Supplier assurance, sometimes called vendor security assessment, third-party risk, or supply chain security, is how a larger organisation checks that the suppliers it depends on protect information properly. If a customer has sent you one, you are being assessed as part of their supply chain, and a clear set of answers is usually the last thing standing between you and a signed contract.
This guide explains what these questionnaires cover, why the questions can feel disproportionate for a small business, and how to answer each area honestly even without a security team.
Draft your answers free →What supplier assurance actually means
When a customer hands you their data or access to their systems, they inherit the risk that you might not look after it well. Their own regulators, auditors, and customers hold them responsible for that entire chain, so they check each supplier before signing and usually again once a year.
That is all a supplier assurance questionnaire is: their way of getting comfortable that working with you will not become their security problem. It is routine due diligence, not a judgement on your business.
Why a small supplier gets a big-company questionnaire
The form you receive is often a standard template the customer sends to every supplier, from a one-person consultancy to a multinational. That is why a five-person business can be asked about data centre access or a 24/7 security operations centre it does not have.
The answer is not to invent controls to match the question. It is to answer proportionately: describe what you actually do, and where something does not apply to a business your size, say "not applicable" with a short reason. Reviewers expect this from smaller suppliers.
The sections you will usually see
Whatever the template, supplier assurance questionnaires tend to cover the same areas:
- Governance: who owns security, what policies you hold, and how you manage risk.
- Access control: named accounts, least privilege, and multi-factor authentication.
- Data protection: how you handle personal data under UK GDPR, retention, and deletion.
- Encryption: protecting data in transit and at rest.
- Secure configuration and patching: keeping devices and software up to date.
- Malware protection and email security.
- Backups, business continuity, and incident response.
- People: staff training, and background checks where relevant.
- Subcontractors and subprocessors who touch the customer’s data.
How to answer as a small business
The reviewer is looking for honesty, proportionality, and consistency, not enterprise polish. State plainly what you do, keep each answer consistent with the others, and never claim a control you do not actually have. An honest "we do not do this yet, and here is our plan" reads far better than a hollow yes that unravels later.
If you hold Cyber Essentials, say so and give the certificate number, as it answers a whole cluster of technical questions at once. If you do not, simply describe the equivalent controls you have in place.
Proving it: evidence and consistency
Where you can, point to something real: a short policy, your MFA settings, your backup arrangement. You rarely need to attach documents, but answers that reference your actual practices carry more weight than generic statements.
Consistency matters just as much. The same underlying fact, such as who approves access or how you report a breach, should read the same way everywhere it comes up. That is far easier when you answer from a reusable set of approved answers rather than writing each one from scratch.
A faster way to complete it
Supplier assurance questionnaires are long and repetitive, and the same fact is easy to phrase five different ways by the end. Tickbox reads your questionnaire, drafts a grounded answer to every question in your own words, and shows which policy or control each answer draws on. You review, edit, and send. Nothing is submitted on your behalf, and it never claims you are certified. Your first few answers are free, so you can judge the quality on your own document before paying anything.
Example answers to common supplier assurance questions
These are illustrative drafts. Tickbox writes answers like these in your own words, grounded in your policies and the relevant framework.
Frequently asked questions
Is a supplier assurance questionnaire the same as a security questionnaire?
In practice, yes. "Supplier assurance", "vendor security assessment", "third-party risk questionnaire", and "security questionnaire" all describe the same thing: a customer checking how a supplier protects information before and during the relationship.
We are only a few people. Why are we being asked all of this?
Because the customer usually sends the same template to every supplier. Answer proportionately, describe what you actually do, and mark questions that genuinely do not apply to a business your size as "not applicable" with a brief reason.
Do we need ISO 27001 to pass one?
No. ISO 27001 helps and is sometimes requested for larger contracts, but most supplier assurance questionnaires can be answered honestly without it. Cyber Essentials is a more realistic and widely accepted baseline for a small UK supplier.
How often will we have to complete these?
Often once per customer to win the work, then typically once a year afterwards, plus a fresh one for each new customer. This is exactly why a reusable set of approved answers saves so much time over the year.
More guides
Answer your questionnaire in minutes
Drop it in and Tickbox drafts every answer for you to review. Your first few are free.
Try it free