There is no single TPRM questionnaire that works for every supplier. A low-risk vendor may need a short review, while a critical cloud provider, payment service provider, university technology vendor, or ICT provider may need deeper evidence and contractual validation.
This guide brings together 15 questionnaire topics that appear frequently in manual third-party risk assessments. Each LearnTPRM resource includes an Excel workbook with risk triage, questions, evidence tracking, findings, and decision support.
How to choose a TPRM questionnaire
Start with the vendor relationship, not the questionnaire name. Record the service, data, access, criticality, geography, subcontractors, business dependency, regulatory scope, and recovery requirements. Then choose the smallest review that gives the decision owner enough evidence to approve, restrict, remediate, accept, or reject the relationship.
15 questionnaire resources
| Questionnaire | Best use |
|---|---|
| Vendor security questionnaire | General vendor security reviews |
| Vendor risk assessment questionnaire | Onboarding, renewal, and material change |
| Third-party risk assessment questionnaire | Broad enterprise and regulated TPRM |
| TPRM questionnaire | Lifecycle-based vendor review |
| Vendor due diligence questionnaire | Pre-contract selection and approval |
| Supplier security questionnaire | Supplier and supply chain risk |
| SIG questionnaire | Broad standardized-style enterprise review |
| SIG Lite questionnaire | Lower-risk scaled reviews |
| SIG Core questionnaire | Critical and higher-risk reviews |
| CAIQ questionnaire | Cloud, SaaS, IaaS, and PaaS |
| CAIQ-Lite questionnaire | Faster lower-risk cloud review |
| HECVAT questionnaire | Higher education and EdTech |
| VSA questionnaire | Technology security and privacy reviews |
| PCI DSS SAQ D for service providers | Eligible payment service providers |
| DORA ICT third-party risk assessment | EU financial entities and ICT providers |
General-purpose questionnaires
Vendor security, vendor risk, third-party risk, TPRM, due diligence, and supplier security questionnaires are often buyer-created. They are useful when the organization needs to combine security, privacy, operational, financial, legal, resilience, and fourth-party questions in one review.
These forms should be tiered. Do not send a critical vendor assessment to every supplier, and do not use a short checklist when the supplier has privileged access or supports an important service.
Standardized and sector-specific questionnaires
SIG and CAIQ are common standardized references for enterprise and cloud assessments. HECVAT is designed for higher education. VSA is associated with technology-company vendor reviews. PCI DSS SAQ D applies to eligible service providers in the payment ecosystem. DORA creates ICT third-party risk obligations for EU financial entities, but firms generally need a DORA-aligned assessment tailored to their service and contract.
Use official forms when a customer, regulator, or program specifically requires them. The LearnTPRM workbooks are original or aligned preparation tools and should not be represented as official versions.
What every manual workbook should include
- Vendor and service profile
- Inherent risk triage
- Risk-based questionnaire
- Evidence register
- Reviewer notes and applicability decisions
- Findings and remediation tracker
- Executive summary
- Framework or regulatory crosswalk
Download the master library
Download the free LearnTPRM TPRM Questionnaire Library Excel workbook.
The master workbook compares all 15 topics and includes a routing guide and core evidence pack. Use the individual workbook linked on each topic page when you are ready to run a specific assessment.