Articles

15 TPRM Questionnaires Used in Vendor Assessments

Blank vendor security questionnaire template on desk in a training room

There is no single TPRM questionnaire that works for every supplier. A low-risk vendor may need a short review, while a critical cloud provider, payment service provider, university technology vendor, or ICT provider may need deeper evidence and contractual validation.

This guide brings together 15 questionnaire topics that appear frequently in manual third-party risk assessments. Each LearnTPRM resource includes an Excel workbook with risk triage, questions, evidence tracking, findings, and decision support.

How to choose a TPRM questionnaire

Start with the vendor relationship, not the questionnaire name. Record the service, data, access, criticality, geography, subcontractors, business dependency, regulatory scope, and recovery requirements. Then choose the smallest review that gives the decision owner enough evidence to approve, restrict, remediate, accept, or reject the relationship.

15 questionnaire resources

Questionnaire Best use
Vendor security questionnaire General vendor security reviews
Vendor risk assessment questionnaire Onboarding, renewal, and material change
Third-party risk assessment questionnaire Broad enterprise and regulated TPRM
TPRM questionnaire Lifecycle-based vendor review
Vendor due diligence questionnaire Pre-contract selection and approval
Supplier security questionnaire Supplier and supply chain risk
SIG questionnaire Broad standardized-style enterprise review
SIG Lite questionnaire Lower-risk scaled reviews
SIG Core questionnaire Critical and higher-risk reviews
CAIQ questionnaire Cloud, SaaS, IaaS, and PaaS
CAIQ-Lite questionnaire Faster lower-risk cloud review
HECVAT questionnaire Higher education and EdTech
VSA questionnaire Technology security and privacy reviews
PCI DSS SAQ D for service providers Eligible payment service providers
DORA ICT third-party risk assessment EU financial entities and ICT providers

General-purpose questionnaires

Vendor security, vendor risk, third-party risk, TPRM, due diligence, and supplier security questionnaires are often buyer-created. They are useful when the organization needs to combine security, privacy, operational, financial, legal, resilience, and fourth-party questions in one review.

These forms should be tiered. Do not send a critical vendor assessment to every supplier, and do not use a short checklist when the supplier has privileged access or supports an important service.

Standardized and sector-specific questionnaires

SIG and CAIQ are common standardized references for enterprise and cloud assessments. HECVAT is designed for higher education. VSA is associated with technology-company vendor reviews. PCI DSS SAQ D applies to eligible service providers in the payment ecosystem. DORA creates ICT third-party risk obligations for EU financial entities, but firms generally need a DORA-aligned assessment tailored to their service and contract.

Use official forms when a customer, regulator, or program specifically requires them. The LearnTPRM workbooks are original or aligned preparation tools and should not be represented as official versions.

What every manual workbook should include

  • Vendor and service profile
  • Inherent risk triage
  • Risk-based questionnaire
  • Evidence register
  • Reviewer notes and applicability decisions
  • Findings and remediation tracker
  • Executive summary
  • Framework or regulatory crosswalk

Download the master library

Download the free LearnTPRM TPRM Questionnaire Library Excel workbook.

The master workbook compares all 15 topics and includes a routing guide and core evidence pack. Use the individual workbook linked on each topic page when you are ready to run a specific assessment.

Sources

Leave a Reply

Discover more from LearnTPRM

Subscribe now to keep reading and get access to the full archive.

Continue reading