Supplier security questionnaires without the spreadsheet
Most supplier assurance programmes die in an inbox. The questionnaire goes out as an attachment, comes back three weeks later half-answered, and nobody can tell whether the answers were true on the day they were written.
Written by Apexward Assure editorial team
Reviewed by Apexward Assure product team
Last reviewed: 30 August 2026
What actually goes wrong with the spreadsheet
The spreadsheet is not a bad format because spreadsheets are bad. It fails because the round-trip has five separate failure points, and a programme of thirty suppliers hits all of them every cycle.
Version drift. You send v3 of the questionnaire. Your colleague sends v2 to a different supplier because that is the copy on their desktop. Six months later you have two sets of answers to two different sets of questions, and no way to compare a supplier against its own previous position, let alone against its peers.
No evidence attached. A cell containing “Yes” is not evidence. It is a claim, made by someone who may not have checked, in a document nobody signed. When your assessor asks how you assured a critical supplier, a column of Yes values is the weakest possible answer.
Chased by email. The status of the assessment lives in your sent items. You find out that a supplier has not responded when you go looking, which is usually the week the contract is up for renewal.
Answered by whoever opened it. The questionnaire lands with an account manager who forwards it to whoever seems technical. Questions about backup retention get answered by someone guessing, because the alternative is admitting they do not know.
Stale on arrival. A returned questionnaire describes the supplier as it was on the day it was filled in, minus the three weeks it sat in a queue. Nothing in the file tells you when it stops being true, and nothing prompts you to ask again.
Segment by the risk the supplier actually carries
The single biggest improvement most programmes can make is to stop sending everyone the same two hundred questions. It produces worse data, not better: the low-risk suppliers do not bother finishing, and the critical ones give you the same generic answers as the stationery firm.
Segment on what the supplier can actually do to you. Three tiers is usually enough:
- Critical. Holds your customer data or personal data, has privileged or persistent access to your systems, or is a single point of failure for a service you sell. A managed IT provider, your hosting platform, your payroll bureau.
- Standard. Processes some data or has limited access, but you could survive a bad week from them. Most SaaS tools, subcontractors on non-sensitive work.
- Low. No access to systems or data, and replaceable. Office supplies, facilities, most professional services.
Write down the criteria before you tier anyone, and record why each supplier landed where it did. That one sentence per supplier is the part an assessor asks about, because it shows the segmentation was a decision rather than a convenience.
What a proportionate question set looks like
For a low-risk supplier, five to ten questions is defensible: who they are, what they do for you, whether they hold any of your data, whether they hold a recognised certification, and a named security contact. If the honest answer to “do they touch our data or systems?” is no, you are recording a decision, not conducting an assessment.
For a critical supplier, thirty to fifty questions covering the things that would actually hurt you: certification status and scope, multi-factor authentication on administrative access, patching timescales, joiners and leavers, backup and tested restore, incident notification commitments and timescales, sub-processors and data location, and whether they in turn assess their own suppliers. Ask about their scope explicitly. A supplier certified to ISO 27001 for one business unit that is not the one serving you is a common and easily missed answer.
Cut anything you would not act on. If a No would not change the contract, the tier, or your risk register, the question is decoration.
Ask for evidence, not assertions
Every question in a critical set should either request an artefact or be a simple factual claim you can verify elsewhere. A certificate number you can look up. A copy of the policy. A screenshot of the multi-factor authentication policy. A summary page from their most recent penetration test. The IASME registry is public, so a Cyber Essentials claim is checkable in under a minute.
Evidence changes the conversation on the supplier’s side too. It is easy to tick Yes on a claim nobody will inspect. It is harder, and more useful, to be asked for the document.
Cadence, and what to do when they will not answer
Annual re-assessment for critical suppliers, every two years for standard, and low-risk suppliers reviewed only when something changes: the contract renews, the service changes, or they have an incident. Set the next date when you close the current assessment. Trigger an off-cycle assessment on events rather than dates, because a supplier breach or an acquisition tells you more than a calendar does.
Some suppliers will not respond, and you need a position for that rather than an indefinite chase. Escalate once through the commercial relationship, since the account manager who wants the renewal is more motivated than the person who received your email. If that fails, accept a substitute: their own Trust Centre page, a certificate, or a completed questionnaire they have already produced for someone else. Most of what you asked for will be in it.
If nothing arrives, record the non-response as a risk with an owner and a decision. Continuing to use an unassessed critical supplier is a legitimate business choice, as long as it is a documented one. An assessor is far more comfortable with “we could not get answers, so we accepted the risk at director level and put a contract clause in at renewal” than with an assessment that quietly never finished.
The barrier is the account
If you move off spreadsheets, do not move to a portal that makes suppliers create accounts. Completion rates fall at the sign-up screen, not at the questions. The person you need is already doing you a favour by answering, and asking them to set a password, verify an email and remember a login is enough friction to push the task to next week permanently.
Login-free links solve this. The supplier clicks, answers, attaches the evidence and is done. You get a timestamped record, the version of the questionnaire they actually saw, and the files attached to the answers they support.
Where Apexward Assure fits
The organisation module keeps suppliers, their tier, their assessments and their evidence in one register, and sends questionnaires as login-free links so a supplier never needs an account with you to answer. Re-assessment dates sit on the supplier record rather than in someone’s calendar, and answers stay attached to the evidence that supports them. If you also get sent questionnaires, a Trust Centre answers most of them before they are asked. The platform is free, so trying it costs nothing beyond the hour it takes to load your supplier list.