Why security questionnaires stall awareness procurement
Security questionnaires are routinely the longest step in security awareness procurement. Compliance teams report spending tens of hours completing a single CAIQ or SIG response, and review cycles commonly run for weeks while evidence is verified by hand. For lean security teams, generic IT questionnaires rarely map to the technical realities of modern attack simulation.
Traditional awareness platforms shipped static templates over simulated email. Modern platforms use open-source intelligence to mirror real threat actors and synthesise attacks across email, SMS, voice cloning and deepfake video. That introduces risk domains a standard questionnaire does not isolate: dynamic prompt generation, third-party speech synthesis, and the handling of publicly sourced employee identity data.
Buyers therefore need to interrogate how these systems process corporate context, not just tick baseline controls. Pairing the questionnaire with a structured awareness RFP framework separates table stakes from genuine safeguards before negotiations stall.
- Reconnaissance boundaries: whether OSINT collection stays within public footprint mapping or reaches unauthorised corporate assets.
- Multi-channel architecture: how voice synthesis and message generation handle employee identifiers across external telephony APIs.
- AI execution boundaries: whether generative components run inside an isolated tenant perimeter or against shared third-party model endpoints.
SIG Lite: the assessment most SaaS buyers send
The Standardized Information Gathering questionnaire, maintained by Shared Assessments, is a cornerstone of third-party risk management[1]. In the current release, SIG Core runs to roughly 855 questions across its risk domains, and SIG Lite condenses that to about 126 for SaaS applications and specialised service providers. Shared Assessments revises the question set annually, so confirm which version a vendor has completed before comparing two responses side by side.
For awareness platforms, SIG Lite inspects the architectural safeguards that matter without burying the team in redundant administrative checks.
| SIG Lite domain | Evaluation focus | Target vendor control |
|---|---|---|
| Access control | Identity governance and administrative sessions | SSO via SAML 2.0, automated provisioning via SCIM |
| Cloud services | Infrastructure hardening and deployment boundaries | Tenant data segmentation and encrypted backups |
| Threat management | Vulnerability management and testing cadence | Annual third-party penetration tests with remediation SLAs |
| Privacy management | Data minimisation and employee privacy | Group-level hashing and anonymisation on by default |
CAIQ answers for SaaS awareness platforms
The Cloud Security Alliance publishes the Consensus Assessments Initiative Questionnaire to establish objective transparency across cloud services. Developed alongside the Cloud Controls Matrix, CAIQ maps its questions directly to cloud security controls[2]. CAIQ v4 comprises 261 questions; CAIQ-Lite condenses these to 124 across the same 17 control domains for a faster high-level review[3]. Responses filed to the CSA STAR registry let a buyer verify control claims independently.
Two domains deserve rigorous verification for awareness tools: multi-tenant isolation and supply chain oversight. These platforms hold employee directories, simulation history and behavioural risk scores. If tenant boundaries are porous or sub-processors unvetted, cross-customer leakage becomes a severe liability.
- Tenant segregation enforced at both database and application layers, with no cross-tenant indexing.
- AES-256 at rest and TLS 1.3 in transit, with dedicated key management.
- Documented technical and organisational measures covering every downstream provider, bound by data processing agreements.
Data residency in Germany and works council approval
Data residency decides more procurement outcomes in DACH than any other single criterion. Many global vendors offer European hosting while their parent entity remains subject to extraterritorial access law. Under Article 44 GDPR, any international transfer must not undermine the level of protection guaranteed by EU law[4].
That obligation needs a rigorous DACH compliance evaluation wherever employee behaviour is tracked. In Germany the works council holds mandatory co-determination rights under Section 87(1) No. 6 BetrVG over any technical system suitable for monitoring employee conduct or performance. Platforms hosted on US hyperscalers routinely face extended works council review over CLOUD Act jurisdiction and individual surveillance.
Sovereign German hosting, audited against the BSI Cloud Computing Compliance Criteria Catalogue (C5), gives that review an auditable baseline[5].
