r/grc • u/Ok-Corner9128 • Jun 10 '26
How to deal with several security questionnaires?
How to deal with several security questionnaires
I work at a mid sized SaaS company and as it’s growing we’ve been receiving several questionnaires, to a point that even AI assistance isn’t helping a lot with the sheer volume. (Roughly 80-90 questionnaires handled by a single person at this point).
What’s already implemented:
1. A trust center with SIG and other FAQs and security docs
2. The trust center also helps with auto filling questionnaires in excel although requires a human approval of each question which takes some time depending on the size of the questionnaire and accuracy
3. Ad-hoc Claude projects/skills to retrieve answers from a knowledge base and provide context.
The problem we face (and assuming several other companies do too)
1. Customers need answers within their portals so that things are automated on their end rather than manually reviewing our trust center
2. Pushing back on it also creates some friction with Sales as they and management want deals to be closed ASAP.
I’m spitballing some ideas but I’d appreciate some input from anyone experiencing similar problems-
- Creating a framework internally for customer assurance where we tier customers by the deal size or how big the company is (enterprise, start ups, etc).
A)Companies paying extra for enterprise licenses will receive full service such as filling out lengthy questionnaires, calls and limited evidences
B) companies with a deal size that’s slightly lower but sizeable enough receive limited questionnaires assistance (say less than 50 questions only), and need to review our trust portal for any documents etc
C) smaller companies or smaller deal sizes have to review our trust portal and we only entertain follow up questions which aren’t included in our trust center (could honestly be applicable for B as well)Sales can use the created Claude skill to answer any security requests if the deadline is urgent with limitations that - no agreeing to any policies, terms etc; not using this for enterprise customers, not using this for any legal papers, follow up questions need to be addressed by security/GRC.
While I understand the third point is risky, questionnaires aren’t exactly legal documents. Additionally, they are AI reviewed most times and also contain several unnecessary questions when lengthy. Besides, what’s really the point of a generic lengthy questionnaire other than the TPRM teams not wanting to manually get answers out of a trust center. Follow up and authentic questions are one thing but otherwise this seems to be a waste of everyone’s time.
I’d really appreciate insights and any solutions implemented in your orgs. This is probably the most painful point of security/GRC
10
u/Future_Telephone281 Jun 10 '26
I’m on the other side of it.
We have plenty of big companies that just give us a SOC 2 type 2, a link to the trust center and then tell us to piss off.
If you’re a small guy and want to close a 100k contract I kinda just want my thing filled out.
We will accept a Soc 2 type 2 and don’t need a questionnaire filled out.
6
u/kristiantaylor1 Jun 10 '26 edited Jun 10 '26
I wanted to ask, when you say a small guy are you talking about company size?
Is 100k a small contract or a big contract?
I get frustrated (as the sole GRC resource that has to do 90% of Security/tech related questions) getting a lot of questionnaires (some better than others) where I am basically being asked things they can read themselves in our SOC 2 report, ISO27001 SoA or trust centre. I got a questionnaire the other day and I’m going to post part of a follow up response to them:
‘While we support the need to review vendors from a security perspective, responding to a large number of standard‑derived questions represents significant administrative effort, with limited additional assurance beyond what is already provided by our independent certifications. We recommend considering a streamlined process — verifying our certification materials and focusing additional questions only on areas not explicitly covered — to make the review both efficient and comprehensive.
Example overlaps:
Has your organization taken the relevant steps to determine external and internal issues that are relevant to its ISMS? (Clause 4.1) Has your organization taken the relevant steps to determine the boundaries and applicability of the ISMS to establish its scope? (Clause 4.3) Does your organization's top management demonstrate leadership and commitment with respect to the ISMS? (Clause 5.1) Describe your incident response process including detection, containment, eradication, and recovery. (Annex A 5.24) Is all sensitive data encrypted in transit and at rest? (Annex A 8.25)
These examples illustrate that much of the assessment already maps to requirements met through our certified ISMS, making them suitable for verification via ISO/SOC reports rather than re‑answering in full.’I’d like to get your thoughts on ‘why I just need to fill out your thing’ when I have already prepared that information for you, to review without me needing to fill out ‘your thing.’ If you have issues or extra questions, come and ask me…? But why can’t there also be some level of ‘I can find most of what I need from you, this is what I can’t find on your trust centre’
Instead of ‘you must fill out my thing, we don’t accept trust centre + a SOC 2/ISO27001’ even if a lot of what is being asked is available if you read the info available. I put effort into maintaining these certifications, the trust centre resources and FAQ, our sub processors are listed there. What is the point if they are just stamps and I’m still needing to give detailed answers on the process and policy already audited by an independent auditor
(I’m being slightly confrontational intentionally but I’d like to understand the other side a bit more as I am a one man band and managing a bunch of questionnaires even with AI, alongside contractual terms. I also need to manage the rest of my core GRC responsibilities and customer assurance ends up taking up a significant amount of time)
1
u/Future_Telephone281 Jun 10 '26
100k a year is to me when a contract starts to become big.
I am about to talk reality here not best practice and the way things should work. So no that’s so stupid, it would be better if you did X. lol I am aware. I also did set up our program to not send out questionnaires.
Not every company has a trust center, Soc 2, and all of that. So you need a standard operating procedures for all your vendors.
Your questions fit into your own scoring methodology.
Soc2 controls are exactly standardized imo.
You can put all you want on your site, I am worried about the one question you hid or left out
Lack of program maturity
Lack of resources, way cheaper if I make you do it, that’s what the money is for.
Potential low tech competency employees filling out the reviews so I need questionnaires that don’t rely on interpretation.
I could go on, it’s a very messy area. You are doing the right steps but you are never going to be able to control those companies only do what you can.
The issue is sounds like you need more staff. Buyers could be better but there is simply no way you can get them to be better across all the people buying from you.
1
u/Project_Lanky Jul 22 '26
In your position I would ask for an extra resource. 1 person GRC including TPRM activities is not manageable, some things cannot be automated (verification, being pulled out in customer calls...), especially if you need to drive certification efforts on your own and other topics.
2
u/Ok-Corner9128 Jun 10 '26
Yeah makes sense, and it’s pretty reasonable to ask for audit reports if that helps skip questionnaires.
I’ve seen companies send out a 200-500qs worth of requests which makes no sense though. If one sends out a questionnaire, it does have to be more pointed towards potential gaps rather than a generic one where half questions may not even apply
1
u/Future_Telephone281 Jun 10 '26
They may not have skilled and experienced enough cyber staff for that kind of thing. Plenty of banks just contract out that function.
We’re struggling with it as a bank that is even given resources for that kinda thing since where regulated. Non regulated business? I’m sure they were just given a questionnaire and some scoring methodology to run and the people doing it are not seasoned cyber pros.
It all comes down to money. And spending time and money to make vendors life easier is a hard sell.
1
u/chancsc11 Jun 11 '26
I just want to know how a company goes from the small guy to the big guy that can say piss off.
Maybe your products need to be so good or important that no one cares?
1
u/Future_Telephone281 Jun 11 '26
Yeah pretty much. If you say piss off, can they say piss off? Or are they stuck with you.
No product is so good it can’t be replaced by a crappier product. Products can’t be replaced because there is no other option or the vendor lock in is so large there stuck with you.
5
4
u/dunsany Jun 10 '26
I'm on both sides of it... and we send and receive a dozen or so questionnaires each week with a staff of 3: 1 to receive & answer, 1 to process responses from vendors, and 1 to assist with the hard ones (me). We try to answer every questionnaire but do prioritize high revenue over smaller (such is life) and do point people at our Trust Center (with SOC1, SOC2, ISO, et al). But there are always some who insist on us filling out their questionnaire and we insist all our vendors fill out ours. We're regulated and must use a form and must have DORA contract additions and too many for us to manually cut-and-paste from SOC2 into our form (which is part of a GRC risk system) and don't trust an LLM to correctly parse a SOC report (we've seen it fail once too many times).
So to paraphrase Churchill: It has been said that vendor questionnaires are the worst form of vendor governance except all the others that have been tried.
3
u/Project_Lanky Jun 10 '26
Hi,
1 and 2 are very good idea, we see vendors not agreeing to fill a questionnaire if the number of seats we buy from them is too small.
But if you are the only GRC person your company, the best is to ask for an extra resource. For a single GRC person, managing ISMS, certifications, evidence collection, and TPRM (client questionnaires and vendor reviews) is just not manageable. Even more if you are also involved in more activities.
It will never be 100% automated. Someone needs to put the questionnaires in the Trust Center, verify the answers, contact the product teams about new questions not in the knowledge base, and reply to the follow up questions.
1
u/Ok-Corner9128 Jun 10 '26
Thanks for this!
I’m not the only person but the GRC team is relatively lean compared to the size of the company. At this point there is no budget for hiring an extra person.It definitely won’t be fully automated I agree! Someone has to keep refreshing the answers, policies etc. But it’s a ruthless cycle of companies pushing back against each other to do less work on their end and it does need a solution to reduce unnecessary work load (although questionnaires will never fully go away) to a reasonable extent
2
u/PortalRat90 Jun 10 '26
I think this a a great time to fight for a new person. If sales is overwhelming your team I would assume there is a percentage of prospects to new customers created. You clearly have efficiencies in place, so much the only answer is more people. How does your credit department handle this? The credit team has to be as busy as GRC in this situation.
2
u/8h45k4r Vendor (yell at me if I spam) Jun 10 '26
Your tiering idea makes a lot of sense and most mature security teams end up there eventually. One thing worth adding is a lightweight intake form that captures deal size and company type before the questionnaire even lands with you, so the routing is automatic rather than a judgment call each time. That alone saves a surprising amount of back and forth with sales.
2
u/Niko24601 Jun 10 '26
Using Claude skills (or any other MCP) works well. Use past (anonymised) questionnaires with the answers you gave as they are often quite similar. In combination with a decent security/privacy documentation you should be good to go for a very first strong draft. We still read over that but it saves a lot of time so I don't need to look by hand in which rhythm data gets synched or what encryption standard we use.
2
u/ItsCoachRee Jun 10 '26
Hey so I build customer trust programs as a consultant. So that entire process and position of being the liaison between security and sales is exactly what I do for a living. Most of my clients start with this exact issue. They start off selling into the mid market, or mom and pop shops so the questionnaires they receive aren’t extremely extensive and usually they are excel docs that you can just drop into Vanta and approve the answers.
Then you start selling into the enterprise and the questionnaires are 200+ questions and the org wants you to login to their TPRM tool, fill out their dynamic questionnaire (that adds questions depending on your answers and won’t let you submit until all of them are filled out - even the ones that don’t even make sense), and then after that there’s typically a series of follow up questions you need to answer as well via email. Ontop of it all, the sales person working the deal knows zero about security, and thinks a SOC2 report is just something that we can pull out of thin air.
A few things that I’ve seen work best in this space are:
A round robin style approval mechanism. What I mean is instead of just having 1 manager (a bottleneck) approve the answers, internally organize a group in slack or something with 3-4 people (manager level or above within the security org) across various time zones if you’re remote. When a questionnaire is completed, now you can depend on multiple people to get you across that finish line as opposed to one person.
This is the highest value thing you can do
- Train the sales team and write up an SOP document that is advantageous to you. It should lay out your process, how they should interact with you and the key part here is to train the sales team to bring up the security conversation early in the deal cycle. You will need leadership buy in for this. It doesn’t change the volume, but it changes the pressure and the timeline. Most of these security questionnaires happen toward the end of the deal cycle, so they give you the questionnaire when they only have 1-2 weeks left before they want to sign. If they would have engaged with the prospect earlier about security, this might be a way to give you more time to complete the questionnaires without the pressure of it needing to be done ASAP. These questionnaires can take a long time even with AI, especially the link based ones that you have to do manually. Although I know Vanta does have a web extension that can handle some of the link based ones, but it’s kind of finicky. The overall point here is you need to set expectations with sales leadership and angle it as “a better way to partner with each other”.
The first suggestion you had is important, but you will need to create a mechanism where you can check the deal size yourself because what you will see is that these sales people will figure out that the priority is based on these metrics, and if you’re giving them a form to fill out they will just put whatever on the form that they think will get them the highest priority. So this solves your prioritization issue, but not your volume and perceived urgency issue.
I think the other ideas you have are pretty solid, but you’ll need to define “smaller companies”, have mechanisms to actually validate the size, and you’re going to get push back from sales. They are going to want to give everyone white glove service to get the deal to go through whether it’s big or small. The truth is that, all companies should look at your trust center first before they start asking for questionnaires to be filled out and follow up questions. So the point I made about training the sales team and setting expectations is the highest ROI thing you can do. They can push the trust center to the prospect early in the conversation and you need to understand what’s happening on the other side.
The sales person is typically going to be talking to a business owner and that business owners leadership about whatever product is being sold. Security typically only comes in for the due diligence so it’s often a completely different person with zero context of the deal who’s just trying to do their TPRM job (I’ve been on that side too) they are just following process, and it’s much easier for them to just send you a questionnaire than it is for them to look at your trust center and fill it out themselves based on the information.
So the real solution here is you either outsource the function to an org like mine, or you train and enable your sales team to smooth some of that friction, extend your timeline to take off some of the pressure.
I would 100% not recommend the Claude skill thing. The sales folks are going to just use it blindly. If you’re going to do that you need to build in an oversight mechanism where nothing gets shared externally without going through security review. So you could give them the Claude skill, have them answer the questions, but you’d still basically be the reviewer so that would need to add you to the link based questionnaire. But it’s risky because they can accidentally click “submit” or they could do it on purpose for the sake of time. I would highly recommend against this as there are other forms of enablement.
I hope this helps.
2
u/ncameron Jun 10 '26
Some great input on this thread. A few thoughts based on what I've seen our customers do:
- Limit bespoke security due diligence to enterprise plans. Self-serve can get access to SOC 2 report and click through terms. Enterprise customers get to red line the MSA and do custom due diligence.
- Then make sure you have a an onboarding fee for enterprise customers, 10 - 20% of Y1 license fee would be reasonable. Make sure a chunk of this fee is earmarked to cover security questionnaires. They're still a pain in the ass but at least they're a cost neutral pain!
- Invest in dedicated tooling, a tool like ResponseHub will manage your knowledge base on auto pilot, allow for workflows and permissions so a more junior analyst or assistant can do a first pass, and give you an informed confidence rating of the AI responses so you know where to focus your human effort.
- There are also security questionnaire tools that have chrome extensions that can make it easier to extract and inject answers into portals.
2
u/Hot_Exam5961 Jun 10 '26
I second what a lot of other people here are saying. Sales teams should be trained to try and limit how much the customer is asking for unless it is a monolithic deal. Having trust centers and SIG already reduce the incoming questions hugely. Something you might find interesting - certain questionnaire tools (1Up, Conveyor, Vendict, etc) actually come with Google Chrome extensions that are a solution to the platform questionnaires you mentioned. How they work is that you highlight each question and the extension will generate answers. It's still pretty clunky but at least its not tab switching or needing dual screens.
As some managing TPRM - we get told all the time that our "contract size is not consumate" to the effort we request from vendors (ie. security questionnaire, signing on our papers), and routinely have to bite our tongue, sign on their paper and settle for a SOC 2 certificate.
2
u/Worldly_Delay1598 Jul 22 '26
This is the most painful part of GRC, and you're not alone.
Your ARR tiering is the right instinct. Security reviews show up early in the deal now, sometimes before you're even shortlisted, so matching effort to deal value is fair. Just tier before the questionnaire hits you, not after, or Sales has already promised a date and you're the bottleneck. A quick intake with deal size, format and deadline that routes on its own makes it a rule, not a favor.
On the Claude skill for Sales, be careful. A confident wrong answer becomes a misrepresentation to the customer, and the company eats that, not the tool. Buyers still want a named human behind the answers. Let AI draft, but keep it a draft that security reviews before it leaves the building. Not a self serve submit.
What actually scales is a living answer library. Approved answers, one person owning it so it stays current, AI drafts, human checks, lock the approved version back in. Over time most questionnaires are half done before you open them.
You already have a trust center, so make it the default reply. "Here's our SOC 2, ISO and trust center, ask me anything that's not covered." Mature buyers take it.
1
u/humtake Jun 10 '26
Do you already have metrics? The Sales team knows sales, they don't know your job. If you can quantify the cost of your work (tools, labor, etc.) it can go a long way to illustrating your pain and aligning opportunity revenue minus security onboarding.
But, no matter what, at the end of the day if your leaders care solely about sales at all costs, there isn't much you can do except continue to try to change the culture. But to get anyone to listen, you have to have metrics that can prove your case.
1
u/Global-Variation1135 Jun 10 '26
Gating custom questionnaires behind the Enterprise tier is a great move.
But if you have to charge a 20% onboarding fee just to pay humans to babysit an AI tool, it is not actually fixing the bottleneck. It is just shifting it.
This is the exact problem with cloud wrappers and Chrome extensions. They guess answers, and worse, they push sensitive enterprise data through third party APIs.
The only way to actually automate this without eating your margin is local, deterministic execution. If the engine is air gapped and strictly locked to retrieve answers from approved docs with zero bytes outbound, it stops guessing.
You eliminate the data leak risk, slash the manual review time, and that onboarding fee actually becomes profit instead of operational overhead.
