Home
›
Magazine
›
Vendor Security Questionnaire: Answers for Awareness Tools
Vendor Security Questionnaire: Answers for Awareness Tools

Vendor Security Questionnaire: Answers for Awareness Tools

September 28, 2026
7 min
Lana Kuzmina
Cyber Threat Analyst
lana

A 15-question shortlist mapped to SIG Lite and CAIQ, with the target answer on each line, so a security awareness review closes in days rather than weeks.

Table of contents

Get started
with revel8

  • Security questionnaires are the longest step in awareness procurement, with review cycles running into weeks while evidence is verified by hand.
  • SIG Lite condenses SIG Core to roughly 126 questions, which makes it the practical screen for a SaaS awareness tool.
  • CAIQ v4 runs to 261 questions and CAIQ-Lite to 124, both mapped to the same 17 cloud control domains.
  • A compliant European platform must confirm contractually that customer data never trains its underlying AI models.
  • German data residency on sovereign infrastructure such as STACKIT shortens works council approval and simplifies the Article 44 transfer question.

Why security questionnaires stall awareness procurement

Security questionnaires are routinely the longest step in security awareness procurement. Compliance teams report spending tens of hours completing a single CAIQ or SIG response, and review cycles commonly run for weeks while evidence is verified by hand. For lean security teams, generic IT questionnaires rarely map to the technical realities of modern attack simulation.

Traditional awareness platforms shipped static templates over simulated email. Modern platforms use open-source intelligence to mirror real threat actors and synthesise attacks across email, SMS, voice cloning and deepfake video. That introduces risk domains a standard questionnaire does not isolate: dynamic prompt generation, third-party speech synthesis, and the handling of publicly sourced employee identity data.

Buyers therefore need to interrogate how these systems process corporate context, not just tick baseline controls. Pairing the questionnaire with a structured awareness RFP framework separates table stakes from genuine safeguards before negotiations stall.

  • Reconnaissance boundaries: whether OSINT collection stays within public footprint mapping or reaches unauthorised corporate assets.
  • Multi-channel architecture: how voice synthesis and message generation handle employee identifiers across external telephony APIs.
  • AI execution boundaries: whether generative components run inside an isolated tenant perimeter or against shared third-party model endpoints.

SIG Lite: the assessment most SaaS buyers send

The Standardized Information Gathering questionnaire, maintained by Shared Assessments, is a cornerstone of third-party risk management[1]. In the current release, SIG Core runs to roughly 855 questions across its risk domains, and SIG Lite condenses that to about 126 for SaaS applications and specialised service providers. Shared Assessments revises the question set annually, so confirm which version a vendor has completed before comparing two responses side by side.

For awareness platforms, SIG Lite inspects the architectural safeguards that matter without burying the team in redundant administrative checks.

SIG Lite domainEvaluation focusTarget vendor control
Access controlIdentity governance and administrative sessionsSSO via SAML 2.0, automated provisioning via SCIM
Cloud servicesInfrastructure hardening and deployment boundariesTenant data segmentation and encrypted backups
Threat managementVulnerability management and testing cadenceAnnual third-party penetration tests with remediation SLAs
Privacy managementData minimisation and employee privacyGroup-level hashing and anonymisation on by default

CAIQ answers for SaaS awareness platforms

The Cloud Security Alliance publishes the Consensus Assessments Initiative Questionnaire to establish objective transparency across cloud services. Developed alongside the Cloud Controls Matrix, CAIQ maps its questions directly to cloud security controls[2]. CAIQ v4 comprises 261 questions; CAIQ-Lite condenses these to 124 across the same 17 control domains for a faster high-level review[3]. Responses filed to the CSA STAR registry let a buyer verify control claims independently.

Two domains deserve rigorous verification for awareness tools: multi-tenant isolation and supply chain oversight. These platforms hold employee directories, simulation history and behavioural risk scores. If tenant boundaries are porous or sub-processors unvetted, cross-customer leakage becomes a severe liability.

  • Tenant segregation enforced at both database and application layers, with no cross-tenant indexing.
  • AES-256 at rest and TLS 1.3 in transit, with dedicated key management.
  • Documented technical and organisational measures covering every downstream provider, bound by data processing agreements.

Data residency in Germany and works council approval

Data residency decides more procurement outcomes in DACH than any other single criterion. Many global vendors offer European hosting while their parent entity remains subject to extraterritorial access law. Under Article 44 GDPR, any international transfer must not undermine the level of protection guaranteed by EU law[4].

That obligation needs a rigorous DACH compliance evaluation wherever employee behaviour is tracked. In Germany the works council holds mandatory co-determination rights under Section 87(1) No. 6 BetrVG over any technical system suitable for monitoring employee conduct or performance. Platforms hosted on US hyperscalers routinely face extended works council review over CLOUD Act jurisdiction and individual surveillance.

Sovereign German hosting, audited against the BSI Cloud Computing Compliance Criteria Catalogue (C5), gives that review an auditable baseline[5].

  • Sovereign infrastructure: core applications and databases on German sovereign cloud, such as STACKIT on Schwarz Gruppe infrastructure, removing exposure to extraterritorial discovery.
  • Works council readiness by default: group-level anonymisation with a minimum cohort of five, which prevents individual surveillance and shortens Betriebsvereinbarung negotiation.
  • Regulatory alignment: conformance with NIS-2 supervisory requirements and ISO 27001 governance.

