Ongoing operations
Vendor self-service due-diligence questionnaires
Assessing a vendor by guessing at their security posture internally is not the same as due diligence actually agreed with the supplier. ISO 27001 A.5.20 is specifically about security requirements being established and agreed with each supplier, not assumed on their behalf.
Transcript
Assessing a vendor by guessing at their security posture on their behalf is not due diligence. This is how you send the assessment to them instead.
Open the Trust & Privacy Hub and go to Data & Vendors. Pick a processor and open its record to see the questionnaire tools.
Send the same risk questionnaire directly to the vendor's own contact by email, as a secure link they can open without logging in.
The vendor answers it themselves, through a plain, unbranded page built for exactly this. Their answers come back structured, not pasted into an email.
Every link sent is tracked: pending, completed, or revoked, so a wrong email address or a vendor that has gone quiet is caught instead of silently ignored.
If a link goes to the wrong person, revoke it. The vendor's access is cut immediately and a fresh link can be sent.
Their answers feed the same scoring engine as a self-assessment, so you compare what they claim with what your own scanning finds, and the vendor's tier reflects both.
Why this is required
A.5.20 sits alongside A.5.19's general supplier risk management: A.5.19 covers assessing and managing supplier risk, A.5.20 covers actually agreeing requirements with the supplier directly. An internal guess at a vendor's practices satisfies neither as well as the vendor's own confirmed answer does.
Due diligence that never reaches the vendor also tends to go stale silently: a vendor's practices can change without your organisation ever finding out, unless you have a repeatable way of asking them again.
What EuroCompliant does
The same risk questionnaire used for internal assessment can be sent directly to a vendor's own contact by email, as a secure, single-use link. No account or login is required on the vendor's side.
The vendor answers it themselves through a plain, unbranded page built for exactly this purpose. Their responses feed the same risk score as an internal assessment, but the evidence trail now shows the vendor's own answers rather than an internal guess.
Every link sent is tracked as pending, completed, or revoked, so a mistyped email address or a vendor who never responds is visible immediately rather than discovered at renewal or audit time.
Walking through it
Add a contact email to the vendor record
The questionnaire link is sent to this address.
Open /privacy-hub →Send the questionnaire
A secure, single-use link is emailed directly to the vendor's contact.
Open /privacy-hub →Track completion
See pending, completed, and revoked links per vendor, and resend or revoke as needed.
Open /privacy-hub →The law
Frequently asked
Does the vendor need an account to answer the questionnaire?
No. The link is a secure, single-use token; the vendor answers directly on a plain page with no login required.
Can a questionnaire link be reused or shared?
It is single-use by default and expires after a set period. If it is sent to the wrong address, it can be revoked from the vendor's record before it is ever answered.
Related guides
Vendor and processor risk scoring
A structured questionnaire turns a vendor register into a dated, explainable risk score per vendor.
Publishing a trust center
A public page, at your own address, answering the security questions a prospect would otherwise ask by email.
Approved answer library and auto-fill
Approved answers to security questionnaire questions, reused automatically the next time the same question appears.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial