Playbook, SaaS company

A procurement reviewer working through a vendor assessment at speed

Somewhere in the middle of a deal that your sales team thinks is going well, a security reviewer the seller has never spoken to opens the marketing site and starts pasting rows from a vendor assessment into the chat box. They will never open the product. They have a spreadsheet, a deadline, and a list of controls, and the speed of the answer decides whether the deal moves this week or next month.

Why this is not the general answer

The handling pattern for security questionnaires holds across every trade. What follows is the part that does not.

  • The person asking is not a user and never will be, they are an assessor working through a template on behalf of somebody who has already chosen you.
  • The questions are commercial security controls: subprocessors, residency, audit scope, breach notification windows, provisioning standards, contract terms.
  • Failure here is silent, because a reviewer who cannot get an answer marks the row unanswered and the deal stalls without anybody telling you why.
  • The endpoint is always a document rather than a conversation, and the document carries an attestation that only a person can put their name to.

How it arrives

  • do you have an audit report we can review
  • who are your subprocessors and where do they operate
  • can we see a summary of your last penetration test
  • do you support scim provisioning and enforced single sign on
  • what is your breach notification window
  • will you sign our data processing agreement or only your own

What has to be indexed for this to work

Material behind this answer
The trust page and the subprocessor listEvery third party that touches customer data, what they do, and where they operate. Reviewers ask this first and it is entirely publishable. Keep it dated, because a list without a date reads as a list nobody maintains.
How an audit report is requestedNot the report, the route to it: who to contact, whether a confidentiality agreement is required first, and how long that usually takes. The assistant can hand somebody that route in one reply, and the route is the actual bottleneck in most deals.
Your data processing agreement and its standard positionWhether you offer your own agreement, whether you will review theirs, and which annexes are already prepared. Reviewers ask this because their legal team asked them, and a clear published position saves a fortnight.
The answers you already reuse across assessmentsMost companies past a certain size have a document of standard responses, written once and pasted repeatedly. It is the highest value material for this cell and it usually lives in one person's drive rather than anywhere indexable.

The reply

A reply worth copying
The subprocessor list with processing locations is published on the trust page, and enforced single sign on with automated provisioning is available on the plans listed there. The audit report is shared under a confidentiality agreement rather than published, and the security team sends it out on request. I cannot complete or return an assessment document, so leave your name, your work email and the deal or account it relates to and the team will send the report and the standard response set together.

It answers the rows it can from published material and gives the route for the row it cannot, which is what an assessor actually needs to keep moving. It never characterises whether an answer satisfies the control, because that judgement belongs to the reviewer and offering it is how a vendor ends up quoted in a report. Asking which deal it relates to means the response lands with the sales thread rather than as an anonymous request.

Where it stops

The trigger. Any request that ends in a document being returned, a term being agreed, or a signature.

The handover, worded
Completed assessments and signed agreements come from the security team rather than from here, and I cannot commit to a contractual position. If you leave your name, your work email and the company you are assessing on behalf of, they will send the report request form and the standard responses in one go.

It stops answering before it guesses, says who will pick it up, and asks for the one thing that makes a reply possible. Nothing about it reads as a dead end.

Never say this here

Out of bounds

  • That you hold a certification, audit report or assessment status that your own published material does not state.
  • An availability commitment or recovery target that is not in a published service agreement.
  • That a given answer will satisfy the reviewer's control or their internal policy.
  • That a contractual term, annex or amendment is acceptable.

Questions

Our reviewers want the answers back in their own template. Can it do that?
No, and it should not appear to. It answers in chat with references back to the source page, which lets a reviewer verify a claim against your own document rather than trusting a chat message. Transcribing that into their template, and attesting to it, is a person's job with a person's liability attached.
Is it risky to let a security team query us through a public widget?
It answers only from what you index, so the exposure is exactly the material you chose to publish. The genuine risk is the opposite of leakage: a confident sounding summary of a carefully worded trust page, which is why quoting with a reference beats paraphrasing here.
What is the fastest thing we can do to improve these answers?
Publish the subprocessor list and the report request route, and date them both. Those two rows appear in nearly every assessment, they block the rest of the sheet, and neither of them requires a legal review to put on a page.

Keep reading

Try it on your own material

Upload a document or point it at your site, paste one line of HTML, then ask it something only your business could answer.