Questionnaires turn vendor assessment from an email-and-spreadsheet exercise into an automated workflow with scored, comparable results.
Vendor questionnaire builder and response scoring

The standard questionnaire

The built-in questionnaire covers 40 questions across seven domains:
  1. Organizational security
  2. Technical controls
  3. Data handling practices
  4. Sub-processor management
  5. Breach notification capabilities
  6. International data transfers
  7. Regulatory certifications
Customize question sets by vendor category or risk tier — a payroll processor and a font CDN do not need the same depth of assessment.

Sending and tracking

1

Select vendors and a question set

Send to one vendor or a batch. Each vendor contact receives a secure link — no account required to respond.
2

Automatic follow-ups

TruePrivacy tracks response rates and sends automated reminders on a configurable cadence.
3

Escalation for non-respondents

After a configured number of reminders, non-response triggers an escalation alert to procurement or legal. You can also set a policy blocking agreement renewal for non-respondents.

Scoring

Responses are scored automatically against your risk framework. Each answer contributes to domain scores and the overall vendor risk score, and answers that fail your policy thresholds are highlighted as findings with suggested follow-up actions.
Re-run questionnaires on a schedule — annually for high-tier vendors, biennially for low-tier — and TruePrivacy will diff the new responses against the previous round, highlighting what changed.
Completed questionnaires, scores, and follow-ups are stored on the vendor record as evidence of your third-party due diligence.