Why your vendors hate your questionnaire (and how to fix it)
A 1,764-question spreadsheet is a punishment, not a control. Tailoring by criticality, one question per control theme, and optional certification short-circuits cut it to 140, with a full audit trail for every choice.
Ask any vendor what they think of security questionnaires and you will get the same answer: they are enormous, repetitive and mostly irrelevant to what the vendor actually does. A 1,764-question spreadsheet is not rigour. It is a tax that produces rushed, copy-pasted answers, which is the opposite of assurance. The fix is not a shorter generic questionnaire; it is a questionnaire whose length is a deliberate function of risk.
Depth should follow criticality
A critical cloud-and-payments vendor genuinely warrants deep probing, but at the effectiveness tier, not by asking every policy-level question ever written. A low-criticality advisory firm warrants a short, policy-level set. Same bank, radically different questionnaires. The criticality tier you assigned before questioning is exactly the input that sets the depth: it decides both which control domains are in scope and how demanding the questions within them are.
One question per control theme
Within the scoped domains, ask one question per normalised control theme rather than one per framework or one per tier. Choose the tier depth by criticality: 'is there a policy?' for low risk, 'can you demonstrate it works, with evidence?' for critical. Then round-robin across domains so coverage stays even instead of exhausting one domain before moving on, and cap the total. That is how you get from 3,900 candidate questions down to 140, or to 25, deliberately and repeatably rather than by hand-trimming a spreadsheet.
Certifications can short-circuit whole domains, at your discretion
If a vendor holds SOC 2 or ISO 27001, the domains that certification attests to do not need to be re-interrogated question by question. You can choose to short-circuit those domains and request the report instead. That single move can remove a third of the questionnaire while strengthening the evidence, because a report from an accredited assessor beats a self-attested checkbox.
The important word is choose. Short-circuiting is an option the assessing team controls, not an automatic behaviour. If your policy is to independently verify certain controls regardless of certification, you keep those domains in scope; if you are comfortable relying on the report, you skip them and request it. Either way, the decision is recorded.
Keep the rationale for every choice
Every question that made the cut, and every domain that was skipped, should ship with a one-line reason. When a vendor asks 'why am I being asked this?' the answer is already written. When an auditor asks 'why wasn't this domain covered?' the answer is already written, along with the certification you relied on instead. Tailoring without an audit trail is just guessing at scale. Tailoring with one is defensible diligence, and it is the difference between a questionnaire your vendors tolerate and one they quietly game.
What good tailoring feels like
Done well, tailoring is invisible to the vendor and obvious to the auditor. The vendor receives a questionnaire that is clearly about their business, at a depth that matches how much you depend on them, with no obviously irrelevant sections. The auditor receives a selection they can trace back to a criticality rating and a set of stated rules. Nobody is punished, and nothing important is skipped by accident.
See it in your own portfolio
Full question bank, both portals, and transparent launch pricing by vendor volume.
See launch pricing