Skip to main content
Third-Party Risk Assessment Script: What to Ask When the Questionnaire FailsRisk Assessment & Treatment
5 min readFor External Auditors and Assessors

Third-Party Risk Assessment Script: What to Ask When the Questionnaire Fails

Purpose of the Script

You're conducting a SOC 2 Type II readiness assessment, and your third-party vendor just returned a security questionnaire with 200 "Yes" answers and no supporting evidence. Or you're preparing for ISO/IEC 27001 certification, and your assessor flags your supplier risk treatment plan as insufficient because it relies entirely on checkbox responses.

This interview script replaces inadequate security questionnaires with targeted questions that reveal actual control implementation, not vendor marketing claims. Use it during vendor onboarding, annual reviews, or when your assurance engagement requires documented evidence of Clause 15 (supplier relationships) compliance.

The script addresses what traditional questionnaires miss: control effectiveness, incident response capability, and alignment with your own ISMS requirements. It's designed for compliance managers and information security officers who need to satisfy ISO/IEC 27001 Annex A 5.19 through 5.23 (supplier controls) or SOC 2 CC9 (risk mitigation) criteria with defensible evidence.

Prerequisites

Before using this script, confirm:

  • Your risk appetite is documented. You need defined thresholds for acceptable supplier risk (ISO/IEC 27001 Clause 6.1.3 requires this). Without this, you can't evaluate vendor responses.

  • You know which controls you're inheriting. Map the vendor's services to your control environment. If they're hosting your customer data, their access controls become part of your CC6 (logical access) narrative for SOC 2 or your A.8 (asset management) implementation for ISO/IEC 27001.

  • You have authority to request evidence. Check your contract. The script asks for logs, policies, and test results. If your MSA doesn't grant audit rights, renegotiate before scheduling the call.

  • You've reviewed their existing certifications. If they hold SOC 2 Type II or ISO/IEC 27001 certification, request the reports first. This script supplements those documents; it doesn't replace them.

The Interview Script

Opening Frame

"We're conducting supplier risk assessments to support our [SOC 2 / ISO/IEC 27001] compliance program. I need to understand how your controls map to our requirements, and I'll be requesting evidence for our audit file. This should take 30-45 minutes."

Section 1: Control Implementation Evidence

Q1: "Walk me through your user lifecycle management process for employees who access our data. Specifically, how do you handle terminations?"

What you're listening for: Automated deprovisioning, access review frequency, segregation of duties between HR and IT. Vague answers like "we follow industry standards" mean the control doesn't exist.

Q2: "Show me a recent access review log for privileged accounts. What's your review cadence, and who approves exceptions?"

Why this matters: ISO/IEC 27001 A.9.2.1 requires user access provisioning. SOC 2 CC6.2 requires periodic review. If they can't produce a log within 24 hours, flag it as a Major Nonconformity risk.

Q3: "Describe your change management process. How do you test changes before production deployment, and how do you document rollback procedures?"

What you're testing: Secure Development Lifecycle maturity. If they don't separate development and production environments (CC8.1), you're inheriting operational risk.

Section 2: Incident Response Capability

Q4: "When was your last security incident? Walk me through your response timeline and what you reported to affected customers."

Red flags: "We've never had an incident" usually means they don't have detection capabilities. "We can't discuss that" suggests contractual notification failures.

Q5: "What's your RTO and RPO for the services we depend on? Show me your most recent business continuity test results."

Why this matters: ISO/IEC 27001 Annex A 5.29 and 5.30 require ICT readiness for business continuity. If their recovery time exceeds your own continuity requirements, you've got a gap.

Q6: "Do you maintain cyber insurance? What's your coverage limit, and does it cover third-party claims?"

What you're assessing: Financial resilience. This won't appear in a questionnaire, but it's material to your risk treatment plan.

Section 3: Alignment With Your ISMS

Q7: "How do you handle data deletion requests? Can you demonstrate cryptographic erasure or physical destruction records?"

Compliance link: SOC 2 CC6.5 (data removal), ISO/IEC 27001 A.8.10 (deletion of information). If they can't prove deletion, you're liable under GDPR or CCPA.

Q8: "What logging do you provide to customers? Can we ingest your audit logs into our SIEM, and what's the retention period?"

What you need: Real-time visibility. If they only provide monthly summaries, you can't meet your own monitoring requirements (ISO/IEC 27001 A.8.16).

Q9: "Walk me through your vendor management program. Who are your critical subprocessors, and how do you assess their security?"

Why this matters: Risk cascades. Their vendors become your vendors. ISO/IEC 27001 Clause 15 applies recursively.

How to Customize It

For SOC 2 Type II preparation: Add questions about complementary subservice organization controls. If you're relying on their infrastructure, document those dependencies in your System Description. Ask: "Which controls in your SOC 2 report apply to our service? Can you provide a bridge letter mapping your controls to our trust services criteria?"

For ISO/IEC 27001 certification: Focus on Annex A alignment. Ask: "Have you performed a gap analysis against ISO/IEC 27001:2022 Annex A? Which controls do you consider not applicable, and what's your justification?" Your Lead Auditor will expect you to document why you accepted those gaps.

For high-risk suppliers (payment processors, healthcare subcontractors): Add regulatory-specific questions. For PCI DSS: "What's your most recent QSA attestation date, and which SAQ level do you complete?" For HIPAA: "Can you provide your most recent business associate agreement and risk assessment?"

For SaaS vendors with shared responsibility: Map their controls to your inherited risks. Ask: "What's your patching SLA for critical vulnerabilities? Do you notify customers before maintenance windows?" If they patch on their own schedule, you need compensating controls.

Validation Steps

After the interview, validate responses against evidence:

  1. Request documentation within 5 business days. Policies, logs, test results, certifications. If they stall, escalate to your procurement team.

  2. Cross-check certifications. Verify SOC 2 reports on the AICPA portal. Confirm ISO/IEC 27001 certificates with the issuing certification body (ISO/IEC 17021 requires public registries).

  3. Map findings to your Risk Treatment Plan. For each gap, document: accepted risk, compensating control, or contract renegotiation. ISO/IEC 27001 Clause 6.1.3(e) requires you to maintain this record.

  4. Update your supplier risk register. Assign risk scores based on data sensitivity and control maturity. Re-assess annually or when their certification status changes.

  5. Brief your auditor. During your assurance engagement, you'll need to demonstrate how you evaluated supplier risks. This script and the resulting evidence file satisfy that requirement.

If the vendor refuses to answer these questions or can't provide evidence, you have three options: accept the risk and document it, implement compensating controls, or find a different vendor. What you can't do is ignore the gap and hope your auditor doesn't notice.

You Might Also Like