Security Answer Kit

All guides

Vendor and subprocessor questions in a vendor questionnaire

Vendor questions ask which third parties touch client data, how you chose them, and whether you will warn the client before adding a new one. Three questions, all answered by one honest list.

What the client wants to know

Your cloud host, email suite, code hosting and support tools can all see client data. The client wants the list, the location and purpose of each provider, and proof that you looked at their security before adopting them. They also want a heads-up before a new one is added.

The 3 questions as clients phrase them

The kit covers 3 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. Do you use subcontractors or subprocessors that will access our data?
  2. How do you assess the security of your vendors?
  3. Will you notify us before adding a new subprocessor?

What a good answer contains

Watch out for

The list is the answer. If it does not exist yet, name your main providers and give a date for the complete list.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: How do you assess the security of your vendors?

Before adopting a tool that touches client data, we check its security documentation (for example SOC 2 or ISO 27001), data location and MFA support.

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Privacy AI tools

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.