01The questionnaire flood in B2B: causes and costs
Security questionnaires come from two directions: in third-party risk management (TPRM), buyers assess their vendors, while in sales, completed questionnaires are increasingly a prerequisite for closing deals. Regulation is a driver as well – NIS2 (Directive (EU) 2022/2555) requires supply chain security measures in Art. 21(2)(d), including the relationships with direct suppliers, and DORA (Regulation (EU) 2022/2554) obliges financial entities in Art. 28(3) to maintain a register of information on all contractual arrangements with ICT third-party service providers. For the responding side, this creates substantial recurring effort, because the questions overlap heavily in substance but vary in format and wording. Add to that the matter of liability: answers are pre-contractual statements that customers and auditors can later rely on.
02Standard catalogs: CSA CAIQ and Shared Assessments SIG
Two catalogs have established themselves as de facto standards. The Consensus Assessment Initiative Questionnaire (CAIQ) from the Cloud Security Alliance comprises 283 yes/no questions in version 4.1 and is synchronized with the Cloud Controls Matrix (CCM) v4.1, which defines 207 controls across 17 domains (published at the end of January 2026); a shortened CAIQ-Lite variant also exists. The Standardized Information Gathering Questionnaire (SIG) from Shared Assessments covers risk domains ranging from cybersecurity through IT, privacy and data governance to business resilience, is updated annually and, with the 2026 edition, formalizes scoping presets (Lite, Core, Detail) for risk-based question depth – complemented, among other things, by a mapping to ISO/IEC 42001 for AI governance. Alongside these, proprietary Excel questionnaires from individual customers remain widespread, asking about the same subject matter in individual structures.
03Typical content – and what makes answers good
In substance, most questionnaires cover the same topic areas: governance and ISMS evidence (such as an ISO/IEC 27001 certificate or a SOC 2 report), identity and access management, encryption, secure development, vulnerability and patch management, incident response and reporting channels, business continuity, data protection and data processing agreements, and subcontractors – increasingly complemented by questions on the use of AI. What is expected is not just yes/no statements but robust evidence: certificates, audit and pentest reports, policy excerpts. The quality benchmark is consistency – answers must match the actual control environment, the scope of the certificates and the contractual commitments, or they become a risk in an audit or in the event of a claim.
04Automation: answer library and AI with review
The foundation of any automation is a curated answer library: vetted question-answer pairs with versioning, subject-matter ownership, validity periods and source references to the underlying controls and policies. AI-assisted tools build on top of it, recognize semantically similar questions across different phrasings and suggest draft answers from the library and the security documentation. A human review before sending remains mandatory: language models can produce plausible but inaccurate answers, and every answer is an assurance given to the customer. The approach only becomes sustainable with governance – an approval process, an audit trail per answer and regular reconciliation of the library against the actual state of the controls.
05Trust center: the proactive counterpart
A trust center reverses the logic: instead of answering every questionnaire individually, the vendor proactively provides certificates, audit reports, policy overviews, subcontractor lists and completed standard questionnaires such as CAIQ or SIG in a portal – with sensitive documents typically behind an NDA gate. Well-maintained trust centers can fully replace a share of incoming questionnaires and shorten the rest to the points that are actually open. A standardized public counterpart for cloud providers is the STAR Registry of the Cloud Security Alliance: Level 1 is a CAIQ-based self-assessment, Level 2 a third-party assessment as a STAR Attestation (SOC 2) or STAR Certification (ISO/IEC 27001). What matters is currency – an outdated trust center generates more follow-up questions than it avoids.
06Embedding into both sides' vendor risk process
For the requesting side, the questionnaire is just one step in the TPRM lifecycle: the vendor's criticality rating determines the appropriate question depth, followed by evaluation of the answers and evidence, contractual controls and continuous monitoring; NIS2 explicitly requires in Art. 21(3) that the specific vulnerabilities and cybersecurity practices of direct suppliers be taken into account. Accepting standard catalogs such as CAIQ or SIG instead of proprietary Excel templates lowers the effort on both sides without losing informative value. For the responding side, this includes a defined intake process with responsibilities and deadlines as well as feeding the findings back into the own ISMS – recurring gaps in questionnaires are a good indicator of genuine need for action. Requirements for both roles are described in ISO/IEC 27036-2:2022 for managing information security in supplier relationships.