How to Answer Vendor Security Questionnaires from Policy Text

Security questionnaires fail in a predictable way. The model fills SOC 2, AES-256, 90-day log retention, and a DPO name you never pasted. Procurement then treats the answers as attestations. Your GRC lead spends the week walking them back. The job is not a fluent yes. The job is a source map from the policies you actually have.
The matching generator is the Vendor Security Questionnaire from Pasted Policies prompt. Browse related cards in the PromptDig library (Browse more prompts). When a filled run survives, share the version you actually use (Share a prompt).
Paste the policies, then map every question to a quote
Do not start with the spreadsheet. Paste the policy pack first: information security, access control, incident response, data retention, subprocessors, and whatever else you actually publish or share under NDA. Company context is who you are, what you host, and which products are in scope. If the questionnaire is for a sandbox, say so. Do not let the model answer as if production is in scope.
The source map should quote a fragment for every claim. "We encrypt at rest" is allowed only if a pasted policy says so, in those words or a close paraphrase you can defend. "We hold SOC 2 Type II" is allowed only if the letter or report is in Inputs. A marketing page that says "enterprise-grade" is not a control.
If the pack is thin, the generator must list gaps instead of filling. A missing incident-response SLA is NO_DATA, not "we respond within 24 hours because that is industry practice." Industry practice is not a policy.
NO_DATA is an answer. Invented controls are not.
Treat every cell as one of three things: a quote from policy, a yes/no that the policy actually supports, or NO_DATA. Partial answers get a comment: "Access reviews are described; frequency is not in the pasted pack."
Do not invent:
- Audit logos, report dates, or certificate IDs
- Encryption algorithms and key lengths
- Retention windows
- Subprocessor names
- Pen-test vendors or last-test months
- Insurance limits
- Headcount of the security team
- On-call SLAs
If Metrics include approved numbers (employee count, regions, uptime from a public status page you pasted), use only those. Do not round them into "99.99." Do not mint a customer reference.
Version-lock named tools. If Inputs say Okta and CrowdStrike, those names may appear. If the EDR is unnamed, write unknown. Do not pick a popular vendor to look complete.
De-identify. Strip emails, ticket IDs, and employee names from the paste before the model sees them, or instruct it to replace them with roles. This is GRC drafting, not legal advice. Say so on the output.
Questionnaire draft, risks, and owners who are still unassigned
The main deliverable is the answered questionnaire in the same order as the source. Short paragraphs. Question ID if you provided one. Answer. Source quote. NO_DATA marker when needed.
Risks and compliance: flag answers that over-claim, banned words (best, guaranteed, #1), and places where sales wants a yes that policy does not support. Next questions get owners only if you named them. Otherwise unassigned. "Ask Legal about data residency" is fine. "Ask Priya by Thursday" is not if Priya is not in Inputs.
Gaps belong at the end: missing policies, missing report dates, missing in-scope systems, missing subprocessors list, missing jurisdiction. Five bullets is enough. The questionnaire ships when those gaps are filled by humans, not when the model sounds confident.
A worked pass: what the portal should never see
Imagine the portal asks for encryption at rest, last pen-test date, and a subprocessor list. Your paste has an access-control policy and a retention page with no months. The source map quotes the access policy for "least privilege" and puts encryption, pen-test, and subprocessors in NO_DATA. The draft answers those three cells with NO_DATA plus "not in pasted pack," not with AES, last March, and a guessed AWS list.
If sales wants a yes because a competitor answered yes, the risks section says so. The next question is unassigned: "who owns the missing pack." Do not name a CISO who is not in Inputs.
That is the whole product. The questionnaire is a filter on policy text. Everything else is a leak you will walk back in email.
Fill the card, then run
Paste the real policy pack and the questionnaire. Empty control fields stay empty. Then run it and read the NO_DATA list before anyone pastes answers into the portal.
Company context and in-scope products: [Context]
Policy pack (paste): [Notes]
Approved numbers only: [Metrics]
Questionnaire text or question list: [Questions]
Audience (procurement, security review, internal GRC): [Audience]
Tone: [Tone]
Legal / compliance notes: [Compliance]
Tools named in policy (or unknown): [Tools]
Words I must not use: [Banned]
A questionnaire is an attestation waiting to happen. The generator should make it smaller and truer, not denser. When a run refuses a fake SOC 2 date, keep that filled card next to the portal. Share the version that survived GRC review, not the one that said yes everywhere.