A Client Sent Us a Security Questionnaire. What Do We Do?

Vendor security questionnaire illustration with a document, a magnifying glass and a checklist showing progress.

A client sends you a vendor security questionnaire to complete before your contract renews. Some questions you can answer straight away. Others mean finding a report or asking your IT provider what they actually did.

The problem is rarely that you’ve done nothing. It’s that the records are scattered, and some of what looks finished is really still in progress. There was a scan, but you’d have to go looking for the report. The email thing got fixed, though you’d need to ask your IT provider what they actually did. And a planned improvement is not the same as a control that’s already in place, which is worth remembering before you round up an answer.

So a form that should take an hour takes a few days, most of it spent chasing down records of work that was already done.

This article shows how to keep useful records of findings, decisions and follow-up actions, so you have information to work from when the next questionnaire arrives.

Why this is landing on your desk

Clients ask because their suppliers have become one of the ways in. A supplier with a compromised mailbox or a spoofable domain is a route into everyone it invoices. Being small does not keep you off the list, it often puts you on it, because you are the easier way in to a client they cannot reach directly.

POPIA gives this a legal edge. Where a supplier processes personal information on a client’s behalf, section 21 requires the client to have a written contract confirming the supplier has the security measures set out in section 19 in place. Section 19 requires reasonable technical and organisational measures to secure personal information’s integrity and confidentiality, and it does not stop at having those measures in place. It also requires the responsible party to regularly verify that they are effectively implemented.

It is not only clients asking. King V Principle 10 puts the same question to your own board, covering governance of data, information and technology, including cybersecurity and the risks that come with outsourced services. Records of findings, decisions and follow-up actions are what let management and the governing body actually exercise that oversight.

What to keep, so the answers exist next time

Findings, decisions and follow-up actions are easier to use when they live in one place, built around five items.

  1. The finding. The original report or result, with its date, source, scope and stated limitations. Which domain, service or part of the business was assessed, and how. This is what stops a result about one area being mistaken for an assessment of the whole business.
  2. What it means. A short explanation of why the finding matters to the business. Whether it touches payment communications, customer information or the ability to operate. Someone without technical knowledge should be able to understand the concern from this alone.
  3. The decision. What was decided, by whom, and why. Approving corrective work, requesting more information, or accepting a risk are all legitimate outcomes. Where action is deferred or a risk is accepted, the reason and a review date belong here too.
  4. Responsibility and timing. Who is responsible for the next step, and when it should happen. If the work sits with an external provider, who inside the business is following up.
  5. The outcome. What happened, with the supporting information kept alongside it. A completion email and a check that the finding was actually addressed answer different questions, and it is worth keeping both.

Someone reviewing the record should be able to understand what was found, what the business decided and where things stand.

A worked example

Here is a fictional example showing how a single finding can be recorded across all five items.

FieldEntry
The findingEmail Trust Status Governance Record, 14 August 2026. Domain: example.co.za. DMARC record present, policy set to p=none. SPF present. Based on publicly observable DNS records at that date. No system access.
What it meansOur domain’s DMARC policy is set to p=none. It does not ask receiving mail systems to quarantine or reject messages that fail DMARC checks. This leaves an impersonation risk, particularly because we send invoices from this domain.
The decisionManaging director approved a move to enforcement on 21 August, on condition that all legitimate sending sources are identified first so that invoices and client mail are not blocked.
Owner and dateOperations manager, working with our IT provider. Monitoring from 1 September. Target of p=quarantine by 30 September and p=reject by 31 October.
The outcomeReassessed 5 October: policy now p=quarantine. Move to p=reject deferred until the CRM is confirmed as authenticating correctly. Review set for 5 November.

The final entry explains what changed, what remains outstanding and why. It also gives a review date, so the next person checking the record knows what still needs attention.

It’s worth reviewing the relevant records whenever a system, service or provider changes, and deciding whether a new assessment is needed. Keeping earlier reports and decisions lets you follow the history.

Using third-party reports to support your answers

A report from a provider is useful when it addresses the question being asked. ARMD.digital’s Email Trust Status, for instance, gives you an external, point-in-time record of a domain’s email authentication settings, based on publicly observable DNS indicators and requiring no access to your systems. It can support an answer about your DMARC policy. It cannot confirm whether staff use MFA or whether your backups can be restored, because neither is covered by the check.

When attaching the report, make sure its date, scope and limitations are clear. Keep it alongside any decisions and follow-up actions, so the record shows what was checked and what happened next.

What if the honest answer is no?

Say so, and say what you are doing about it and by when. A dated plan with a named owner is more credible than a yes you cannot support. Reviewers see a lot of optimistic answers, and an honest gap with a target date usually reads better than a vague reassurance.

Make the next request easier

The questionnaire in front of you is as good a place as any to start. As you answer it, keep what you find rather than letting it disappear back into an inbox once the form is submitted. Note what’s still unresolved and who’s chasing it.

Next time, you’ll have records to work from. Check what’s changed, update the relevant information and identify any new questions that need attention.

Not sure where to start? Your domain’s email authentication is a reasonable first record to build.
Get your Email Trust Status