How to answer
Do you assess the security of your vendors and sub-processors?
The question your customer is really asking is whether their data can reach somewhere they have not been told about.
Yes. Before a vendor processes customer data we review its security posture, which for major providers means its current SOC 2 Type II report or ISO 27001 certificate, and we execute a data processing agreement. Vendors are reviewed again [annually], and the current list is published.
Square brackets are yours to fill in. FillTrust grades an answer like this implied, not stated when your documents support it.
- Answered from
- Your vendor management policy, your sub-processor list, and your DPA.
- Evidence to attach
- Occasionally your sub-processor register, or the assurance report you hold for a named vendor.
- Where it is asked
- CAIQ v4.0 · STA-08SIG LiteISO 27001 Annex A · A.5.19
The buyer sending you this questionnaire has their own customers, their own regulator and their own version of this question to answer. Their concern is concrete: if their data reaches a fourth party, are they going to find out from you or from a news story.
Say what happens before a vendor is onboarded. For a small company the true answer is usually short. You check whether the vendor publishes a SOC 2 report or an ISO certificate, you read what it covers, you sign a DPA, and you decide. Written down, that is a vendor assessment process. Reviewers are not expecting a scored risk register; they are expecting evidence that somebody looked before the data moved.
Distinguish the tiers, briefly. A cloud provider holding all customer data and an analytics tool receiving anonymous page views are not the same risk and should not get the same paragraph. Saying that assessment depth follows what the vendor can access is a sophisticated answer that costs one sentence.
The list is the load-bearing part. A published sub-processor list is the single strongest thing you can offer here, because it is verifiable, it is what the DPA obliges you to maintain, and it is what the buyer's own DPA obliges them to pass on. If yours is a page on your site, link it in the answer. Keeping it current matters more than most questionnaire answers, because unlike a claim about your practices, an omission here can be spotted by anyone who looks at your DNS records or your privacy policy.
Change notification. Most DPAs commit to notifying customers before a new sub-processor is added, with a window to object. If yours does, say so here, because it answers the reviewer's underlying worry directly.
Where this usually lands. Implied, and correctly so. Most companies do the check and never write down that they do it. One paragraph in a policy, naming the trigger and the evidence you look for, converts this and its several rephrasings into a confirmed answer that quotes a document.
How this one goes wrong
Specific to this question, not general advice.
- Describing a formal vendor risk programme you do not run. At fifteen people the honest process is a check before onboarding and a published list, and that is a defensible answer.
- Answering only about sub-processors. Vendors who touch your production systems without touching customer data, such as a CI provider or an endpoint agent, are in scope for this question too.
- Having a list that is out of date. A published sub-processor list is checkable, so an omission is discoverable in a way most questionnaire answers are not.