Ongoing operations
Vendor self-service due-diligence questionnaires
Assessing a vendor by guessing at their security posture internally is not the same as due diligence actually agreed with the supplier. ISO 27001 A.5.20 is specifically about security requirements being established and agreed with each supplier, not assumed on their behalf.
Transcript
Assessing a vendor by guessing at their security posture on their behalf is not due diligence. ISO 27001 A.5.20 wants security requirements actually agreed with the supplier, not assumed internally.
Send the same risk questionnaire directly to the vendor's own contact by email, as a secure one-time link. No account or login is required on their end.
The vendor answers it themselves, through a plain, unbranded page built for exactly this. Their responses feed the same risk score, but now the evidence trail shows the vendor's own answers, not a guess.
Every link sent is tracked: pending, completed, or revoked, so a wrong email address or a vendor who never responds is visible at a glance, not discovered months later.
Why this is required
A.5.20 sits alongside A.5.19's general supplier risk management: A.5.19 covers assessing and managing supplier risk, A.5.20 covers actually agreeing requirements with the supplier directly. An internal guess at a vendor's practices satisfies neither as well as the vendor's own confirmed answer does.
Due diligence that never reaches the vendor also tends to go stale silently: a vendor's practices can change without your organisation ever finding out, unless you have a repeatable way of asking them again.
What EuroCompliant does
The same risk questionnaire used for internal assessment can be sent directly to a vendor's own contact by email, as a secure, single-use link. No account or login is required on the vendor's side.
The vendor answers it themselves through a plain, unbranded page built for exactly this purpose. Their responses feed the same risk score as an internal assessment, but the evidence trail now shows the vendor's own answers rather than an internal guess.
Every link sent is tracked as pending, completed, or revoked, so a mistyped email address or a vendor who never responds is visible immediately rather than discovered at renewal or audit time.
Walking through it
Add a contact email to the vendor record
The questionnaire link is sent to this address.
Open /data-records →Send the questionnaire
A secure, single-use link is emailed directly to the vendor's contact.
Open /data-records →Track completion
See pending, completed, and revoked links per vendor, and resend or revoke as needed.
Open /data-records →The law
Frequently asked
Does the vendor need an account to answer the questionnaire?
No. The link is a secure, single-use token; the vendor answers directly on a plain page with no login required.
Can a questionnaire link be reused or shared?
It is single-use by default and expires after a set period. If it is sent to the wrong address, it can be revoked from the vendor's record before it is ever answered.
Related guides
Vendor and processor risk scoring
A structured questionnaire turns a vendor register into a dated, explainable risk score per vendor.
Publishing a trust center
A public page, at your own address, answering the security questions a prospect would otherwise ask by email.
Approved answer library and auto-fill
Approved answers to security questionnaire questions, reused automatically the next time the same question appears.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial