FREE WORKSHEET · FOR B2B SOFTWARE AND SERVICE SUPPLIERS

Security questionnaire checklist.
Know what supports every answer.

A buyer review gets difficult when an approved answer no longer fits the product or use case. Use these six checks to identify the evidence, limitation and decision needed to finish one question.

No email required. Work in your own approved workspace; do not send sensitive evidence with an initial inquiry.

Six checks before the response leaves your team.

  1. Define the service being reviewed

    Which product, environment, data flow and buyer use case does this questionnaire cover?

    Record the deadline, required response format and reviewer. An answer about another product or environment needs a fresh applicability check.

    Leave with: A scope statement the response owner can confirm.

  2. Match each answer to current evidence

    What supports the exact claim, and does it apply to this scope?

    Record the source, version or date, evidence owner and relevant limitation. A policy describes intended practice; it may not establish what is operating in this environment.

    Leave with: A source reference and a clear limit for each material answer.

  3. Separate supported answers from open gaps

    Can the evidence support the whole answer, only part of it, or neither?

    Keep unsupported facts open. If the buyer's form forces a yes/no choice, have the accountable reviewer decide how to express the limitation in the permitted format.

    Leave with: An explicit gap, clarification or scoped exception instead of a guessed answer.

  4. Give every unresolved item an owner

    Who can provide the missing fact or authorize the proposed response?

    Name the next action, due date and decision owner. Distinguish a planned fix from a completed control; do not promise delivery dates on another team's behalf.

    Leave with: A short action list with accountable owners and review dates.

  5. Approve the exact response and attachments

    Has the authorized person reviewed this version, its limitations and what may be shared?

    Check that the exported answer matches the approved wording and evidence. Confirm permitted recipients and sharing conditions before anyone returns the package.

    Leave with: An attributable approval of the response version being returned.

  6. Keep the return and follow-up record

    What was returned, what did the buyer ask next, and what change would reopen an answer?

    Keep the returned version, date and any acknowledgement. Record acceptance separately: a successful upload or email does not establish the buyer's decision.

    Leave with: A review record that can be checked when the service or evidence changes.

The policy says backups are encrypted. The service scope is unclear.

A buyer asks whether all backups for the reviewed service are encrypted. The answer library says yes, but the available policy does not identify that service's backup environment.

What is known
The policy describes encryption as a requirement. It does not establish the current configuration for this service.
What is missing
Applicable configuration evidence, its date, the responsible owner and any exceptions.
What happens next
The owner verifies the environment. The response approver decides the wording and limitation before it is returned in the buyer's required format.

That is a bounded case to investigate. It is not a reason to reuse an unsupported yes.

See a synthetic buyer-review workflow

Practical questions.

We already have a trust center. Is this still useful?

Yes, when a question needs more than an approved reusable answer. Use the checklist for product-specific scope, missing evidence, exceptions and approval. Keep your existing systems as the authoritative source for the records they own.

Can we complete the worksheet ourselves?

Yes. The checklist and Markdown worksheet are free, with no registration or email gate. Start with one difficult question and keep any populated worksheet in your own approved workspace.

When does paid help make sense?

When the review has a deadline, a response owner and a difficult question that needs investigation or coordinated decisions. THONIS offers a free written fit review first. Any paid diagnostic or sprint has an agreed scope, fee and acceptance criteria.

Does this replace a required independent assessment?

No. It does not issue a SOC report, ISO certificate, penetration-test report or other independent assurance result. The qualified provider still performs any work your contract requires; the buyer retains its acceptance decision.

Need help with the answer that is holding up the review?

Describe the blocked question, product scope, deadline and response owner. Start with a free written fit review; a call is optional. Do not attach sensitive records.