Security Questionnaire Response Template
Four sheets and four documents that answer a buyer's questionnaire inside their own file, then name every answer with no document behind it.
Free download · No account needed
Evidence Gap Memo
Arcwell Systems, CAIQ v4.0.3 returned to Calder Mutual
| Sheet as it arrived | 261 questions, 17 control domains |
| Substantive answers | 238 Yes or No |
| Evidenced | 74, each naming a document |
| Described only | 121, prose with nothing nameable |
| Bare assertion | 43, a Yes and nothing else |
1. Fix before it goes out
| ID | Domain | What is wrong |
|---|---|---|
| IAM-14.1 | Identity & Access | Yes, no description, no document |
| CEK-03.1 | Cryptography | Names Encryption Standard v2, register holds v4 |
| LOG-05.1 | Logging | Names a runbook nobody can release |
2. Disclose in the covering note
Eleven answers describe a control accurately and have no document to attach. They are listed by domain in the Submission Note rather than written to look evidenced.
A bare Yes is a gap, not an answer
Every answer in Evidence Coverage is one of four things: evidenced, described only, bare assertion, or gap. Nothing in this file asserts a control the company cannot produce a document for.
3. Questions with no counterpart in your history
Nine of the 261 have never been answered before, all in Supply Chain and Universal Endpoint. They are routed to owners, not guessed.
A completed security questionnaire is mostly assertion. Across 120 finished CAIQs published in the Cloud Security Alliance's own STAR Registry, 32,506 questions in all, 89.8% of the substantive Yes and No answers name no supporting document. The justification column is entirely empty on 59.1% of rows, and an actual filename appears 25 times in the whole corpus. The reviewer reading your sheet is reading claims, and the document behind each claim sits in a drive nobody named.
Not that nobody thought to ask. CSA's own CAIQ v4 workbook marks its description column optional and recommended, and defines it as a description with references. The harder problem is that the questionnaire is not one questionnaire. Those 120 files declare seven versions of the same standard and six different question counts, and they carry 536 distinct question IDs between them. Only 89 of those IDs appear in every version, so a bank built on one version covers under a third of the next sheet that arrives.
So this pack answers inside the file that arrived, in its layout and version, and then audits itself. Every substantive answer lands in Evidence Coverage as evidenced, described only, bare assertion or gap, and the gap memo separates what to fix from what to disclose. The documents those answers cite are dated and scoped in the trust package, and the certificates, tax forms and registrations asked alongside them live in a separate register. The questionnaire rarely arrives alone, so the privacy annex, the contract review and the redlines that follow are their own jobs.
What's in the pack
Answered Questionnaire
The buyer's own file answered in place, their columns and their answer vocabulary kept, with the detected layout and version recorded.
Evidence Coverage
One row per substantive answer, scored evidenced, described only, bare assertion or gap, with the named document and whether it is current and releasable.
Question Map
Every arriving question matched to your history by control identity rather than ID string, with the match method and confidence recorded per row.
Open Questions by Owner
The questions nobody can answer from paper, grouped by the person who can, with days open and whether the answer is blocking submission.
Evidence Gap Memo
The internal document: what to fix before sending, what to disclose, and which questions have no counterpart in anything you have answered before.
Response Standard
Answer vocabulary, when an answer needs a named document, what counts as a nameable document, and what may never be asserted without one.
Escalation Note
The question verbatim with its control ID, what is actually being asked, and the deal date behind it, so an engineer answers without a meeting.
Submission Note
The covering document: what is enclosed, which answers were NA and why, how to request documents under NDA, and the gaps volunteered up front.
How to use it
- 1
Open in River, or take it blank
Open the pack in River and hand it the questionnaire, or download the Word documents and CSV sheets and fill them in yourself.
- 2
Send the file that arrived
A CAIQ export, a SIG spreadsheet, a portal download, a bespoke sheet from the buyer's own security team. The layout and version get detected, not assumed.
- 3
Match, then draft in place
Prior answers are matched by control identity across versions. Answers go back into their columns, naming the supporting document wherever one exists.
- 4
Audit before you send
Evidence Coverage scores every substantive answer, the gap memo ranks what to fix, and the unresolved questions go out to named owners with a date.
Frequently asked questions
Is this template free?
Yes. The zip is Word documents and CSV sheets, no account and no card. Edit with AI is the optional half: River reads your questionnaire and your policy set, fills the sheets, and writes the gap memo. The other packs sit in the template library, and the single-output jobs in the tool library.
What format are the downloaded files?
Word (.docx) for the four documents, CSV (.csv) for the four sheets, zipped together. Excel, Numbers and Google Sheets open the sheets straight off the download. Nothing needs converting, and your buyer's workbook is never converted either: answers go back into the file they arrived in.
Our buyer sent their own spreadsheet, not a CAIQ. Does that work?
That is the normal case. The pack reads whatever arrived, finds the question column, the answer column or columns and the free-text column, records the declared version, and answers in place. Among 120 filed CAIQs there are seven declared versions, six question counts and two incompatible answer encodings, so nothing is assumed.
What counts as naming a document?
A filename, a titled policy or standard, a dated audit report, or a URL somebody can actually request. "We follow industry best practice" is not one. Any answer with nothing nameable behind it is written as a bare assertion in Evidence Coverage rather than dressed up as an evidenced one.
We answered a questionnaire last year. Can we reuse those answers?
The Question Map matches this sheet against your history by CCM control ID first, then by control identity across versions, then by question text, recording which method matched. Across the v3 to v4 boundary the reusable share averages about a third, so unmatched questions are named rather than approximated. The whole back catalogue is a separate pass through the answer bank build.
What happens to questions only engineering can answer?
Questions turning on current system configuration get escalated rather than inferred. They land in Open Questions by Owner with the question verbatim, its control ID and the date the deal needs it, and the Escalation Note gives each owner enough context to answer without a meeting.
Do we need a SOC 2 report before this is useful?
No. The pack works from whatever you hold: policies, a pen test summary, a SOC 2 report if you have one. What it will not do is answer as though a document exists when it does not. Missing evidence becomes a gap row and a line in the Submission Note.
Answer in their sheet, and know what you cannot evidence
Take the Word documents and CSV sheets blank, or open this exact pack in River and let it read the questionnaire first.
Edit with AI