Vendor and subprocessor questions in a vendor questionnaire
Vendor questions ask which third parties touch client data, how you chose them, and whether you will warn the client before adding a new one. Three questions, all answered by one honest list.
What the client wants to know
Your cloud host, email suite, code hosting and support tools can all see client data. The client wants the list, the location and purpose of each provider, and proof that you looked at their security before adopting them. They also want a heads-up before a new one is added.
The 3 questions as clients phrase them
The kit covers 3 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Do you use subcontractors or subprocessors that will access our data?
- How do you assess the security of your vendors?
- Will you notify us before adding a new subprocessor?
What a good answer contains
- A current list of the vendors that store or process client data, with the location and purpose of each. Offer it on request.
- Vendor checks: before adopting a tool that touches client data, you check its security documentation (for example SOC 2 or ISO 27001), data location and MFA support, and review the list yearly.
- Notice: you inform clients before adding a subprocessor that will process their personal data, where a data processing agreement requires it.
- AI tools you approve for client data count as subprocessors and belong on the same list.
Watch out for
The list is the answer. If it does not exist yet, name your main providers and give a date for the complete list.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- Vendors: A current list of vendors (subprocessors) that touch client data is kept. If not yet: List every tool and vendor that stores or processes client data, with its location and purpose.
Example: how a prepared answer opens
Question: How do you assess the security of your vendors?
Before adopting a tool that touches client data, we check its security documentation (for example SOC 2 or ISO 27001), data location and MFA support.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.