You have a security questionnaire. It runs to several hundred rows, it was written for hosted software, and the vendor will complete it in two days using answers they have given ninety times before.
What comes back tells you the vendor can complete a questionnaire. That is a real signal about organizational maturity and it is not the same thing as having done diligence.
Two weeks to answer a simple question
Composite from a few evaluations in devolved organizations: a research university group, several faculties, federated IT, a purchase covering research administration and grant documentation.
The questionnaire came back complete. Certifications attached, everything in order, no red flags. Procurement signed it off in a week, which was fast and felt like a win.
About nine months later a faculty raised a query about where a particular category of data had been processed during the previous quarter. Nothing had gone wrong. Nobody had been breached. But a subprocessor in the chain had changed, the notice had gone to a shared procurement mailbox that nobody monitored, and it took roughly two weeks to assemble an answer to a question that should have taken an afternoon.
The questionnaire had asked whether the vendor used subprocessors. It had not asked how the university would find out when the list changed, and that is the question that mattered.
Why the form misses
Four structural reasons, none of which involve anyone cutting corners.
It asks about controls in general rather than about your deployment in particular. It is answered by a compliance function rather than by the people who operate the system. It captures a point in time, and the product you are buying changes monthly. And it was written for a category where the software you license is the software you run, which is not the arrangement here.
That last one matters most. Most products in this category sit on capability the vendor does not own, served from infrastructure they do not run, and the questionnaire has no row for that.
Five questions instead
Run these as a conversation, forty-five minutes, with the vendor’s engineering lead in the room rather than their compliance team. Insist on that. The whole value is in the follow-up questions, and a compliance function cannot answer follow-ups.
One. Where does our data go, every hop, and how will we be told when that list changes?
Not whether they use subprocessors. The list, the notification mechanism, the notice period, and which address it goes to. The mechanism is the part everyone forgets and the part that failed at the university.
Two. What of ours is retained, for how long, and what is derived from it that survives deletion?
Deleting source data does not necessarily remove what was built from it. Indexes, embeddings, caches, logs, evaluation sets, corrections your users made. This is the question with the widest range of answers in the industry right now, which is exactly why it is worth asking.
Three. Who at your company can see our data, in what circumstances, and can we see that access?
Support debugging is the usual route and it is entirely legitimate. You want to know the path exists, what triggers it, whether it requires customer approval, and whether the log is visible to you or only to them.
Four. What changed in the last twelve months that you were not obliged to tell customers about?
This surfaces the entire class of change that sits outside contractual notice provisions. It is also an excellent question for a reference call, where you will sometimes get a more complete answer.
Five. Show me your last incident and the write-up.
Not whether they have had incidents. Every operation running at scale has. A vendor who produces a post-incident review, even heavily redacted, is showing you how they operate more convincingly than any certificate. A vendor who says they have not had one is either very new or not counting the same things you would.
Keep the form
None of this is an argument for skipping the questionnaire. Send it. Your own audit function needs it, a vendor who cannot complete one is telling you something real about their maturity, and comparing completed forms across three vendors does occasionally surface a genuine difference.
The mistake is treating a completed form as a finished investigation. The form is the floor. The forty-five minute conversation is the diligence, and it costs less than the week your team will spend reconciling three completed spreadsheets.
One thing to do differently
Ask question two in writing, and keep the written answer.
What is derived from our data, and what survives deletion. It is the question where answers vary most between vendors, it is the one your data protection colleagues will come back to in year two, and a written answer given during evaluation is worth considerably more than a verbal reassurance you half remember.