Vendor questionnaires are useful compliance evidence, especially for contractual attestation, control design and accountability, but they are point-in-time and self-reported. NIS2 and DORA require organisations to maintain ongoing risk management and supplier oversight, so questionnaires need to sit alongside continuous evidence, monitoring and documented follow-up.
A questionnaire can document what a supplier says about its controls. Regulatory compliance also requires evidence that supplier risk is understood, monitored, and acted on over time.
That distinction matters for NIS2 and DORA. A completed form may support due diligence at onboarding, yet it cannot show what changed three months later, whether the supplier relationship evolved, or whether an external exposure appeared after the assessment.
A defensible programme uses questionnaires for the evidence they are good at collecting, then keeps the risk picture current with monitoring, validation, and documented decisions.
What vendor questionnaires are good for
Vendor questionnaires are useful for collecting supplier-declared evidence about policies, control design, certifications, responsibilities, and contractual commitments. They create a structured record of what the supplier has attested to and give risk teams a consistent basis for due diligence and follow-up.
Questionnaires earned their place in third-party risk management because many important controls cannot be observed from outside a supplier environment. A supplier can describe how privileged access is managed, which standards it follows, how incidents are escalated, where data is processed, and who owns specific responsibilities.
That evidence supports several practical parts of the supplier lifecycle:
- Contractual attestation. The supplier formally states how particular controls, processes, and obligations are handled.
- Control design. Security and risk teams can understand policies and safeguards that are invisible to external assessment.
- Accountability. Responses create a documented basis for clarifications, remediation commitments, and contractual requirements.
- Standardised due diligence. Frameworks such as SIG can make assessment more consistent across a large vendor population.
This fits naturally into a broader third-party risk management lifecycle where due diligence, contracting, monitoring and offboarding each produce different forms of evidence.
Where questionnaires fail as compliance evidence
Questionnaires become weak compliance evidence when they are treated as a complete record of supplier risk. They capture a supplier response at a specific moment, rely heavily on self-reporting, can be difficult to verify, and often age faster than formal reassessment cycles can keep up with.
The issue is less about the questionnaire itself and more about what happens after it is completed. A 200-question assessment can be thorough on the day it is submitted and still provide little evidence about the supplier six months later.
The main reasons why they fall short when treated as the only source:
1. They are point-in-time
A questionnaire records what was true, or what the supplier believed was true, when the answers were submitted. Cloud infrastructure, software, ownership, subcontractors, and exposed services can change between review cycles.
2. They are self-reported
The supplier controls the answer. Most programmes still need a way to validate material claims, especially where an answer affects supplier tiering, remediation or acceptance of residual risk.
3. Verification is uneven
Some answers can be supported with certifications, policies, test reports, or technical evidence. Others remain difficult to verify because the relevant controls are internal or because the organisation lacks independent telemetry.
4. Response friction limits coverage
Long assessments consume time on both sides. High-friction processes encourage lighter reviews for lower-tier suppliers and can delay reassessment when the vendor population is large.
The compliance gap appears when the organisation can show that a questionnaire was sent, yet cannot show how supplier risk was monitored after the response arrived.
What NIS2 and DORA expect that a questionnaire cannot produce
NIS2 and DORA place supplier risk inside an ongoing risk management process. A questionnaire can contribute evidence, but the wider programme needs current inventories, risk-based oversight, documented decisions, monitoring of relevant changes, and evidence that issues were followed through over time.
NIS2 makes supply chain security part of the cybersecurity risk management measures expected from essential and important entities. The practical evidence goes beyond a completed assessment: teams need to know which suppliers matter, how risks are handled, and how the programme stays current as dependencies and exposures change.
ThingsRecon's evidence-based NIS2 guidance frames this around identifiable suppliers and assets, continuous oversight, documented risk decisions and evidence that can be traced back to the underlying finding.
DORA is even more explicit for financial entities because ICT third-party risk sits inside the wider digital operational resilience framework. Organisations need visibility across ICT services and dependencies, ongoing oversight, contractual governance and records that support the management of third-party risk throughout the relationship lifecycle.
A questionnaire alone struggles to demonstrate several things a reviewer may reasonably ask for:
- what changed in a supplier's external exposure after onboarding
- which suppliers support critical or important services
- how material findings were validated and remediated
- whether monitoring occurred between scheduled reviews
- which dependencies or subcontractors became relevant during the period
- what evidence supports the organisation's current risk decision
The same issue appears when selecting a third-party risk tool for DORA and NIS2. The useful test is whether the platform helps maintain evidence between assessments, rather than producing a polished snapshot that immediately begins to age.
How continuous monitoring complements questionnaires
Continuous monitoring fills the time gap between questionnaires. It can surface changes in external assets, cyber hygiene, supplier relationships and business context, giving teams new evidence to validate, investigate, or use as a trigger for reassessment.
Questionnaires and continuous monitoring observe different parts of the supplier relationship. The questionnaire can capture internal policies and supplier attestations. External monitoring can keep watching observable conditions without waiting for the supplier to complete another review.
A useful monitoring programme can detect changes such as new internet-facing assets, certificate or DNS changes, exposed services, software changes, deterioration in cyber hygiene, relevant business events, and newly observable supplier connections.
The value comes from connecting those changes to an action. A new finding may trigger validation, supplier outreach, a remediation ticket, a risk-tier change or a formal reassessment. That gives the organisation a dated evidence trail showing how oversight continued after onboarding.
For supply chain risk, continuous supplier intelligence can also expose relationships that were missing from the original questionnaire or vendor inventory. That matters because a programme cannot assess a dependency it has never identified.
Can a TPRM programme run without questionnaires?
Some third party risk programmes can reduce questionnaire use substantially, especially for low-risk or externally observable controls. Higher-risk relationships still benefit from direct supplier evidence where internal controls, data handling, resilience arrangements or contractual responsibilities cannot be established externally.
The right amount of questionnaire activity depends on the supplier, the service and the evidence already available. A low-impact provider with no sensitive access may justify a lightweight assessment supported by external monitoring. A supplier supporting a critical service, processing regulated data or operating privileged integrations will usually require deeper due diligence.
External evidence can answer many questions efficiently. It can show what infrastructure is exposed, which technologies are visible, whether configurations changed and which digital relationships can be observed. It cannot confirm every internal policy, private control, or contractual obligation.
That creates a practical division of labour: use supplier engagement where the answer exists inside the supplier, and use independent evidence where the condition can be observed continuously from outside.
A defensible hybrid model
A defensible supplier assurance model combines risk-based questionnaires with independent evidence, continuous monitoring and documented follow-up. The aim is to preserve supplier accountability while maintaining a current view of the risks that can change between formal assessments.
For most organisations, the strongest model is layered rather than questionnaire-heavy:
- Discover and scope the supplier population, including relevant relationships that may be missing from procurement records.
- Tier suppliers by criticality, access, regulatory relevance and dependency so due diligence effort matches potential impact.
- Collect supplier evidence for controls, responsibilities and facts that cannot be established independently.
- Validate material claims where supporting documentation or external evidence is available.
- Monitor meaningful changes between formal assessments and define the triggers that require action.
- Record findings, ownership, remediation, exceptions and risk decisions so the oversight trail can be reconstructed later.
This model gives questionnaires a clear role without asking them to carry the whole compliance burden.
Questionnaire evidence vs continuous evidence: comparison table
Questionnaire alone | Questionnaire + external monitoring | Verdict for an auditor | |
|---|---|---|---|
| Supplier control attestation | Strong for declared policies and controls | Strong, with added evidence where claims can be validated externally | Useful evidence when scope, date and ownership are clear |
| Current external posture | Weak after the submission date | Stronger because observable changes can be tracked between reviews | Shows oversight continued beyond onboarding |
| Change history | Limited to periodic reassessment | Provides dated evidence of relevant changes and follow-up | Supports a reconstructable oversight trail |
| Supplier and dependency coverage | Depends on the known vendor population and supplier disclosure | Can reveal observable suppliers, assets and indirect relationships outside the original inventory | Stronger when discovered relationships are validated and governed |
| Remediation evidence | Can record commitments | Can connect changes and findings to investigation, tickets and reassessment triggers | Most defensible when ownership and closure are documented |
| Overall assurance | Point-in-time supplier declaration | Layered assurance using supplier evidence plus independent observation | More resilient evidence for ongoing supplier oversight |
The auditor test: what could you prove about last quarter?
A useful compliance test is simple: if an auditor or regulator asked how a critical supplier was overseen last quarter, could you show more than its last questionnaire? A defensible answer includes the assessment, the evidence reviewed since then, changes detected, decisions made, remediation activity and the current risk position.
A questionnaire can be an important part of that file. The stronger record also shows what happened between the questionnaire date and today.
For a critical supplier, you should be able to reconstruct the period: when it was assessed, which evidence was accepted, what monitoring took place, which material changes were detected, who reviewed them, what action followed and why the current level of risk is considered acceptable.
That is the standard worth designing towards in both NIS2 supplier-risk programmes and DORA third-party ICT risk programmes. The objective is a current, evidence-backed record of supplier oversight that can survive scrutiny after the fact.





