When Clients Audit You
How Enterprise Vendor Security Requirements Actually Work

If you've ever received a security questionnaire from a client and wondered whether answering it truthfully would cost you the relationship, this post is for you.
The vendor security assessment has quietly become one of the most consequential documents in enterprise business development. It shows up late in the sales cycle, right when everyone wants to close. It asks questions your team may not have clean answers to. And if you're on the receiving end for the first time, it can feel like being handed a pop quiz in a subject you didn't know was on the syllabus.
Here's what's actually happening and what enterprise clients are really looking for when they send it.

Why Enterprise Clients Are Doing This
Ten years ago, vendor security assessments were largely the domain of financial services and healthcare. Today they're standard practice across industries, and the questionnaires are getting longer, more specific, and harder to bluff through.
The reason is straightforward: enterprise organizations are responsible for protecting their customers' data, even when that data passes through a vendor's systems. When a breach happens at a vendor, and they happen regularly, the enterprise that hired that vendor often bears the regulatory, legal, and reputational consequences. That dynamic has fundamentally changed how procurement, legal, and IT security teams evaluate the vendors they work with.
They're not being difficult. They're managing their own risk. And increasingly, they're being required to by their own regulators, cyber insurers, and boards.
“Enterprise clients aren't being difficult when they send a security questionnaire. They're managing their own risk and, increasingly, they're being required to by their insurers, regulators, and boards.”
What the Questionnaire Is Actually Measuring
Most vendor security questionnaires are variations on the same underlying question: Can we trust this organization with our data?
That question breaks down into several more specific ones that the assessment is designed to answer.
Do you have a security program, or just a security policy?
There's a meaningful difference between having a written policy that says "we take security seriously" and having an operational program with assigned ownership, regular testing, documented controls, and evidence of continuous improvement. Sophisticated clients know how to tell the difference. They ask for policies and procedures, but they also ask how often they're reviewed, who owns them, and what happens when a gap is discovered.
Are your controls actually working?
This is where the compliance frameworks and external attestations (SOC 2 Type II, ISO 27001, NIST CSF) come in. Enterprise clients reference these not because they love acronyms, but because each one represents a verified answer to this question. A SOC 2 Type II report from an accredited auditor says: an independent third party tested these controls over a period of months and found them operating as described. That's a more reliable signal than a self-attestation, and sophisticated clients know it.
Who has access to our data, and what controls govern that access?
Access control is one of the most scrutinized areas in any vendor assessment. Clients want to know who at your organization can access their data, under what circumstances, and with what oversight. Phishing-resistant multi-factor authentication (MFA), Role-Based Access Control (RBAC) enforced by least privilege, centralized logging, and automated HR offboarding workflows are all fair game. This is also where AI tools in your environment are increasingly becoming relevant…more on that shortly.
What happens when something goes wrong?
Incident response is a non-negotiable area for most enterprise clients. They want to know you have a documented plan, that your team has tested it, that you have notification procedures (and timelines), and that you carry adequate cyber insurance. The question isn't whether a vendor will ever have an incident, it's whether they'll handle it in a way that limits harm and keeps the client informed.
How do you handle our data specifically?
Data handling questions cover where data is stored, how it's encrypted in transit and at rest, how long it's retained, how it's deleted, and whether it ever crosses international borders in ways that create regulatory complications. For clients in regulated industries, this section of the assessment can be determinative.
The Questions That Have Changed in the Last Two Years
If you haven't been through a vendor assessment recently, here's what's new.
- AI governance: As AI tools become embedded in how organizations work, enterprise clients are starting to ask about them explicitly. Which AI systems in your environment have access to client data? Does that data leave your environment? Is it used to train models? What policies govern employee use of AI tools? These questions are early stage compared to where they'll be in three years, but they're showing up now and vendors who have clear, documented answers are at an advantage.
- Supply chain security: Clients aren't just evaluating your security program; they are scrutinizing your Nth-party risk. They're asking about your Software Bill of Materials (SBOM), the security of your sub-processors, and the cloud infrastructure you run on. The logic is simple: a breach in your supply chain becomes a breach for them.
- Cyber insurance specifics: General "we carry cyber insurance" answers are being replaced with questions about policy limits, coverage categories, exclusions, and whether coverage includes specific incident types like ransomware. Clients who have been through insurance claims understand that policy details matter significantly.
Where Most Vendors Get It Wrong
The most common mistake in responding to a vendor security assessment isn't dishonesty. It's treating the questionnaire as a one-time hurdle rather than a reflection of an ongoing program.
Sophisticated clients have reviewed enough assessments to recognize the difference between a response that describes a real security program and one that describes what the vendor wishes their program looked like. The tells are usually in the specifics: vague answers to specific questions, policies with no clear ownership, certifications that are expired or out of scope, incident response plans with no evidence of testing.
The second most common mistake is answering in isolation. Most vendor assessments are completed by someone in IT or operations who fills in what they know and sends it back. The problem is that security questions often touch legal, HR, finance, and leadership, and answers that don't reflect input from those teams can be technically accurate but substantively misleading.
The third mistake is waiting until an assessment arrives to build the program. The best time to have a documented security posture is before your most important client asks for one. By the time the questionnaire hits your inbox, the clock is already running.
“The most common mistake isn't dishonesty. It's treating a questionnaire as a one-time hurdle rather than a reflection of an ongoing program.”
What a Strong Response Looks Like
A vendor who handles a security assessment well does a few things consistently.
They provide documentation, not just claims. SOC 2 Type II reports, ISO 27001 certificates, policies with revision histories, and evidence of testing are standard. Claims without documentation are noted and followed up on.
They answer specifically. Vague answers to specific questions read as gaps. Clients notice.
They acknowledge limitations with context. No vendor has a perfect security program, and enterprise clients know it. What they're evaluating is whether the vendor understands their own posture, has a plan for improving it, and communicates honestly about it. "We don't currently have ISO 27001 certification but we're in the process of building toward it, and here's where we are" is a better answer than an evasive non-response.
They treat the assessment as a conversation. Some of the best vendor relationships are built during the security review process. A vendor who engages substantively, asks clarifying questions, and offers to walk the client's security team through their program is signaling something important: they take security seriously, and they're not afraid of scrutiny.

What This Means for Your Organization
If you're on the selling side of this dynamic, the questionnaire isn't the problem. It's a signal about where the bar is now set and where your program needs to be to compete for and retain enterprise relationships.
That means building a security program that can actually answer the hard questions, not just the easy ones. It means having documentation that reflects operational reality, not aspirational policy. And it means treating compliance as a continuous discipline rather than something you revisit when a questionnaire lands.
If you're on the buying side, the assessment is one of the better tools you have. Use it as a conversation, not just a checklist. The most important information you'll get often comes from how a vendor responds to the questions they can't answer cleanly.
Either way, the security conversation between enterprise clients and their vendors has permanently changed. The organizations building trust in this environment — on both sides of the table — are the ones engaging with it directly.
Fortellar helps organizations build compliance programs that can answer the hard questions and hold up to scrutiny when clients ask them. Get in touch if you want to talk through where your program stands.



