New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Ongoing operations

Vendor self-service due-diligence questionnaires

Assessing a vendor by guessing at their security posture internally is not the same as due diligence actually agreed with the supplier. ISO 27001 A.5.20 is specifically about security requirements being established and agreed with each supplier, not assumed on their behalf.

Transcript

Assessing a vendor by guessing at their security posture on their behalf is not due diligence. This is how you send the assessment to them instead.

Open the Trust & Privacy Hub and go to Data & Vendors. Pick a processor and open its record to see the questionnaire tools.

Send the same risk questionnaire directly to the vendor's own contact by email, as a secure link they can open without logging in.

The vendor answers it themselves, through a plain, unbranded page built for exactly this. Their answers come back structured, not pasted into an email.

Every link sent is tracked: pending, completed, or revoked, so a wrong email address or a vendor that has gone quiet is caught instead of silently ignored.

If a link goes to the wrong person, revoke it. The vendor's access is cut immediately and a fresh link can be sent.

Their answers feed the same scoring engine as a self-assessment, so you compare what they claim with what your own scanning finds, and the vendor's tier reflects both.

Why this is required

A.5.20 sits alongside A.5.19's general supplier risk management: A.5.19 covers assessing and managing supplier risk, A.5.20 covers actually agreeing requirements with the supplier directly. An internal guess at a vendor's practices satisfies neither as well as the vendor's own confirmed answer does.

Due diligence that never reaches the vendor also tends to go stale silently: a vendor's practices can change without your organisation ever finding out, unless you have a repeatable way of asking them again.

What EuroCompliant does

The same risk questionnaire used for internal assessment can be sent directly to a vendor's own contact by email, as a secure, single-use link. No account or login is required on the vendor's side.

The vendor answers it themselves through a plain, unbranded page built for exactly this purpose. Their responses feed the same risk score as an internal assessment, but the evidence trail now shows the vendor's own answers rather than an internal guess.

Every link sent is tracked as pending, completed, or revoked, so a mistyped email address or a vendor who never responds is visible immediately rather than discovered at renewal or audit time.

Walking through it

1

Add a contact email to the vendor record

The questionnaire link is sent to this address.

Open /privacy-hub →
2

Send the questionnaire

A secure, single-use link is emailed directly to the vendor's contact.

Open /privacy-hub →
3

Track completion

See pending, completed, and revoked links per vendor, and resend or revoke as needed.

Open /privacy-hub →

The law

Frequently asked

Does the vendor need an account to answer the questionnaire?

No. The link is a secure, single-use token; the vendor answers directly on a plain page with no login required.

Can a questionnaire link be reused or shared?

It is single-use by default and expires after a set period. If it is sent to the wrong address, it can be revoked from the vendor's record before it is ever answered.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial