Security diligence worksheet

Provider security questionnaire for service access.

Use the same questions for each provider. Record the service covered, written answer, evidence date, owner, exception, and follow-up instead of treating a sales promise or certification badge as the whole answer.

This worksheet supports due diligence. It is not an audit, certification, legal opinion, or determination of compliance. Follow applicable law, contractual requirements, and company policy, and involve qualified security, privacy, legal, or risk reviewers when needed. Never paste secrets or live customer records into this worksheet.

Question groups8

Cover the service from scope through offboarding.

Answer ruleWritten + scoped

Record the service, evidence date, owner, and exception.

No total scoreResolve gaps

One material unknown can matter more than many yes answers.

Question bank

Tie every answer to the service you may buy.

Ask for enough detail to identify scope, evidence, owners, and exceptions. Do not request passwords, keys, recovery codes, raw customer data, or exploitable system details.

Security review

Service scope and data

Make sure every answer applies to the service you may buy. A company-wide policy does not show which workers, systems, locations, or data are covered.

  • What customer data and systems will this service access, store, transfer, or delete?
  • Which staff, work locations, devices, and remote-work arrangements are in scope?
  • Who owns security for this service and can answer evidence questions?
Security review

Identity and access

Ask how the provider names users, protects sign-in, limits permissions, reviews accounts, and removes access.

  • Will each worker and administrator use an individual account, and which MFA methods are required?
  • How are permissions approved, reviewed, changed, and removed?
  • Are any shared accounts needed? If so, what approved exception, attribution, expiry, and rotation rules apply?
Security review

People and subcontractors

Find out who can reach the service or buyer data, including people outside the provider's main team.

  • Which roles can access buyer systems or data, and what training or review applies to them?
  • Which subcontractors or subprocessors can reach the service or buyer data?
  • How will the provider tell you when a relevant subcontractor, location, or staffing model changes?
Security review

Logs, vulnerabilities, and testing

Ask for current evidence that clearly applies to the service. A badge or policy title by itself does not show how the purchased service works today.

  • Which logs record account use, access changes, and important security events, and what safe evidence can the provider share?
  • How are vulnerabilities, patches, and important control exceptions tracked for this service?
  • Which audit, certification, or test evidence applies to this exact service, location, and report period?
Security review

Incident response

Write down the provider contact, reporting trigger, contract term, how records will be shared, and who is responsible for each step. Do not assume one notice deadline applies everywhere.

  • Who reports a suspected incident, through which route, and under which written notice term?
  • How are relevant records preserved, and who is responsible for each step during an incident?
  • When were the service's response contacts or handoffs last tested?
Security review

Backups and continuity

A backup claim is useful only when its scope and recovery test are clear. Set recovery targets from business needs, contracts, risk reviews, and applicable requirements.

  • What is backed up, where is it kept, and which systems are outside that scope?
  • How is recovery tested, and which service did the latest test cover?
  • Who decides whether the provider can use an alternate worker, location, system, or supplier during an outage?
Security review

Offboarding and data return

Plan the end of service before access starts. Name the records that prove accounts were removed and data was returned or deleted.

  • How are worker, administrator, supplier, and service accounts removed when scope or staffing changes?
  • How will buyer data be returned or deleted, including copies held by relevant subprocessors?
  • Which evidence confirms removal or deletion, and who reviews unresolved exceptions?
Security review

Evidence, exceptions, and the decision

Do not turn self-reported answers into a security score. Record what is confirmed, what remains unclear, and who decides whether to accept, mitigate, or pause the risk.

  • Which answer has dated evidence that covers the named service?
  • Which gap needs a mitigation owner, agreement term, or qualified review?
  • Is the item confirmed in writing, unclear, not applicable, accepted with mitigation, or paused?
Fictional review rows

A yes answer is not enough without scope and evidence.

These examples show how to record the review. They do not set universal controls or prove a provider is secure. On smaller screens, scroll the table horizontally to see every field.

Four fictional examples. Replace them with provider-specific answers and evidence.
Control areaQuestionEvidence to requestBuyer decision
IdentityWhich accounts and MFA methods cover administrators?Dated access-policy section plus a safely redacted record showing the rule is enforced for the named serviceConfirm scope or clarify
Supplier accessWhich subprocessors can reach buyer data?Current subprocessor list, purpose, location, notice term, and service scopeConfirm, mitigate, or pause
Incident responseWho reports an incident and under which written term?Contract section, named contact route, documented roles and responsibilities, and latest exercise dateQualified review if unclear
OffboardingHow are access and buyer data removed at service end?Account-removal record, return or deletion method, exceptions, and reviewerConfirm before kickoff
Copy-ready worksheet

Keep the answer, evidence, exception, and owner together.

Send sensitive evidence through an approved secure channel. The template only holds review notes and does not upload or save answers.

PROVIDER SECURITY QUESTIONNAIRE

Provider: [Provider name]
Service being reviewed: [Named service or team]
Data and systems in scope: [List]
Buyer reviewer: [Name and role]
Review date: [Date]
Next review date: [Date]

Repeat this block for each question:

CONTROL AREA: [Identity, data, incident response, continuity, supplier access, or offboarding]
QUESTION: [Paste the exact question]
PROVIDER ANSWER: [Written answer]
EVIDENCE: [Policy, dated report, redacted record, test summary, or contract section]
SCOPE: [Service, system, location, staff, and report period covered]
OWNER: [Provider owner and buyer reviewer]
EXCEPTION: [Limit, gap, shared account, excluded system, or subcontractor]
FOLLOW-UP DATE: [Date]
AGREEMENT OR SLA CHANGE: [Describe the change, or none]
REVIEW NEEDED: [Security, privacy, legal, procurement, risk, or none]
DECISION: [Confirmed in writing, needs clarification, not applicable, mitigate, or pause]

QUESTIONS

SERVICE SCOPE AND DATA
1. What customer data and systems will this service access, store, transfer, or delete?
2. Which staff, work locations, devices, and remote-work arrangements are in scope?
3. Who owns security for this service and can answer evidence questions?

IDENTITY AND ACCESS
4. Will each worker and administrator use an individual account, and which MFA methods are required?
5. How are permissions approved, reviewed, changed, and removed?
6. Are any shared accounts needed? If so, what approved exception, attribution, expiry, and rotation rules apply?

PEOPLE AND SUBCONTRACTORS
7. Which roles can access buyer systems or data, and what training or review applies to them?
8. Which subcontractors or subprocessors can reach the service or buyer data?
9. How will the provider tell you when a relevant subcontractor, location, or staffing model changes?

LOGS, VULNERABILITIES, AND TESTING
10. Which logs record account use, access changes, and important security events, and what safe evidence can the provider share?
11. How are vulnerabilities, patches, and important control exceptions tracked for this service?
12. Which audit, certification, or test evidence applies to this exact service, location, and report period?

INCIDENT RESPONSE
13. Who reports a suspected incident, through which route, and under which written notice term?
14. How are relevant records preserved, and who is responsible for each step during an incident?
15. When were the service's response contacts or handoffs last tested?

BACKUPS AND CONTINUITY
16. What is backed up, where is it kept, and which systems are outside that scope?
17. How is recovery tested, and which service did the latest test cover?
18. Who decides whether the provider can use an alternate worker, location, system, or supplier during an outage?

OFFBOARDING AND DATA RETURN
19. How are worker, administrator, supplier, and service accounts removed when scope or staffing changes?
20. How will buyer data be returned or deleted, including copies held by relevant subprocessors?
21. Which evidence confirms removal or deletion, and who reviews unresolved exceptions?

EVIDENCE, EXCEPTIONS, AND THE DECISION
22. Which answer has current evidence that covers the named service?
23. Which gap needs a mitigation owner, agreement term, or qualified review?
24. Is the item confirmed in writing, unclear, not applicable, accepted with mitigation, or paused?

Do not paste passwords, recovery codes, API keys, private keys, live customer records, or other secrets into this document. Use an approved secure channel for sensitive evidence.

This template stays visible and selectable. Nothing is uploaded or saved.

45-minute first pass

Check what the service covers before relying on a certification.

The first pass should expose missing scope and owners. A qualified reviewer can then spend time on the important gaps.

  1. Name the service, data, systems, locations, and provider team you are reviewing.
  2. Send the same questions to each provider and ask for written, scoped answers.
  3. Record the evidence date, service scope, provider owner, exception, and buyer reviewer.
  4. Mark unsupported or disputed answers for clarification instead of filling in the gaps yourself.
  5. Send important gaps to your security, privacy, legal, procurement, or risk owner.
  6. Carry accepted terms into the agreement, onboarding packet, access plan, and next review.
Pause and clarify

Do not treat a broad answer as evidence for this service.

Mark the item for follow-up when the provider cannot show who, what, where, when, and which service the answer covers.

  • The answer covers the provider company but not the service, workers, systems, or location you may use.
  • Administrative access has no named account, MFA rule, approval owner, or review record.
  • A subcontractor can reach buyer data, but its purpose, location, notice rule, or control scope is unclear.
  • Incident language names no reporting route, written commitment, evidence owner, or division of work.
  • A certification or test is offered without its scope, date, assessor, exceptions, or covered service.
  • Backups are mentioned, but no one can show what was restored or when recovery was last tested.
  • The provider cannot explain how accounts are removed or how buyer data is returned or deleted.
Official source notes

Use security guidance to ask better questions, not to claim approval.

These sources support identity, supplier, incident, and service-end questions. They do not certify this worksheet or any provider.

  • NIST Cybersecurity Framework 2.0 covers identity, supplier requirements, incident coordination, and service-relationship planning.
  • NIST SP 800-53 Rev. 5 covers account management, identification, authentication, least privilege, and access removal.
  • CISA guidance on MFA explains why accounts should use more than one way to verify identity and recommends phishing-resistant options where possible.
  • NIST SP 800-161 Rev. 1 covers supplier risk across acquisition, contracts, monitoring, incidents, and the end of a relationship.
  • NIST SP 800-61 Rev. 3 covers incident responsibilities, information flow, coordination, and third-party roles.
Before data or access

Ask the right reviewer to check important gaps.

Bring the named service, open questions, written evidence, exceptions, and proposed agreement changes. Do not send secrets through the contact form.

Build your handoff system

Ready to plan your first offshore role?

Use OutsourcedU to write the role, SOPs, onboarding steps, and weekly review before you hire more people.