Skip to content

Glossary

Security questionnaire

The standard set of questions a buyer sends a vendor before approving a purchase, and frequently the slowest step in adopting anything new.

In plain terms

A list of questions sent to a vendor before they are approved, asking how they run their security, what happens to material you send, and who else is involved. Some are a page and some are hundreds of rows. The vendor answers, somebody reads the answers, and frequently a second round follows because the first answers were not specific enough to record.

01

Why it matters

Because it is where adoption timelines are actually spent, and because most of the delay is structural rather than anybody being slow. Each round costs days of waiting on both sides, and the number of rounds is largely decided by how specific the first answers were. Understanding that changes what a buying team can do about it, which is more than most buying teams believe.

02

How it works

Its purpose is to produce a record somebody can rely on, not to be convinced. A reviewer has to write down what was established, so an answer that reads well and says nothing checkable creates work rather than closing it. That is why a vague reply generates another round: the reviewer literally cannot complete their own task with it.

Much of it is the same questions everywhere, which is why vendors keep prepared answers and why standard formats exist. A vendor asked to complete a bespoke spreadsheet when it holds a completed standard one is being asked for translation work, and accepting the format it already has is frequently the single largest saving available in the whole exercise.

Existing artefacts answer a lot of it. An audit report or a certification with its scope statement covers many rows outright, and asking for those first often reduces the questionnaire to the parts genuinely specific to your situation. Sending the full list without asking is how a two-week step becomes a two-month one.

For AI tools a few questions carry most of the weight, and they are not usually on the standard form. What is retained and for how long, whether material is used to train, which model provider sits behind the product, and where processing happens. Adding those four to a general questionnaire is worth more than the other several hundred rows combined.

Two ways to run the same review

Two ways to run the same reviewThe useful thing about this comparison is that it puts the timeline back under the buying team's control, which is not where most teams believe it sits. The common experience is of a process that takes as long as it takes, conducted by other people, with the vendor as the variable. In fact the number of rounds is close to determined by three decisions made before anything is sent: whether existing artefacts were requested first, whether the vendor's own completed format was accepted, and whether the questions asked were specific enough to produce recordable answers. None of those requires authority over the reviewers or leverage with the vendor. They are simply the difference between asking everything of everybody and asking the things that are not already answered somewhere.Four roundsSend the full bespokespreadsheet.Receive general answers.Ask again, more specifically.Twice.One roundAsk for the report andcertification first.Accept the vendor's standardformat.Add the four questions aboutour material.Both approaches establish thesame facts. One takes weekslonger, and every step thatcaused the difference was chosenby the buyer rather than by thevendor.
The useful thing about this comparison is that it puts the timeline back under the buying team's control, which is not where most teams believe it sits. The common experience is of a process that takes as long as it takes, conducted by other people, with the vendor as the variable. In fact the number of rounds is close to determined by three decisions made before anything is sent: whether existing artefacts were requested first, whether the vendor's own completed format was accepted, and whether the questions asked were specific enough to produce recordable answers. None of those requires authority over the reviewers or leverage with the vendor. They are simply the difference between asking everything of everybody and asking the things that are not already answered somewhere.
03

Seen in the wild

  • Asking what an assistant retains and whether material is used for training, which a general questionnaire rarely covers.

    ChatGPT
  • Establishing how a search tool handles permissions from the systems it reaches, which is the question specific to that product.

    Glean
  • Asking how an automation platform stores the credentials it holds for every other service you connect.

    Make
04

Common misconceptions

People assume

It is slow because vendors drag their feet.

In fact

Most delay is rounds, and rounds come from answers too general for a reviewer to record. Vendors usually reply promptly with what they have. Sending a bespoke format when they hold a completed standard one, and not asking for existing reports first, cause more delay than anybody's responsiveness.

People assume

A longer questionnaire is more thorough.

In fact

Past a point it mostly adds rounds. Hundreds of general rows produce general answers, while a handful of specific questions about what happens to your material produce answers a reviewer can act on. For AI tools the questions that matter are usually absent from the long form entirely.

05

Questions

How do we make it faster?
Ask for existing reports and certifications first, accept the standard format the vendor already holds, and add the few questions specific to your situation. Most of the delay is extra rounds, and each of those three removes a cause of one rather than pressing anybody to hurry.
What should we add for an AI tool?
What is retained and for how long, whether material may be used to train, which model provider sits behind the product, and where processing happens. Those four are frequently missing from general forms and are usually the ones that would actually change a decision.
Why do vague answers cause another round?
Because the reviewer's output is a record of what was established, and a reassuring sentence gives them nothing to write. That is a structural feature of the task rather than pedantry, and it is why specific answers close a review while confident general ones extend it.
06

Key takeaways

  • The point is a record somebody can rely on, not persuasion.
  • Most delay is extra rounds, caused by answers too general to record.
  • Existing reports and certifications answer many rows before you ask.
  • For AI tools, four specific questions beat several hundred general rows.
08

Tools that use this

  • ChatGPT

    Retention and training questions a general form rarely covers.

  • Glean

    How permissions from reached systems are handled, specific to the product.

  • Make

    How credentials for every connected service are stored.

Last checked July 2026

All glossary terms