Skip to main content
Category: Breach and Risk Assessment

Vendor Risk Assessment Questionnaire

Also known as: VRAQ, Vendor Assessment Questionnaire, Vendor Risk Assessment (VRA) Questionnaire, Third-Party Risk Assessment Questionnaire
Simply put

A vendor risk assessment questionnaire is a standardized set of questions that an organization sends to a third-party vendor to understand the risks of working with them. It generally covers areas such as the vendor's security practices, data handling, and compliance controls. It is a tool for gathering information and does not by itself guarantee that a vendor is safe or compliant.

Formal definition

A Vendor Risk Assessment Questionnaire (VRAQ) is a structured, standardized instrument used within third-party risk management to evaluate a vendor's security posture, active risk management strategies, safeguards, controls, and compliance-related practices. It typically supports an organization's due-diligence process by eliciting evidence about how a vendor manages risks associated with the products or services it provides, including its handling of data entrusted to it. The questionnaire is one input into a broader vendor risk assessment; its outputs must be validated against supporting evidence rather than treated as self-attested assurance, and a completed questionnaire alone does not establish that a vendor meets any specific legal, contractual, or regulatory obligation. This entry describes the instrument itself and does not cover the mechanics of scoring methodologies, contractual remediation, cross-border transfer arrangements, retention rules, or the allocation of controller and processor obligations, which depend on the applicable jurisdiction, framework, and implementation context.

Why it matters

Organizations increasingly rely on third-party vendors to process, store, or transmit data on their behalf, and the risks those vendors carry can become the organization's own risks. A Vendor Risk Assessment Questionnaire is a primary due-diligence instrument for surfacing how a vendor manages security, data handling, and compliance-related controls before and during a relationship. Where a vendor acts as a data processor, the accountability for selecting and overseeing that vendor generally remains with the data controller in most jurisdictions, so the questionnaire supports the controller's ability to demonstrate that it exercised diligence rather than relying on unexamined trust.

A critical limitation is that a completed questionnaire captures self-attested assurances. Responses represent what a vendor states about its practices, not verified evidence that those practices are implemented or effective. Treating a filled-in questionnaire as proof of compliance is a common and consequential error: under accountability-oriented governance frameworks, demonstrable evidence is required, not merely stated intent. A questionnaire response should therefore be validated against supporting artifacts such as attestations, audit reports, or independent certifications where the risk warrants it.

The questionnaire is also only one input into a broader vendor risk assessment. It does not by itself establish that a vendor meets any particular legal, contractual, or regulatory obligation, nor does it resolve who bears which obligation. Determinations about controller and processor responsibilities, cross-border transfer mechanisms, retention, and contractual remediation depend on the applicable jurisdiction, framework, and implementation context and fall outside what the instrument alone can answer.

Who it's relevant to

Third-Party Risk and Vendor Management Teams
These teams design, distribute, and evaluate questionnaires as part of vendor due diligence. They are best positioned to treat responses as one input among several and to escalate items that require independent validation rather than accepting self-attestation as assurance.
Data Protection Officers and Privacy Leads
Where a vendor processes personal data, the questionnaire helps assess how the vendor handles data entrusted to it. In most jurisdictions the controller retains accountability for vendor selection and oversight, so DPOs use questionnaire outputs to support demonstrable diligence, while recognizing that the instrument does not resolve controller and processor obligations on its own.
Information Security Teams
Security teams interpret responses about a vendor's security posture, safeguards, and controls. They typically confirm whether stated controls are backed by verifiable evidence, since a questionnaire captures claimed rather than validated implementation.
Compliance and Governance Leads
These roles rely on questionnaire evidence to support accountability, which requires demonstrable proof rather than stated intent. They recognize that a completed questionnaire alone does not establish that a vendor meets any specific legal, contractual, or regulatory obligation.
Procurement and Vendor Onboarding Functions
Procurement teams often initiate the questionnaire during onboarding and coordinate its completion. They benefit from understanding that the questionnaire supports a decision rather than guaranteeing that a vendor is safe or compliant, and that further review may be needed before a relationship proceeds.

Inside VRAQ

Organizational and Security Governance
Questions covering the vendor's information security program, governance structure, assigned responsibilities, and relevant certifications or attestations (for example, ISO/IEC 27001, ISO/IEC 27701, or SOC 2 reports). This helps assess whether the vendor has demonstrable, evidenced controls rather than stated intent alone.
Data Processing Role and Scope
Elements that establish whether the vendor acts as a data processor, a sub-processor, or in some contexts an independent or joint controller, and what categories of data are involved. Clarifying the role matters because obligations differ: under regimes such as the EU GDPR and UK GDPR, controllers and processors carry distinct responsibilities.
Categories of Data Handled
Identification of whether the engagement involves personal data and, specifically, special category or sensitive data, which typically attracts heightened requirements. This section should distinguish ordinary personal data from special category data rather than treating all data uniformly.
Technical and Organizational Measures
Detail on controls such as access management, encryption, and pseudonymization. Note that these measures reduce risk but do not, by themselves, remove data from scope; encrypted, tokenized, or pseudonymized data generally remains personal data where re-identification is possible.
Sub-processor and Supply Chain Management
Questions on the vendor's use of sub-processors, how they are authorized and disclosed, and how flow-down obligations are imposed. This addresses the extended risk surface beyond the immediate vendor relationship.
Cross-Border Data Transfer Handling
Where applicable, information on the locations of processing and storage and the transfer arrangements relied upon. The questionnaire typically flags whether transfers occur; the detailed mechanics of a specific transfer mechanism are generally addressed in contractual instruments rather than in the questionnaire itself.
Incident Response and Breach Notification
Elements covering the vendor's ability to detect, respond to, and notify the customer of security incidents or personal data breaches within agreed timeframes, supporting the customer's own obligations.
Evidence and Documentation
Requests for supporting artifacts such as policies, audit reports, or certifications. Under accountability-oriented frameworks, demonstrable evidence is expected rather than mere assertions of compliance.