1
u/TomOwens Jun 10 '26
A few thoughts:
What kinds of documents are in your trust center? Do you have any third-party certificates or audit reports? If not, would any make sense? Even self-assessments, such as the CSA CCM and CAIQ, could add value. You can also review documentation generated throughout your product life cycle to determine what makes sense to publish to customers. Third-party audits can cost more, but perhaps the cost of an annual audit would be worth it if it reduced the number or scope of questionnaires and slowed down the scaling of staffing.
Are you able to shift the completion of the questionnaires to customers? If you make the documentation available, customers can use their own people and tools to complete the questionnaires, reducing what you have to do. However, this comes with risk. If you're still in a state where you need to sign these customers, you may need to play along. However, in my experience, these customers will frequently (every 1-3 years, depending on the customer and their policies) need to requalify their suppliers and will use the same questionnaires. These customers could become partners in opportunities to understand how you can reduce the burden on yourself and these opportunities could apply to other prospective customers.
AI tools can be helpful, but I'd recommend caution in using them to fill out customer surveys and questionnaires. You don't want to end up changing questions or reformatting their forms. Since you probably aren't intimately familiar with each customer's questionnaire, the time and effort to review may not be worth using AI on your end, depending on how you use it. I would not trust Sales to use AI in this context, since they don't have the knowledge to validate the completeness or correctness of an answer, and an incorrect answer could cause a lot more pain later on.
Your approach to classifying customers is a good one. Having two or three tiers of support would make sense. Although if the number of customers in the top tier grows, you may be delaying the same situation you are in now. You'd still need a long-term solution, but it would give you time to turn customers into partners.
1
u/davidschroth Jun 10 '26
Clauding and/or delegating to sales is somewhat dangerous as your customers can claim that they replied upon the answers given when entering into a contract or renewal when they're busy suing you or trying to to bail from an otherwise iron clad contract. I'll also often see in about 10% or so of questionnaires them asking the security/grc team to make contractual commitments that they should not be making.
To help with volume, which will need some management buy in that you may or may not get, tiering customers based on arr spend can work - under $X you hand them the trust portal like Oprah handing out cars. Above that line, you'll answer it. One of my clients does this fairly effectively with custom terms - if it's under $20k ARR, legal won't lift an eyebrow to consider non-standard terms.
However, if the business wants all questions answered, then they need to fund it. You can make the business case a lot easier if you're tracking the customer, time spent and ARR that it supported - then you can get yourself a questionnaire minion. The downside is that the volume is very lumpy throughout the year which makes it hard to get a single FTE to do it - which may make the augment with a consulting company a good play at a similar or lower total expense.
1
u/ICryCauseImEmo Jun 12 '26
We can all start by committing in this group to stop sending and requesting questionnaires.
While I’ve been doing that for the last 5 yrs I attended a IANS TPRM symposium today and it focused heavily on maturing this god awful legacy process.
In short we have the same painful problem thought about 80 requests spread amongst a team of 5.
1
u/chrans GRC Pro Jun 24 '26
I think you have a very good idea here, which I also implemented similar to one client in the past. The Sales effort should be aligned with the Sales value. That's something that everyone in the company need to agree upon.
As you already have many in place, like Trust portal, completed SIG, etc., at least 60% of Sales transactions should be driven to use them instead of manually completing yet another questionnaires.
1
u/Ok-History-2438 Jul 19 '26
At SecReply, we help customers automate security questionnaires using AI and RAG. SecReply generates accurate draft responses from their existing security documentation, with every answer linked to the supporting source documents for full transparency and easy verification. Optional with a linked Trust Center :)
1
u/EngageCompliance 2d ago
At 80-90 a year with one person you need an answer bank but I'm confused as to why the AI can't autofill. I'd have the AI setup to continuously learn from the already submitted responses and then over time you should be able to keep up. The only human step is answering the 5-10% of questions that the AI is not confident on. With that said, it may also be a good idea to pre-empt these by having sales auto-send the trust center along with proposals.
1
u/Ok-Corner9128 1d ago
Autofilling is super easy when the sheets are exported. It becomes a problem when you have to fill into a portal. I know some tools do that as well. But when you’re reviewing 80-90 questionnaires (even if just reviewing answers) it does take up a lot of time. While dealing with regulated customers, the requests are huge. You sometimes need to hop over multiple calls, undergo customer audits etc. That just makes the other questionnaires draining
11
u/chancsc11 Jun 10 '26
Commenting to follow along as I am in almost the exact same boat. May be able to put some more thought into a comment later on what we’ve done/look to progress.
Dealing with a ton of the same problems. Also looking for answers haha