← All Tools

📝 Vendor Risk Questionnaire Generator

Build a tailored third-party security questionnaire from curated banks of questions. Useful for new-supplier due diligence, periodic reviews, DORA Article 28 assessments, NIS2 supply-chain due diligence, or GDPR processor onboarding.

100% client-side. No vendor data is stored or transmitted. The tool only generates a question template — you collect answers in your own GRC, spreadsheet, or workflow tool.

Vendor profile

Hold Ctrl/Cmd to select multiple.

Question banks to include

Regulatory overlays

Questionnaire


                    

Tips

  • Match your question depth to vendor criticality — over-engineered checklists for low-risk vendors are why TPRM dies.
  • Ask for evidence with deadlines: SOC 2 / ISO 27001 cert (current), pen-test summary (within 12 months), DPA / SCCs as applicable.
  • Track residual risks and remediation actions in a register, not the questionnaire itself.
  • Re-assess high/critical vendors annually and on any material event.