Free tool How audit-ready is your organisation? Get your score in 3 minutes. Take the readiness check

Vendor & supplier audit template

Vendor information security questionnaire

Ask software and service vendors how they protect your data before you share it with them.

Use this template in Vexsai
4categories
16Yes/No questions
~16 minto complete

Who it's for: IT, security and procurement teams reviewing technology vendors.

Access control

  1. Is multi-factor authentication enforced for staff accessing customer data?
  2. Is access to customer data limited by role and reviewed regularly?
  3. Is access removed promptly when staff leave?
  4. Are admin activities logged?

Data protection

  1. Is customer data encrypted in transit?
  2. Is customer data encrypted at rest?
  3. Are backups taken, and is restoring from them tested?
  4. Can the vendor state where customer data is stored?

Operations

  1. Are systems patched on a defined schedule?
  2. Is there an incident response plan with customer notification steps?
  3. Has an independent security assessment or penetration test been done in the last 12 months?
  4. Are sub-processors listed and assessed?

People & policy

  1. Is there an approved information security policy?
  2. Do staff receive security awareness training at least yearly?
  3. Are staff bound by confidentiality agreements?
  4. Is there a named person responsible for security?

For each answer, record a short reason and attach supporting evidence (certificates, logs, photos) where available. These questions reflect general good practice; adapt them to the standards and laws that apply to you.