Describe what you will actually store
Before sending a security questionnaire, list the record categories you expect to use, who needs them and which other systems they will reach. Separate a public document library from participant records, worker files and internal investigations. The same product can be appropriate for one task and unsuitable for another. Use invented data during vendor demonstrations.
Ask which company provides the service, which subprocessors are involved and where the relevant production, backup and support activities occur. “Hosted in Australia” may describe one component. Request the scope of the statement, the supporting document and its date. Do not infer a complete privacy or security assessment from hosting geography.
Demonstrate access from both sides
Prepare an access table with the roles your organisation actually needs. For example, a worker may need an assigned resource while a manager needs the related review record. Ask the vendor to demonstrate permitted access and a denied action using separate test accounts. Check what happens when a worker changes team or leaves.
Have the vendor revoke a test account and explain whether existing sessions, shared links, offline copies and integrations are affected. Observe what can be demonstrated and document the remainder as unanswered. Do not run unagreed penetration tests against a public service. A controlled demonstration is a buying check, not a security certification.
Ask what a successful recovery means
Request the date and scope of the last relevant restore test. Ask what data was restored, how completeness was checked and how long the exercise took. Distinguish a backup job reporting success from a demonstrated restore. Ask whether the recovery objective covers files, database records, configuration and linked attachments.
A useful answer describes both evidence and limits. For example: “A fictional organisation was restored in isolation; attachments and selected records were reconciled. A full service outage was not tested.” This invented answer is more assessable than “fully backed up”. Your buying decision should reflect the recovery scope your service needs, not a promise inferred from a green status icon.
Keep an evidence decision register
Record each vendor statement, its source, the date supplied, the service or plan it covers and your reviewer’s decision. If the vendor supplies an assurance report, check the named entity, period, exclusions and services in scope; use an appropriately qualified reviewer for matters beyond your expertise. Store confidential reports according to their access conditions.
Ask who contacts you about an incident, how the contact list is maintained and which contractual commitments apply. Keep a practical escalation contact outside the application. Repeat the review when your intended use, integrations or vendor service changes. Marketplace inclusion does not establish these controls: our catalogue distinguishes dated vendor information from hands-on testing and unresolved questions.
Make it useful today
Your working checklist
Use example data here. Answers stay in this page until you choose to save a file. Closing the page loses unsaved answers. No account or email is required.
Make your shortlist earn its place
Use the same evidence request with every shortlisted vendor, including ProviderQMS. Compare what is documented and demonstrated; keep unknowns visible.
Compare the multi-vendor catalogue →Sources and scope
Official and vendor sources provide context. The worksheet and example are our practical editorial method, not an official form, independent product certification or audit result. Check requirements that apply to your service.