.
The cyber insurance coverage is undisclosed or sits below $5M for any vendor touching more than a trivial volume of company data. The number does not need to be enormous; it needs to exist.
The 47-question template
Copy this block into the procurement intake form. Send to the vendor's security contact at intake. Require written answers (PDF, signed by the vendor's CISO or equivalent, returned within 10 business days). Map each answer to the relevant DPA and MSA clause during negotiation.
VENDOR SECURITY QUESTIONNAIRE
[Company Name] | Effective [Date]
Vendor: __________________ Vendor Security Contact: __________________
Response Due: 10 business days from receipt
SECTION 1: DATA CLASSIFICATION
[ ] 1.1 What categories of [Company] data will you process? (PII, PHI,
payment card, confidential business, trade secrets, source code,
other)
[ ] 1.2 Will you process PHI? If yes, will you execute a BAA?
[ ] 1.3 What data minimization commitments will you make in writing?
[ ] 1.4 What is the retention period for [Company] data during the
engagement, and after termination?
[ ] 1.5 Will you commit, in writing, to permanent deletion of all [Company]
data (production and backup) within 30 days of termination, with
written certification of deletion?
SECTION 2: ACCESS CONTROLS
[ ] 2.1 Do you support SAML 2.0 SSO and SCIM provisioning?
[ ] 2.2 Is MFA enforced for all administrative and customer-facing accounts?
Which factors are supported?
[ ] 2.3 Is RBAC implemented with documented role definitions?
[ ] 2.4 What is your least-privilege provisioning process for engineering
and support personnel?
[ ] 2.5 What is your personnel background check policy at hire? Renewal
cadence?
[ ] 2.6 What is your onboarding/offboarding SLA for personnel access to
systems that touch customer data?
[ ] 2.7 What privileged access management tooling and process governs
engineering access to production?
SECTION 3: INFRASTRUCTURE
[ ] 3.1 Which cloud provider hosts the production environment (AWS, GCP,
Azure, other)?
[ ] 3.2 Is US-only data residency available? Documented?
[ ] 3.3 What encryption-at-rest standard is used? (AES-256 or stronger
expected.) Key management?
[ ] 3.4 What encryption-in-transit standard is used? (TLS 1.2 minimum,
TLS 1.3 expected.)
[ ] 3.5 What tenant isolation model is used? (Single-tenant, multi-tenant
with logical isolation, multi-tenant with row-level isolation.)
[ ] 3.6 Describe your backup and disaster recovery architecture, including
backup encryption and geographic distribution.
[ ] 3.7 What are your contractual RPO and RTO commitments?
[ ] 3.8 If processing PHI: is the infrastructure BAA-eligible end-to-end,
including all sub-processors?
SECTION 4: COMPLIANCE CERTIFICATIONS
[ ] 4.1 SOC 2 Type II: most recent report available under NDA. What was
the auditor's opinion? Any qualifications?
[ ] 4.2 ISO 27001: certified? Most recent certificate?
[ ] 4.3 ISO 27017 and ISO 27018: certified?
[ ] 4.4 HIPAA: self-assessed or HITRUST CSF certified?
[ ] 4.5 PCI-DSS: if applicable, what level, and most recent AoC?
[ ] 4.6 Other (FedRAMP Moderate or High, IRAP, ISMAP, StateRAMP, etc.)?
SECTION 5: AI-SPECIFIC
[ ] 5.1 Do you train AI models on customer data, in any form, at any time?
(Yes/no, in writing, with the contractual clause cited.)
[ ] 5.2 Which third-party LLM providers are in your processing chain
(OpenAI, Anthropic, Google, Cohere, AWS Bedrock, Azure OpenAI,
other)? List all.
[ ] 5.3 Do you have zero-data-retention agreements in place with every
LLM provider listed in 5.2? Provide the contractual reference.
[ ] 5.4 Is PII and PHI scrubbed or tokenized before any LLM API call?
Describe the mechanism.
[ ] 5.5 Are audit logs maintained for every LLM call, with prompt, model,
and response metadata? What is the retention period?
[ ] 5.6 Is AI-related incident response separated from data-breach
incident response, and what triggers each?
[ ] 5.7 What AI bias, accuracy, and hallucination testing is performed
before model or prompt changes ship to production?
[ ] 5.8 Can the customer opt out of AI features entirely while continuing
to use the underlying service?
SECTION 6: INCIDENT RESPONSE
[ ] 6.1 What is the breach notification SLA, in hours, from detection?
(72 hours mirroring GDPR is the standard ask; HIPAA requires 60
days from discovery for notice to affected individuals.)
[ ] 6.2 What is the notification channel? (Email to designated contact,
dashboard, contractual notice address.)
[ ] 6.3 What internal forensic investigation capacity do you maintain?
External IR firm on retainer?
[ ] 6.4 What is the SLA for delivering a post-incident written report?
[ ] 6.5 What cyber insurance coverage do you carry, by policy limit and
carrier?