Common questions

Answers to the questions practitioners most commonly ask about VRAQ.

Does a completed vendor risk assessment questionnaire mean the vendor is compliant?
No. A completed questionnaire captures a vendor's self-attested representations at a point in time; it is not a determination of compliance and does not, by itself, discharge your accountability obligations. Under most governance frameworks, accountability requires demonstrable evidence, not stated intent, so questionnaire responses generally need to be corroborated with supporting artifacts such as certifications, audit reports, or contractual commitments. Whether a vendor's practices actually meet a given legal or standards requirement depends on the applicable regime, the context of the processing, and how controls are implemented and maintained over time.
Does using a vendor risk questionnaire replace the need for a data processing agreement or contractual controls?
No. A questionnaire is an assessment and due-diligence instrument, while a data processing agreement or comparable contractual arrangement establishes the enforceable obligations between the parties. They serve different functions and are generally used together. Where a controller engages a processor, applicable law in several regimes typically requires the relationship to be governed by a written contract or other binding instrument; a questionnaire informs that arrangement but does not substitute for it. This entry does not cover the specific clauses required in any given jurisdiction.
When in the vendor lifecycle should the questionnaire be issued?
A questionnaire is typically issued during onboarding or pre-contract due diligence, before data is shared or processing begins, so that identified risks can inform the sourcing decision and contractual terms. Many organizations also reissue or refresh questionnaires periodically or upon triggering events, such as a material change in the service, a change in the categories of data processed, a change in sub-processors, or after a reported incident. The appropriate cadence generally depends on the risk tier assigned to the vendor and your internal governance policy.
How should questionnaire content be tailored to the vendor's risk level?
Questionnaire depth is generally scaled to the sensitivity and volume of data involved and the vendor's role in the processing. A vendor that processes special category or sensitive data, or one acting as a processor with broad access, typically warrants a more detailed set of questions and stronger evidentiary follow-up than a low-risk supplier with no access to personal data. Tiering the questionnaire helps focus assessment effort proportionately, but the criteria for each tier should be documented so the approach is defensible and consistently applied.
What evidence should accompany questionnaire responses?
Because accountability generally requires demonstrable evidence rather than self-attestation alone, responses are typically supported by artifacts such as independent audit reports, recognized certifications, penetration test summaries, policy extracts, or subprocessor lists. The reviewer should assess whether the evidence is current, in scope for the service being procured, and issued by a credible party. This entry does not prescribe which specific certifications are required, as that depends on the applicable framework, sector, and risk profile.
Who should own the questionnaire process and act on its findings?
Ownership is generally shared across functions: procurement or vendor management typically coordinates the process, while privacy, security, and legal stakeholders assess responses within their respective domains, reflecting the distinction between governance concerns such as data ownership and stewardship and security concerns such as confidentiality, integrity, and availability. Findings should be routed to defined risk owners with a documented remediation or acceptance decision, so the outcome is traceable. Assigning clear accountability and retaining records of decisions supports a defensible governance posture.

Common misconceptions

A completed vendor risk assessment questionnaire proves the vendor is compliant.
A questionnaire captures self-reported and, where supported, evidenced information at a point in time. It supports a risk assessment but does not by itself guarantee compliance, which depends on context, jurisdiction, implementation, and ongoing verification. Responses should be corroborated with independent evidence where feasible.
If a vendor confirms it encrypts, tokenizes, or pseudonymizes data, that data is no longer personal and the assessment can be relaxed.
Encryption, tokenization, and pseudonymization are risk-reducing technical measures, but pseudonymized and similarly protected data generally remains personal data where re-identification is possible. Only irreversible anonymization typically removes data from the scope of most data protection regimes, and that determination requires careful analysis.
The questionnaire replaces the data processing agreement and other contractual controls.
A questionnaire informs due diligence; it does not establish the binding obligations that contracts do. Matters such as processing instructions, sub-processor authorization, transfer mechanisms, and liability are generally allocated through contractual instruments rather than the questionnaire itself.

Best practices

Tailor the questionnaire to the vendor's actual role (processor, sub-processor, or controller) and the data categories involved, applying deeper scrutiny where special category or sensitive data is in scope.
Request corroborating evidence such as certifications, audit reports, or policy documents rather than accepting stated intent, consistent with accountability expectations under governance frameworks.
Explicitly address sub-processors and supply chain arrangements, including how flow-down obligations and disclosure of new sub-processors are handled.
Flag where cross-border transfers occur and confirm the corresponding contractual transfer arrangements separately, since the questionnaire generally scopes rather than fully governs transfer mechanics.
Treat the questionnaire as one input to an ongoing, risk-based process, refreshing it periodically and upon material changes rather than as a one-time exercise.
Do not treat technical measures like encryption or pseudonymization as removing data from scope; assess residual re-identification and access risks accordingly.