Provider security questionnaire for service access.
Use the same questions for each provider. Record the service covered, written answer, evidence date, owner, exception, and follow-up instead of treating a sales promise or certification badge as the whole answer.
This worksheet supports due diligence. It is not an audit, certification, legal opinion, or determination of compliance. Follow applicable law, contractual requirements, and company policy, and involve qualified security, privacy, legal, or risk reviewers when needed. Never paste secrets or live customer records into this worksheet.
Cover the service from scope through offboarding.
Record the service, evidence date, owner, and exception.
One material unknown can matter more than many yes answers.
Tie every answer to the service you may buy.
Ask for enough detail to identify scope, evidence, owners, and exceptions. Do not request passwords, keys, recovery codes, raw customer data, or exploitable system details.
Service scope and data
Make sure every answer applies to the service you may buy. A company-wide policy does not show which workers, systems, locations, or data are covered.
- What customer data and systems will this service access, store, transfer, or delete?
- Which staff, work locations, devices, and remote-work arrangements are in scope?
- Who owns security for this service and can answer evidence questions?
Identity and access
Ask how the provider names users, protects sign-in, limits permissions, reviews accounts, and removes access.
- Will each worker and administrator use an individual account, and which MFA methods are required?
- How are permissions approved, reviewed, changed, and removed?
- Are any shared accounts needed? If so, what approved exception, attribution, expiry, and rotation rules apply?
People and subcontractors
Find out who can reach the service or buyer data, including people outside the provider's main team.
- Which roles can access buyer systems or data, and what training or review applies to them?
- Which subcontractors or subprocessors can reach the service or buyer data?
- How will the provider tell you when a relevant subcontractor, location, or staffing model changes?
Logs, vulnerabilities, and testing
Ask for current evidence that clearly applies to the service. A badge or policy title by itself does not show how the purchased service works today.
- Which logs record account use, access changes, and important security events, and what safe evidence can the provider share?
- How are vulnerabilities, patches, and important control exceptions tracked for this service?
- Which audit, certification, or test evidence applies to this exact service, location, and report period?
Incident response
Write down the provider contact, reporting trigger, contract term, how records will be shared, and who is responsible for each step. Do not assume one notice deadline applies everywhere.
- Who reports a suspected incident, through which route, and under which written notice term?
- How are relevant records preserved, and who is responsible for each step during an incident?
- When were the service's response contacts or handoffs last tested?
Backups and continuity
A backup claim is useful only when its scope and recovery test are clear. Set recovery targets from business needs, contracts, risk reviews, and applicable requirements.
- What is backed up, where is it kept, and which systems are outside that scope?
- How is recovery tested, and which service did the latest test cover?
- Who decides whether the provider can use an alternate worker, location, system, or supplier during an outage?
Offboarding and data return
Plan the end of service before access starts. Name the records that prove accounts were removed and data was returned or deleted.
- How are worker, administrator, supplier, and service accounts removed when scope or staffing changes?
- How will buyer data be returned or deleted, including copies held by relevant subprocessors?
- Which evidence confirms removal or deletion, and who reviews unresolved exceptions?
Evidence, exceptions, and the decision
Do not turn self-reported answers into a security score. Record what is confirmed, what remains unclear, and who decides whether to accept, mitigate, or pause the risk.
- Which answer has dated evidence that covers the named service?
- Which gap needs a mitigation owner, agreement term, or qualified review?
- Is the item confirmed in writing, unclear, not applicable, accepted with mitigation, or paused?
A yes answer is not enough without scope and evidence.
These examples show how to record the review. They do not set universal controls or prove a provider is secure. On smaller screens, scroll the table horizontally to see every field.
| Control area | Question | Evidence to request | Buyer decision |
|---|---|---|---|
| Identity | Which accounts and MFA methods cover administrators? | Dated access-policy section plus a safely redacted record showing the rule is enforced for the named service | Confirm scope or clarify |
| Supplier access | Which subprocessors can reach buyer data? | Current subprocessor list, purpose, location, notice term, and service scope | Confirm, mitigate, or pause |
| Incident response | Who reports an incident and under which written term? | Contract section, named contact route, documented roles and responsibilities, and latest exercise date | Qualified review if unclear |
| Offboarding | How are access and buyer data removed at service end? | Account-removal record, return or deletion method, exceptions, and reviewer | Confirm before kickoff |
Keep the answer, evidence, exception, and owner together.
Send sensitive evidence through an approved secure channel. The template only holds review notes and does not upload or save answers.
PROVIDER SECURITY QUESTIONNAIRE Provider: [Provider name] Service being reviewed: [Named service or team] Data and systems in scope: [List] Buyer reviewer: [Name and role] Review date: [Date] Next review date: [Date] Repeat this block for each question: CONTROL AREA: [Identity, data, incident response, continuity, supplier access, or offboarding] QUESTION: [Paste the exact question] PROVIDER ANSWER: [Written answer] EVIDENCE: [Policy, dated report, redacted record, test summary, or contract section] SCOPE: [Service, system, location, staff, and report period covered] OWNER: [Provider owner and buyer reviewer] EXCEPTION: [Limit, gap, shared account, excluded system, or subcontractor] FOLLOW-UP DATE: [Date] AGREEMENT OR SLA CHANGE: [Describe the change, or none] REVIEW NEEDED: [Security, privacy, legal, procurement, risk, or none] DECISION: [Confirmed in writing, needs clarification, not applicable, mitigate, or pause] QUESTIONS SERVICE SCOPE AND DATA 1. What customer data and systems will this service access, store, transfer, or delete? 2. Which staff, work locations, devices, and remote-work arrangements are in scope? 3. Who owns security for this service and can answer evidence questions? IDENTITY AND ACCESS 4. Will each worker and administrator use an individual account, and which MFA methods are required? 5. How are permissions approved, reviewed, changed, and removed? 6. Are any shared accounts needed? If so, what approved exception, attribution, expiry, and rotation rules apply? PEOPLE AND SUBCONTRACTORS 7. Which roles can access buyer systems or data, and what training or review applies to them? 8. Which subcontractors or subprocessors can reach the service or buyer data? 9. How will the provider tell you when a relevant subcontractor, location, or staffing model changes? LOGS, VULNERABILITIES, AND TESTING 10. Which logs record account use, access changes, and important security events, and what safe evidence can the provider share? 11. How are vulnerabilities, patches, and important control exceptions tracked for this service? 12. Which audit, certification, or test evidence applies to this exact service, location, and report period? INCIDENT RESPONSE 13. Who reports a suspected incident, through which route, and under which written notice term? 14. How are relevant records preserved, and who is responsible for each step during an incident? 15. When were the service's response contacts or handoffs last tested? BACKUPS AND CONTINUITY 16. What is backed up, where is it kept, and which systems are outside that scope? 17. How is recovery tested, and which service did the latest test cover? 18. Who decides whether the provider can use an alternate worker, location, system, or supplier during an outage? OFFBOARDING AND DATA RETURN 19. How are worker, administrator, supplier, and service accounts removed when scope or staffing changes? 20. How will buyer data be returned or deleted, including copies held by relevant subprocessors? 21. Which evidence confirms removal or deletion, and who reviews unresolved exceptions? EVIDENCE, EXCEPTIONS, AND THE DECISION 22. Which answer has current evidence that covers the named service? 23. Which gap needs a mitigation owner, agreement term, or qualified review? 24. Is the item confirmed in writing, unclear, not applicable, accepted with mitigation, or paused? Do not paste passwords, recovery codes, API keys, private keys, live customer records, or other secrets into this document. Use an approved secure channel for sensitive evidence.
This template stays visible and selectable. Nothing is uploaded or saved.
Check what the service covers before relying on a certification.
The first pass should expose missing scope and owners. A qualified reviewer can then spend time on the important gaps.
- Name the service, data, systems, locations, and provider team you are reviewing.
- Send the same questions to each provider and ask for written, scoped answers.
- Record the evidence date, service scope, provider owner, exception, and buyer reviewer.
- Mark unsupported or disputed answers for clarification instead of filling in the gaps yourself.
- Send important gaps to your security, privacy, legal, procurement, or risk owner.
- Carry accepted terms into the agreement, onboarding packet, access plan, and next review.
Do not treat a broad answer as evidence for this service.
Mark the item for follow-up when the provider cannot show who, what, where, when, and which service the answer covers.
- The answer covers the provider company but not the service, workers, systems, or location you may use.
- Administrative access has no named account, MFA rule, approval owner, or review record.
- A subcontractor can reach buyer data, but its purpose, location, notice rule, or control scope is unclear.
- Incident language names no reporting route, written commitment, evidence owner, or division of work.
- A certification or test is offered without its scope, date, assessor, exceptions, or covered service.
- Backups are mentioned, but no one can show what was restored or when recovery was last tested.
- The provider cannot explain how accounts are removed or how buyer data is returned or deleted.
Use security guidance to ask better questions, not to claim approval.
These sources support identity, supplier, incident, and service-end questions. They do not certify this worksheet or any provider.
- NIST Cybersecurity Framework 2.0 covers identity, supplier requirements, incident coordination, and service-relationship planning.
- NIST SP 800-53 Rev. 5 covers account management, identification, authentication, least privilege, and access removal.
- CISA guidance on MFA explains why accounts should use more than one way to verify identity and recommends phishing-resistant options where possible.
- NIST SP 800-161 Rev. 1 covers supplier risk across acquisition, contracts, monitoring, incidents, and the end of a relationship.
- NIST SP 800-61 Rev. 3 covers incident responsibilities, information flow, coordination, and third-party roles.
Ask the right reviewer to check important gaps.
Bring the named service, open questions, written evidence, exceptions, and proposed agreement changes. Do not send secrets through the contact form.
Ready to plan your first offshore role?
Use OutsourcedU to write the role, SOPs, onboarding steps, and weekly review before you hire more people.