[ ] 6.6 Who is the named communication chain to the [Company] security
and legal teams during an incident?
[ ] 6.7 What carve-outs to indemnification apply in the event of a data
breach?
SECTION 7: SUB-PROCESSORS
[ ] 7.1 Provide a complete, current sub-processor list, including
purpose of processing and data category for each.
[ ] 7.2 What is the sub-processor approval mechanism: prior written
consent, or notification with right to object?
[ ] 7.3 What sub-sub-processor chain visibility is maintained (i.e., do
you flow these requirements down to your sub-processors)?
[ ] 7.4 What is the notification timeline for adding a new sub-processor
(30 days expected)?
[ ] 7.5 Is sub-processor data residency contractually limited to the
residency commitments made under Section 3?
[ ] 7.6 What compliance attestations (SOC 2, ISO 27001, HIPAA) are
required of each sub-processor, and how is this evidenced?
VENDOR ATTESTATION
The undersigned attests that the responses above are accurate as of the
date below and will notify [Company] within 30 days of any material
change to the responses during the engagement.
Signature: __________________________
Name/Title: _________________________
Date: ______________________________
Calibrate this template to the data risk of the deployment, not to the size of the vendor. A small vendor processing PHI gets the full questionnaire; a large vendor processing only marketing automation telemetry can have Sections 4 and 5 abbreviated. The structure of the seven sections generalizes; the depth of follow-up does not.
Refresh the template annually. The 2026 version of this document has eight AI-specific questions; the 2022 version had zero.
The questions that are now obvious were not asked five years ago, and the questions that are not yet on this template will be obvious in 2028. Treat the VSQ as a living artifact in the legal-ops repo, version it, and circulate the new version with the next vendor onboarding.
FAQ
What is a vendor security questionnaire?
A vendor security questionnaire is a standardized set of questions an organization sends a third-party vendor to confirm, in writing, how the vendor handles company data, access, infrastructure, compliance, AI processing, incidents, and sub-processors. It is the written record that legal and security review before signing, and it becomes part of the audit trail at renewal.
How many questions should a SaaS security questionnaire have?
Enough to cover the real risk without stalling the vendor. The full SIG runs past 800 questions and CAIQ runs about 261, but most in-house teams get roughly 80 percent of the signal from a focused 47-question template across seven sections. Calibrate the depth to the data risk of the deployment, not to the size of the vendor.
What AI questions should be in a vendor security questionnaire?
The five that matter most: whether the vendor trains on customer data (contractually, not in marketing), which LLM sub-processors are in the call chain, whether the vendor holds zero-data-retention agreements with each of those LLMs, whether PII and PHI are scrubbed before any LLM call, and whether the customer can opt out of AI features. A vendor processing PHI through a generic LLM endpoint with no ZDR agreement is a HIPAA exposure.
What is the difference between SIG and CAIQ?
SIG (from Shared Assessments) is the broad vendor-risk questionnaire used in financial services and regulated industries; SIG Lite runs about 150 questions and SIG Core past 800. CAIQ (from the Cloud Security Alliance) is the cloud-specific complement, about 261 questions mapped to the Cloud Controls Matrix, and it is free and public. Use CAIQ for a cloud-native vendor's first read and reserve SIG for regulated-data engagements.
What are the biggest red flags in a vendor's answers?
A SOC 2 Type I instead of a current Type II, a sub-processor list that is hidden or stops at the first layer, "we don't train on your data" in marketing but not the DPA, a breach-notification commitment with no number, and refusal to sign a BAA when the deployment involves PHI. Each of these should be escalated on the first read.
How fast should a vendor return a security questionnaire?
Ten business days is a reasonable SLA for a focused questionnaire. A competent SaaS vendor with a Vanta or Drata trust center can return most of it within the hour. A slow response is rarely "we are busy"; it usually means the vendor cannot answer the question.
What should a breach notification SLA say?
A number, in hours, from detection. 72 hours mirrors the GDPR standard and is defensible; for context, the SEC's Form 8-K Item 1.05 rule gives public companies four business days to disclose a material incident, and the HIPAA Breach Notification Rule allows up to 60 days from discovery for notice to affected individuals. A vendor that will only commit to "without undue delay" is committing to nothing.
Vaquill AI runs the VSQ review against a compliance check and holds the responses, DPAs, and BAAs in a matter-centric record alongside the rest of a vendor relationship, so the audit trail survives the renewal. See /features/matters.
New legal AI guides, weekly.
Further Reading
100 Generative AI Prompts for In-House Lawyers (2026)
Read postAI Governance Policy for In-House Legal Teams: A 2026 Template
Read postDPA Review Field Guide for In-House Counsel
Read postOutside Counsel Guidelines Template: 12 Rules Every GC Should Include in 2026
Read postLegal AI in Microsoft Word: Contract Review, Redlining, and Research in a Word Add-In
Read postLegal AI Word Add-Ins Compared: 14 Tools, Features, and Pricing (2026)
Read post
Co-Founder & CEO · Attorney
Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.