Skip to main content
Sign in See the demo

25 security questionnaire questions, and how to answer them with evidence.

For each question: what the reader is really looking for, the document that proves the answer, and the mistake that lowers a score. No answers to copy: a generic answer is spotted immediately and costs you trust.

How to use this page

Take your last questionnaire, find the equivalent questions here, and check just one thing: do you have the document listed alongside? If not, the task is not to write a better answer but to write that document.

Version 1, 25 entries. Continuously expanded.

The 25 questions

25 questions shown

01Governance

Do you have an information security policy approved by management?

What the reader is looking for

The reader is checking that a formal framework exists and is backed by executive management, not the literary quality of the document.

The document that proves it

The policy itself, with its approval page: name of the signatory, job title, approval date, date of the next review.

The classic mistake

Answering “yes” without attaching the approval page. An undated, unsigned policy is treated as non-existent.

02Governance

Who is responsible for information security in your organisation?

What the reader is looking for

An identified contact and a reporting line: the reader wants to know whether the function really exists or is diluted.

The document that proves it

Job description or organisation chart showing the role, its reporting line and its scope.

The classic mistake

Giving a name without a job title or reporting line, or naming an external provider as responsible without specifying internal oversight.

03Governance

How often do you review your security policies?

What the reader is looking for

A written review frequency and evidence that it is kept, not an intention.

The document that proves it

The policy’s review clause, and the minutes of the last review carried out.

The classic mistake

Answering “regularly” or “at least once a year” without producing the latest minutes. A frequency without evidence of execution does not count.

04Governance

Do you run security awareness activities for your staff?

What the reader is looking for

A recurring, measured programme, with a coverage rate.

The document that proves it

Awareness programme, schedule, and participation rate for the last financial year.

The classic mistake

Mentioning induction training only. The reader is looking for recurrence and measurement.

05Governance

Are you ISO/IEC 27001 certified, or equivalent?

What the reader is looking for

The exact scope of the certification, not just the fact that it exists.

The document that proves it

The current certificate, with its expiry date and its scope annex.

The classic mistake

Answering “yes” when only one site or subsidiary is covered. A scope narrower than the service sold is a discrepancy discovered at clarification.

06Governance

Do you carry out internal security audits?

What the reader is looking for

An audit programme, its independence, and the follow-up of the findings.

The document that proves it

Audit plan, latest report, and corrective action tracker with closure dates.

The classic mistake

Providing the report without the follow-up of findings. An open finding is more visible than one that has been addressed.

07Technical

How do you manage access and access rights?

What the reader is looking for

The principle applied, least privilege, segregation of duties, and evidence of access reviews.

The document that proves it

Access management procedure and minutes of the latest access rights review.

The classic mistake

Describing the tool without mentioning the periodic review. It is the review, not the tool, that proves control.

08Technical

Is multi-factor authentication in place?

What the reader is looking for

The exact scope: administrator access, remote access, business applications, service accounts.

The document that proves it

Authentication policy and a configuration screenshot or technical attestation for each scope.

The classic mistake

Answering a blanket “yes” when service accounts or a legacy tool are excluded. State the scope and the date by which it will be brought into compliance.

09Technical

How do you manage security patches?

What the reader is looking for

Committed timeframes by criticality level, and evidence that they are met.

The document that proves it

Patch management procedure with timeframes by criticality, and the compliance indicator for the last quarter.

The classic mistake

Writing “as soon as possible”. A timeframe with no figure is read as the absence of a process.

10Technical

Do you carry out penetration tests?

What the reader is looking for

The frequency, the scope, the independence of the provider and how the vulnerabilities found are handled.

The document that proves it

The provider’s attestation letter and a summary of the remediation plan, without disclosing the detailed technical report.

The classic mistake

Sending the full report: it contains your vulnerabilities. An attestation and a summary are enough, and are what is expected.

11Technical

Is your data encrypted?

What the reader is looking for

Encryption in transit and at rest, algorithms, and above all key management.

The document that proves it

Technical architecture documentation specifying the mechanisms and key management.

The classic mistake

Answering “yes, bank-grade encryption”. Without a mechanism or key management, the phrase is empty.

12Technical

How are your environments separated?

What the reader is looking for

Strict separation between production, acceptance testing and development, and no real data outside production.

The document that proves it

Architecture diagram and anonymisation procedure for test datasets.

The classic mistake

Leaving out the question of production data copied into acceptance testing: that is the point the auditor checks first.

