Vendor Risk Assessment Questionnaire
A vendor risk assessment questionnaire is a standardized set of questions that an organization sends to a third-party vendor to understand the risks of working with them. It generally covers areas such as the vendor's security practices, data handling, and compliance controls. It is a tool for gathering information and does not by itself guarantee that a vendor is safe or compliant.
A Vendor Risk Assessment Questionnaire (VRAQ) is a structured, standardized instrument used within third-party risk management to evaluate a vendor's security posture, active risk management strategies, safeguards, controls, and compliance-related practices. It typically supports an organization's due-diligence process by eliciting evidence about how a vendor manages risks associated with the products or services it provides, including its handling of data entrusted to it. The questionnaire is one input into a broader vendor risk assessment; its outputs must be validated against supporting evidence rather than treated as self-attested assurance, and a completed questionnaire alone does not establish that a vendor meets any specific legal, contractual, or regulatory obligation. This entry describes the instrument itself and does not cover the mechanics of scoring methodologies, contractual remediation, cross-border transfer arrangements, retention rules, or the allocation of controller and processor obligations, which depend on the applicable jurisdiction, framework, and implementation context.
Why it matters
Organizations increasingly rely on third-party vendors to process, store, or transmit data on their behalf, and the risks those vendors carry can become the organization's own risks. A Vendor Risk Assessment Questionnaire is a primary due-diligence instrument for surfacing how a vendor manages security, data handling, and compliance-related controls before and during a relationship. Where a vendor acts as a data processor, the accountability for selecting and overseeing that vendor generally remains with the data controller in most jurisdictions, so the questionnaire supports the controller's ability to demonstrate that it exercised diligence rather than relying on unexamined trust.
A critical limitation is that a completed questionnaire captures self-attested assurances. Responses represent what a vendor states about its practices, not verified evidence that those practices are implemented or effective. Treating a filled-in questionnaire as proof of compliance is a common and consequential error: under accountability-oriented governance frameworks, demonstrable evidence is required, not merely stated intent. A questionnaire response should therefore be validated against supporting artifacts such as attestations, audit reports, or independent certifications where the risk warrants it.
The questionnaire is also only one input into a broader vendor risk assessment. It does not by itself establish that a vendor meets any particular legal, contractual, or regulatory obligation, nor does it resolve who bears which obligation. Determinations about controller and processor responsibilities, cross-border transfer mechanisms, retention, and contractual remediation depend on the applicable jurisdiction, framework, and implementation context and fall outside what the instrument alone can answer.
Who it's relevant to
Inside VRAQ
Common questions
Answers to the questions practitioners most commonly ask about VRAQ.