- Sovereign infrastructure: core applications and databases on German sovereign cloud, such as STACKIT on Schwarz Gruppe infrastructure, removing exposure to extraterritorial discovery.
- Works council readiness by default: group-level anonymisation with a minimum cohort of five, which prevents individual surveillance and shortens Betriebsvereinbarung negotiation.
- Regulatory alignment: conformance with NIS-2 supervisory requirements and ISO 27001 governance.
ISO 27001:2022 and AI model safety
A certified information security management system gives third-party verification that a vendor runs disciplined governance. ISO/IEC 27001:2022 restructured Annex A into 93 controls across four themes, and added controls such as A 5.7 threat intelligence, A 8.10 information deletion and A 8.11 data masking, which makes it the reference point for ISO 27001 and NIS-2 supply chain verification.
For platforms that use large language models to synthesise lures, the certificate has to be paired with explicit contractual AI governance. The certificate proves process discipline; it does not by itself say where inference runs or what happens to the prompt.
| Questionnaire domain | Requirement | Expected vendor answer |
|---|---|---|
| Annex A 5.19 to 5.22, supplier security | Supply chain risk management | Full sub-processor disclosure and monitored SLAs |
| Annex A 8.11, data masking | Protection of employee identifiers | Pseudonymised hashing before simulation logs reach dashboards |
| AI model training boundaries | Zero data contamination | Contractual guarantee that customer data never trains or fine-tunes models |
| AI infrastructure locality | Sovereign execution perimeter | Inference hosted on sovereign European infrastructure |
A 15-question shortlist for vendor review
To compress the review without losing scrutiny, issue a focused 15-question set mapped to SIG Lite and CAIQ control categories. Each line names the answer to look for.
- Where are customer data, databases and application workloads physically hosted? Target: sovereign data centres in Germany or the EU.
- Does the vendor hold an accredited ISO/IEC 27001:2022 certificate covering all platform services? Target: yes, audited by an independent accredited body.
- How is logical tenant isolation enforced across application and storage layers? Target: row-level security and isolated encryption keys per tenant.
- Are customer inputs, employee names or simulation metrics used to train or fine-tune AI models? Target: explicit contractual guarantee of zero model training on customer data.
- Where are generative AI and inference workloads processed? Target: dedicated European sovereign infrastructure.
- Does the platform support SCIM 2.0 provisioning and SAML 2.0 SSO? Target: out-of-the-box integration with Microsoft Entra ID and Google Workspace.
- Which personal data attributes are strictly required to operate? Target: minimised to name, email, department and language.
- How does reporting protect employee privacy and satisfy the works council? Target: group-level anonymisation with a minimum cohort of five.
- What is the incident notification protocol and SLA? Target: written customer notification within 24 to 48 hours of a confirmed incident.
- Does the vendor provide audit-ready logs for NIS-2 and ISO 27001 verification? Target: immutable logging of simulations, interactions and completions.
- How are sub-processors managed, monitored and audited? Target: transparent registry with DPAs and annual reviews.
- What cryptographic standards protect data in transit and at rest? Target: TLS 1.3 and AES-256.
- How often are third-party penetration tests conducted? Target: annually, with an executive summary available on request.
- What is the deletion procedure at contract termination? Target: cryptographic erasure of tenant data within 30 days.
- Does the platform integrate threat reporting into client mail applications? Target: native Outlook and Gmail reporting that feeds SOC workflows.
revel8 is built to answer these out of the box: hosted on sovereign STACKIT infrastructure in Germany, ISO/IEC 27001:2022 certified, with no customer data used to train models, works council privacy thresholds on by default, and risk monitoring and mitigation that turns employee reporting into an active detection layer. If you are working through a questionnaire now, our team can walk through these answers against your own control set.
Sources
- Standardized Information Gathering (SIG) Questionnaire, Shared Assessments
- What is CAIQ?, Cloud Security Alliance
- CCM-Lite and CAIQ-Lite, Cloud Security Alliance
- Art. 44 GDPR: General principle for transfers, GDPR-info
- C5 criteria catalogue, BSI

.avif)