13Technical

Do you log access and sensitive actions?

What the reader is looking for

What is logged, for how long, and who uses those logs.

The document that proves it

Logging policy with retention period, and a description of the monitoring.

The classic mistake

Confusing logging with monitoring. Logs that nobody reads detect nothing.

14Technical

Do you have security monitoring and incident detection?

What the reader is looking for

A real detection capability, with coverage hours and a response time.

The document that proves it

Description of the set-up, coverage hours, and committed response time.

The classic mistake

Announcing round-the-clock coverage when it relies on an informal on-call arrangement. The commitment must be sustainable.

15Data

Where would the data we entrust to you be hosted?

What the reader is looking for

The exact country, the entity operating the hosting, and the applicable law.

The document that proves it

Hosting documentation, contractual region, and the relevant clause of the data processing agreement.

The classic mistake

Answering “in Europe”. The reader wants the country and the entity, and will check whether processing follows storage.

16Data

Is any data transferred outside the European Economic Area?

What the reader is looking for

Whether transfers take place, including through a support subcontractor, and the safeguards governing those transfers.

The document that proves it

Register of transfers, standard contractual clauses, and impact assessment if one exists.

The classic mistake

Answering “no” while forgetting support access from another country. Remote access is a transfer.

17Data

What is your data retention period?

What the reader is looking for

Retention periods by data category, and an effective deletion mechanism.

The document that proves it

Retention policy by category and evidence that purges are carried out.

The classic mistake

Giving a single retention period for all data. A credible policy distinguishes between categories.

18Data

How do you handle a data subject rights request?

What the reader is looking for

A tool-supported process, a timeframe, and an identified point of contact.

The document that proves it

Request handling procedure, with committed timeframe and a register of requests handled.

The classic mistake

Pointing to a contact address without describing the internal process or the timeframe.

19Data

Have you appointed a data protection officer?

What the reader is looking for

The existence of the role, its independence and its published contact details.

The document that proves it

Formal appointment and contact details, as published and declared.

The classic mistake

Appointing someone without formalising the role or ensuring independence from the processing they oversee.

20Data

Is your data used to train artificial intelligence models?

What the reader is looking for

A clear, contractually binding answer on secondary use of the client’s data.

The document that proves it

Contractual clause prohibiting secondary use, and isolation architecture documentation.

The classic mistake

Answering with an intention. On this point, only an enforceable contractual clause is taken seriously.

21Third parties and continuity

How do you assess the security of your own subcontractors?

What the reader is looking for

An assessment process before contracting, and periodic reassessment.

The document that proves it

Third-party assessment procedure, list of critical subcontractors and the date of their last assessment.

The classic mistake

Providing the list without the assessment dates. A list alone proves no control. This is the reverse of the questionnaire: see Optivalue Reach.

22Third parties and continuity

Do you have a business continuity and disaster recovery plan?

What the reader is looking for

Quantified recovery time and data loss objectives, and evidence of a recent test.

The document that proves it

Continuity plan with quantified objectives, and the report of the last test exercise.

The classic mistake

Producing a plan without a test report. A plan that has never been tested commits no one.

23Third parties and continuity

How often do you test backup restores?

What the reader is looking for

A test frequency and evidence of the last successful test, not just the existence of backups.

The document that proves it

Backup policy with test frequency, and the report of the last restore test.

The classic mistake

Answering “backups are tested regularly”. Give the frequency and the date of the last test.

24Third parties and continuity

What is your security incident management process?

What the reader is looking for

The steps, the roles, and the committed client notification timeframe.

The document that proves it

Incident management procedure and the contractual notification clause.

The classic mistake

Describing the process without stating the notification timeframe. That is precisely what will be written into the contract.

25Third parties and continuity

Have you suffered a data breach in the last twenty-four months?

What the reader is looking for

An honest answer and a demonstration that the incident was handled and led to improvements.

The document that proves it

Post-incident report, notification made, and action plan with its closed actions.

The classic mistake

Denying on principle. A declared, well-handled incident is more reassuring than an unverifiable absence of incidents.

Can’t find your question? It most likely belongs to one of these twenty-five families, worded differently. That is exactly the work the platform does: recognising that a new question is a variant of one already handled. See the security questionnaires page.

These twenty-five questions, on your documents, in one hour.

You will see which ones your current documentation already proves, and which ones call for a document you do not have yet.

Demo on your documents When a document is missing