15 Best Vendor Assessment Questions to Ask

The 15 best vendor assessment questions for privacy, security, transfers, sub-processors, AI use and resilience, with guidance on proportionate scrutiny.

Topics: Vendor Risk, Third-Party Risk, Due Diligence, GDPR, AI Governance

A supplier can become part of your data environment long before it becomes visible in your risk reporting. A cloud service receives employee records, a marketing agency accesses customer data, or an AI provider processes prompts containing confidential information. The best vendor assessment questions expose that dependency early, establish who is accountable, and create evidence that can withstand scrutiny.

The objective is not to send every supplier a 200-question form. It is to apply proportionate scrutiny based on the data involved, the service provided, the jurisdictions affected, and the supplier’s role in a critical process. A stationery supplier and a processor hosting sensitive personal data should not receive the same assessment.

Start with risk, not a generic questionnaire

A useful vendor assessment begins with internal classification. Before asking a supplier for evidence, determine whether it will act as a processor, controller, sub-processor or independent service provider. Identify the categories of data, the volume and sensitivity of information, where processing will occur, and whether the service supports a regulated or business-critical activity.

This scoping stage determines the depth of the review. High-risk vendors may require a detailed privacy, security, resilience and AI governance assessment, supported by contractual review and periodic reassessment. Lower-risk vendors may only need confirmation that no personal data is processed and that access controls are appropriate.

The questions below are designed for vendors that process personal data, support important operational functions, or provide AI-enabled services. They should be adapted for GDPR, UK GDPR, Swiss nFADP, Thailand PDPA and other applicable requirements rather than treated as a fixed global template.

The 15 best vendor assessment questions

1. What personal data will you process, and for what documented purpose?

This establishes the scope of the relationship. Ask for data categories, data subject groups, processing activities, retention expectations and the business purpose for each use. Vague answers such as “service delivery” should be clarified. The organisation needs a description detailed enough to support its ROPA and, where relevant, a DPIA.

2. What is your role under applicable data protection law?

A vendor may be a processor for one activity and an independent controller for another, such as account administration, billing or product analytics. Ask the supplier to explain its role by processing purpose. This prevents a common contractual failure: applying processor terms to activity where the supplier determines its own purposes and means.

3. Where will data be stored, accessed and transferred?

Do not limit this question to the primary hosting location. Ask where support teams, engineering teams, sub-processors and backup environments may access data. The answer should identify transfer mechanisms, relevant safeguards, and the supplier’s process for responding to changes in processing locations.

4. Which sub-processors do you use, and how do you govern them?

Supplier oversight does not stop at the contracting entity. Request a current sub-processor list, the services each party provides, their locations, and the notification process for proposed changes. A vendor should be able to demonstrate due diligence, written obligations and ongoing oversight of its own supply chain.

5. What technical and organisational measures protect our data?

Ask for specific controls rather than a general assurance that security is “industry standard”. Relevant evidence may include access management practices, encryption arrangements, segregation controls, vulnerability management, logging, secure development processes and independent assurance reports.

The level of evidence depends on risk. A supplier processing special category data or serving as a core platform should provide materially more detail than a low-impact provider. Certifications can be useful, but they do not replace an assessment of how controls apply to the proposed service.

6. How do you manage user access and privileged accounts?

This question addresses one of the most consequential operational risks: unnecessary access. Ask how access is approved, reviewed, removed and monitored, particularly for administrative and support personnel. Establish whether multi-factor authentication is used, whether privileged access is time-bound, and how access to customer environments is recorded.

7. What is your process for detecting, managing and notifying data breaches?

A supplier should explain how it identifies incidents, triages severity, preserves evidence and communicates with customers. Ask for notification timeframes, escalation contacts, the information provided in an initial notice, and how the supplier supports investigation and remediation.

The contract should align with this operational process. A promise to notify “without undue delay” is insufficient if nobody knows who receives the notice or what happens outside normal business hours.

