Template
Vendor Onboarding Security Questionnaire
A 37-question security questionnaire inside a nine-step onboarding workflow, from intake and tiering to contract safeguards and go-live.
An editable 35-page form for bringing a new vendor on board, or re-reviewing one after a material change. Every answer gets a vendor response, the evidence required, an analyst rating and a next action.
What’s inside
- A readiness section covering the onboarding pack, inputs, stakeholders, systems access, planning estimates by tier, and 2026 reference points across DORA, GDPR, India DPDP, the EU AI Act, OCC 2023-17 and RBI
- A nine-step workflow from intake and a duplicate-tool check through tiering, the questionnaire, DPA review and risk acceptance to the contract security schedule, provisioning and final sign-off
- A ten-question intake form for the business owner, and 37 security questions across 11 domains, from access management and encryption to AI and model use and insurance
- A tiering and DPA guide, a contract security schedule checklist, a review summary with a findings register, and an eight-artifact onboarding pack tracker
- Completion checklists, decision gates, a nine-row red-flag table with the required action, and the final approval block
The analyst assigns the rating after validation instead of taking the vendor’s answer at face value: Met, Partly Met, Not Met, Evidence Pending or Not Applicable. Critical findings block onboarding until they are fixed, High findings need a written, dated remediation commitment, and production access waits for recorded sign-off at the level the tier requires.