ISO 27001:2022 and AI model safety

A certified information security management system gives third-party verification that a vendor runs disciplined governance. ISO/IEC 27001:2022 restructured Annex A into 93 controls across four themes, and added controls such as A 5.7 threat intelligence, A 8.10 information deletion and A 8.11 data masking, which makes it the reference point for ISO 27001 and NIS-2 supply chain verification.

For platforms that use large language models to synthesise lures, the certificate has to be paired with explicit contractual AI governance. The certificate proves process discipline; it does not by itself say where inference runs or what happens to the prompt.

Questionnaire domainRequirementExpected vendor answer
Annex A 5.19 to 5.22, supplier securitySupply chain risk managementFull sub-processor disclosure and monitored SLAs
Annex A 8.11, data maskingProtection of employee identifiersPseudonymised hashing before simulation logs reach dashboards
AI model training boundariesZero data contaminationContractual guarantee that customer data never trains or fine-tunes models
AI infrastructure localitySovereign execution perimeterInference hosted on sovereign European infrastructure

A 15-question shortlist for vendor review

To compress the review without losing scrutiny, issue a focused 15-question set mapped to SIG Lite and CAIQ control categories. Each line names the answer to look for.

  1. Where are customer data, databases and application workloads physically hosted? Target: sovereign data centres in Germany or the EU.
  2. Does the vendor hold an accredited ISO/IEC 27001:2022 certificate covering all platform services? Target: yes, audited by an independent accredited body.
  3. How is logical tenant isolation enforced across application and storage layers? Target: row-level security and isolated encryption keys per tenant.
  4. Are customer inputs, employee names or simulation metrics used to train or fine-tune AI models? Target: explicit contractual guarantee of zero model training on customer data.
  5. Where are generative AI and inference workloads processed? Target: dedicated European sovereign infrastructure.
  6. Does the platform support SCIM 2.0 provisioning and SAML 2.0 SSO? Target: out-of-the-box integration with Microsoft Entra ID and Google Workspace.
  7. Which personal data attributes are strictly required to operate? Target: minimised to name, email, department and language.
  8. How does reporting protect employee privacy and satisfy the works council? Target: group-level anonymisation with a minimum cohort of five.
  9. What is the incident notification protocol and SLA? Target: written customer notification within 24 to 48 hours of a confirmed incident.
  10. Does the vendor provide audit-ready logs for NIS-2 and ISO 27001 verification? Target: immutable logging of simulations, interactions and completions.
  11. How are sub-processors managed, monitored and audited? Target: transparent registry with DPAs and annual reviews.
  12. What cryptographic standards protect data in transit and at rest? Target: TLS 1.3 and AES-256.
  13. How often are third-party penetration tests conducted? Target: annually, with an executive summary available on request.
  14. What is the deletion procedure at contract termination? Target: cryptographic erasure of tenant data within 30 days.
  15. Does the platform integrate threat reporting into client mail applications? Target: native Outlook and Gmail reporting that feeds SOC workflows.

revel8 is built to answer these out of the box: hosted on sovereign STACKIT infrastructure in Germany, ISO/IEC 27001:2022 certified, with no customer data used to train models, works council privacy thresholds on by default, and risk monitoring and mitigation that turns employee reporting into an active detection layer. If you are working through a questionnaire now, our team can walk through these answers against your own control set.

Sources

  1. Standardized Information Gathering (SIG) Questionnaire, Shared Assessments
  2. What is CAIQ?, Cloud Security Alliance
  3. CCM-Lite and CAIQ-Lite, Cloud Security Alliance
  4. Art. 44 GDPR: General principle for transfers, GDPR-info
  5. C5 criteria catalogue, BSI

FAQ

What is a vendor security questionnaire?

A standardised set of questions used to evaluate how a third-party vendor handles security, protects employee data and manages cyber risk before a contract is signed.

What is the difference between SIG Core and SIG Lite?

SIG Core is the full Shared Assessments question set, running to roughly 855 questions in the current release. SIG Lite condenses it to about 126 for faster screening of lower-risk software. The question count changes with each annual revision, so check which version a response covers.

How many questions are in CAIQ?

CAIQ v4 comprises 261 questions mapped to the Cloud Controls Matrix. CAIQ-Lite condenses these to 124 across the same 17 control domains for a quicker high-level review.

Why is ISO 27001:2022 important for awareness platforms?

The 2022 revision restructured Annex A into 93 controls and added supply chain and cloud controls, so the certificate evidences that the vendor manages information security across its operations. It does not by itself say where AI inference runs, which needs a separate contractual answer.

Do awareness vendors train AI on our company data?

That has to be answered contractually rather than assumed. A compliant enterprise platform states explicitly in its questionnaire response that customer data is never used to train or fine-tune the underlying models.

How does German data residency speed up procurement?

Hosting on a sovereign German cloud addresses works council privacy concerns and the Article 44 transfer question upfront, which removes the two objections that most often extend a review.

Sources

Related Articles

White abstract curved shape with jagged edges on a black background.

Ready to defend against
AI-powered attacks?

‍
‍