8. How long do you retain data, and how is it securely deleted?

Retention often becomes unclear at termination. Ask for standard retention periods, deletion methods, backup treatment, customer controls and the availability of deletion certificates or other evidence. Also confirm whether data may be retained for legal claims, security investigation or statutory obligations, and under what controls.

9. How do you support data subject rights requests?

Where a supplier acts as processor, it must be able to assist with access, deletion, rectification, restriction and objection requests where applicable. Ask how requests are received, authenticated, tracked and completed. The supplier should distinguish between requests it handles on its own behalf and those it supports for customers.

10. Can you provide the information required for our DPIA or LIA?

High-risk processing cannot be assessed properly when vendors provide only broad marketing descriptions. Ask whether the supplier can supply information about data flows, security measures, residual risks, transfer arrangements and mitigations needed for a Data Protection Impact Assessment or Legitimate Interest Assessment.

This is especially relevant where the vendor introduces profiling, monitoring, behavioural analytics or large-scale processing. A mature supplier understands that privacy documentation is not a contractual afterthought.

11. Does your service use AI, automated decision-making or model training?

AI capability should be assessed separately from conventional software functionality. Ask whether customer data, prompts, outputs or metadata are used to train, tune or evaluate models. Confirm whether AI features can be disabled, what human oversight is available, and whether the provider maintains records of model purpose, limitations and intended use.

For systems within the scope of the EU AI Act, request information that supports risk classification, supplier obligations and internal AI system registry records. The answer should clarify whether the vendor is providing an AI system, a general-purpose AI model, or a supporting component.

12. What controls address AI-specific risks?

Where AI is involved, ask how the supplier manages output reliability, harmful or inappropriate content, bias testing, prompt injection, model changes, logging and human intervention. Not every AI service requires the same level of review. A generative assistant used for public content presents different risks from an AI tool influencing recruitment, credit, healthcare or employee performance decisions.

The key question is whether the supplier can provide operational evidence, not simply broad responsible AI commitments.

13. What contractual commitments will you accept?

The assessment should confirm whether the supplier will enter into an appropriate data processing agreement and support required clauses on confidentiality, security, sub-processing, audits, international transfers, assistance and deletion. Legal teams should also review liability allocation, service levels, intellectual property provisions and restrictions on secondary use of data.

Contract review and DPA redlining are most effective when informed by the assessment evidence. Otherwise, negotiators may be debating clauses without understanding how the service actually operates.

14. How do you maintain business continuity and service resilience?

Privacy risk and operational resilience are connected. Ask about disaster recovery, backup arrangements, recovery objectives, dependency mapping, incident testing and communication procedures. For critical vendors, request evidence that continuity plans are tested and that material findings are tracked to resolution.

15. How will you demonstrate continued compliance after onboarding?

A point-in-time questionnaire becomes stale quickly. Ask how the supplier communicates material changes, renewed certifications, security incidents, new sub-processors, changed data locations and new AI functionality. Define reassessment triggers as well as a routine review cycle.

Turn supplier answers into accountable action

The value of a vendor assessment lies in what happens after the response is received. Assign ownership for reviewing privacy, security, legal, procurement and business continuity evidence. Record risks, decisions, remediation actions, due dates and approvals in one place. If an issue is accepted, document the rationale and the accountable risk owner rather than leaving it in an email thread.

This also avoids duplicated work. Information gathered during a supplier review can populate ROPA entries, support DPIAs, inform contract redlines, contribute to AI system oversight and provide evidence during audits. Privacy360 supports this connected approach by bringing vendor and third-party risk assessment into the same operational system as privacy assessments, processing records, incident management and AI governance.

Where internal capacity is limited, many organisations combine platform-led governance with external expertise. Formiti's data protection consulting services can support programme design, assessment quality reviews and multi-jurisdiction implementation alongside the platform.

The strongest supplier programmes do not seek perfect answers from every vendor. They create a repeatable method for asking the right questions, escalating material gaps and proving that decisions were made with appropriate control. That is how third-party oversight becomes a managed governance process rather than a collection of completed forms.