Vendor & supplier audit template
Vendor information security questionnaire
Ask software and service vendors how they protect your data before you share it with them.
4categories
16Yes/No questions
~16 minto complete
Who it's for: IT, security and procurement teams reviewing technology vendors.
Access control
- Is multi-factor authentication enforced for staff accessing customer data?
- Is access to customer data limited by role and reviewed regularly?
- Is access removed promptly when staff leave?
- Are admin activities logged?
Data protection
- Is customer data encrypted in transit?
- Is customer data encrypted at rest?
- Are backups taken, and is restoring from them tested?
- Can the vendor state where customer data is stored?
Operations
- Are systems patched on a defined schedule?
- Is there an incident response plan with customer notification steps?
- Has an independent security assessment or penetration test been done in the last 12 months?
- Are sub-processors listed and assessed?
People & policy
- Is there an approved information security policy?
- Do staff receive security awareness training at least yearly?
- Are staff bound by confidentiality agreements?
- Is there a named person responsible for security?
For each answer, record a short reason and attach supporting evidence (certificates, logs, photos) where available. These questions reflect general good practice; adapt them to the standards and laws that apply to you.