The regulation requires measures appropriate to the risk, and the questionnaire is how a buyer finds out what a supplier means by appropriate.
Why it matters when the plan changes
The questionnaire is usually the first place a buyer's security team meets a supplier, and it sets the terms of trust for the relationship. Article 32 of the General Data Protection Regulation requires measures appropriate to the risk, and the questionnaire is the practical test of that abstract standard. Answers that are accurate, specific and honest about gaps produce a security review that ends. Answers that read as marketing produce a longer review and a reputation for evasion that outlasts the deal.
The tension is that questionnaires are written for large, certified suppliers, and their yes-or-no format has no box for an honest intermediate answer. A young supplier with strong practice and no certificate is pushed toward a misleading yes or a damaging no. An independent security audit, defined as a review of an organisation's security level, records and activities, tests what the questionnaire only claims; the way through is to answer in prose where the form does not fit, and to say exactly what evidence exists.
In practice
A supplier answers a two-hundred-question form with yes wherever it can defend the word. The buyer's security team samples ten answers and asks for evidence. Eight are supported and two turn out to describe intentions. The two cost the supplier more credibility than eight honest partial answers would have, and the review restarts from a position of doubt.
Evidence
Controllers and processors must implement technical and organisational measures appropriate to the risk.
Article 32, General Data Protection Regulation (2016)An information security audit is an independent review of an organisation's security level, records and activities.
Information security audit, Wikipedia (2026)
What it cannot tell you
A questionnaire records what a supplier states about its own practice; it does not verify that the practice exists or works as described. It is silent on execution quality, on how controls perform under real incidents, and on anything a supplier chooses not to disclose. It cannot substitute for independent testing or audit.
Questions
Questionnaires usually cover certifications and audits, access control and authentication, encryption at rest and in transit, network security, logging and monitoring, incident response, business continuity, sub-processors and hosting, secure development practice, penetration testing, and data handling including retention and deletion, all mapped to the technical and organisational measures required under Article 32 of the General Data Protection Regulation (2016).
In prose, stating what exists, what its limits are and what is planned with a timeframe. A no with an explanation is a better answer than a yes that has to be walked back, because a security team can work with an honest gap and cannot work with a discovered overstatement.
No. A questionnaire is self-reported, and its value depends on the evidence behind each answer. Independent verification, such as the information security audit described on Wikipedia in 2026 as a review of an organisation's security level, records and activities, is what actually confirms the claims a questionnaire only asks about.
Because they are long, generic and written for suppliers of a different size, and because each answer can trigger a follow-up. Suppliers that keep a maintained answer bank with evidence attached, and buyers that accept prose where the form does not fit, cut the time dramatically.
Specific answers with evidence offered before it is asked for, explicit statements of limits, a named person for follow-up, and consistency between the questionnaire, the processing agreement and the sub-processor list. Inconsistency between documents is the fastest way to lose a reviewer's confidence.