Every organisation that sells to larger companies answers the same security questionnaire many times a year: a customer's vendor assessment, the cyber insurer's renewal form, an auditor's request list, each worded differently, each asking about the same thirty or forty controls. Questionnaires (under Third-Party Risk) turns that into one job: upload the file as it arrived, let the platform draft the answers from your control library and from answers you have approved before, review them, and send the spreadsheet back.

Uploading a questionnaire

Choose New questionnaire, pick the file and say who sent it (customer, insurer, auditor, regulator). Excel and CSV files are read row by row: the column whose cells read like questions becomes the question list and any short cell before it on the same row is kept as the section or reference. Word and text documents are read line by line: lines that end with a question mark or start with a number become questions, short lines above them become sections. Files up to 5 MB and 1,000 questions are accepted. Anything the parser did not recognise can be added afterwards by hand.

Drafting answers

Draft answers works through the unanswered questions ten at a time. Each question is first looked up in the answer library, the answers you approved on earlier questionnaires; an exact match or a close paraphrase is filled in from record with the control it rests on. The rest go to your organisation's own AI provider, configured under Settings, AI, with one instruction: answer only from the control library, the requirements each control satisfies, its evidence and the approved policies, cite the control, and say "No information on record" rather than invent. Every drafted answer shows where it came from and, for AI drafts, how well the context supported it.

ℹ️
No AI provider configured? Library answers are still filled in, and every remaining answer can be written by hand. Nothing leaves the platform unless a provider is configured, and then only the compact control context and the questions.

Reviewing and approving

Each question shows the draft, the control it is based on (change it from the picker if the platform chose wrong) and the actions Approve and Not applicable. Edit the text in place; leaving the field saves it. With Save approved answers to the answer library ticked, approving an answer stores it under the question as it was asked, so the next questionnaire that asks the same thing, in the same words or close to them, is answered from record. The library grows with every questionnaire and the share of questions that need a human falls.

Exporting

Export (Excel) produces a workbook with one row per question in the original order: section, question, answer, status, the control behind it and the evidence noted against it. A questionnaire whose status is Approved is marked Exported on download. Requesters who want their own template filled in get the answers column to paste; the export keeps the order so that takes minutes.

Where it connects

  • Controls: the library is the source of every answer; a control with a clear description and current evidence produces a better draft than a bare title.
  • TPRM questionnaires: the other direction, the questionnaires you send to your own vendors.
  • Trust centre: publishing your certifications, policies and standard answers there deflects many questionnaires before they are sent.