River
Y CombinatorBacked by Y Combinator

Software & TechnicalFree

ISO 27001 Vendor Questionnaire Response

A questionnaire answer is a claim about a system, a period and a party. River scopes every one of them to the document behind it.

Start here

River answers the questionnaire in the file it arrived in, from the documents you actually hold. Every row carries the answer, the evidence behind it, and the boundary that evidence draws: which system it covers, which period it covers, and which party performs the control. Where your answer claims more ground than the document supports, the row says so before a reviewer finds it. Where the honest answer is shared, it names the half that belongs to the buyer.

Every guide to this job stops in the same place: build an answer library, cite a document, get it out faster. That advice is correct and it solves the wrong half. A reviewer who receives your answer and your report reads both, and the failure they find is not a missing citation. It is a Yes whose evidence covers a period that ended last spring, a different product, or a control your cloud provider performs and your own report excludes.

Built for the engineer who inherits the security questionnaire because nobody else can answer question 140. Reach for it when the deal is waiting and the evidence is spread across four documents with three different scopes. The vulnerability management pack supplies the finding and remediation evidence these questions ask for, and the commercial response pack runs the buyer-facing process around it. The solution architecture document is where the system boundary you are answering about gets written down once.

Which system, which period, which party

Start with the party. The AICPA's own SOC 2 guide defines the carve-out method as one where the subservice organization's system components are excluded from the description and from the scope of the examination. Only the types of controls that provider is expected to implement get disclosed. Almost every SOC 2 carves out its cloud host. So a Yes on physical datacenter access, evidenced by your report, cites a document that deliberately says nothing about it. The honest answer names your provider's report.

Then the period. A Type 1 report opines on design as of one specified date and makes no statement that a single control operated. A Type 2 covers a stated period. The same guide is blunt about the edge of it: evidence about the satisfactory operation of controls in prior periods does not provide evidence of the operating effectiveness of controls during the current period. Your answer inherits the dates on your evidence whether the row prints them or not, so the row prints them.

The questionnaire usually has a column for this and it sits empty. CSA's Cloud Controls Matrix carries 197 control objectives across 17 domains, and the CAIQ built on it asks 261 questions against them with a control ownership column beside every answer. Six values are available, from provider-owned through shared to customer-owned. A Yes with that column blank reads as a promise to do all of it, which is how a shared control becomes your obligation in someone else's contract.

How it works

  1. Send the questionnaire

    A CAIQ export, an ISO 27001 control sheet, a portal download or the buyer's own spreadsheet.

  2. List your evidence

    Policies, the SOC 2, the certificate and Statement of Applicability, pen test summaries, with their dates.

  3. Name the product

    Which environment the buyer is actually purchasing, because that decides which evidence covers the answer.

  4. Review the exceptions

    Answers land filled; you read the scope verdicts, the shared controls and the open questions.

What you get

  • Every question answered inside the workbook that arrived, keeping its layout and its identifiers
  • The evidence document, section and date behind each answer, printed on the row itself
  • A scope verdict per answer: covered, carved out, out of period, or design only
  • Control ownership stated per question, so a shared control never reads as a sole promise
  • The obligations your report puts on the buyer, extracted and handed over up front
  • The questions only your live configuration can settle, routed with the context to settle them

Common questions

We already have an answer library. Why not just autofill it?

Because a library stores answers, not their scope. The row that was true in March cites a report whose period has closed, a product you have since split in two, or a control you have moved to a managed service. Autofill reproduces the sentence and drops the boundary, which is the part a reviewer checks first.

What does it do when the honest answer is No?

Writes No, then writes what is true instead: the compensating control you do run, the recorded reason the control sits outside your Statement of Applicability, or the date the work lands. A justified exclusion and an unaddressed gap read identically as a bare No, and only one of them costs you the deal.

We only have a Type 1 report so far. Is that a problem?

It is a scope fact rather than a problem, and stating it is what keeps the answer defensible. A Type 1 opinion covers design as of one date, so answers resting on it say the control is designed and implemented rather than tested over time. Reviewers accept that. What they reject is finding it out themselves.

Our buyer sent a CAIQ. Does the answer vocabulary matter?

It carries meaning the sheet itself defines. CSA's questionnaire treats NA as out of scope for the assessment, with ownership left blank, while No means in scope and not implemented. Those are different claims about your business, so answers go in using the vocabulary of the file rather than a house style.

Why would we tell the buyer what they have to do?

Because your own report already names it. It lists the controls it assumed your customers would implement, which is a set of things the buyer must do for your commitments to hold. That list normally sits unread in section three and surfaces in week two of their rollout. Handing it over with the answers moves the conversation to implementation.

Which questions get routed rather than answered?

The ones turning on live configuration rather than policy: current retention windows, whether a region encrypts with customer-managed keys, the real version of a runtime, which open source packages actually ship. Each goes out with the question verbatim, the control it maps to and what is actually being asked. Where nobody can say what is deployed, the architecture reconstruction answers that first.

Does the same answer work for the next questionnaire?

The scoped version does; the bare one never did. An answer carrying its evidence, its period and its ownership can be re-checked against a newer report in seconds, because you can see which fact changed. Incident questions work the same way, which is why the postmortem record is the evidence behind them rather than a recollection.

ISO 27001 Vendor Questionnaire Response

Fill in the form and your workspace opens with the work already underway.