Third-party risk

What a bank actually looks for when it sends you a technology due diligence questionnaire

A spreadsheet arrives with two hundred questions and a fourteen-day deadline, and someone tells you it’s a formality. It isn’t — but it also isn’t the test most vendors think it is.

A spreadsheet arrives. Two hundred and forty questions across eleven tabs, a fourteen-day turnaround, and a sales lead telling you this is “just a formality before we sign.”

It is not a formality. But it is also not the test you probably think it is.

Most vendors treat the questionnaire as an exam to be passed — find the answer that scores best, phrase it confidently, move on. That misreads the situation, and the misreading is why competent firms with genuinely decent controls end up flagged, delayed, or quietly dropped at renewal.

I spent close to a decade inside the technology risk function of one of Canada’s five largest banks, and eleven years before that in Big 4 advisory helping financial institutions build and test exactly these processes. I’ve written questionnaires, read the answers, and sat in the committees where the resulting assessments were argued over. What follows is what happens on the other side of that spreadsheet.

The first thing to understand: you are not the audience

Your answers are not being read by someone deciding whether to like you. They are being read by someone who has to write a document.

That document is a third-party risk assessment. It has your firm’s name on it, a risk rating, a list of identified gaps, and a recommendation. It goes into a system of record. It gets sampled by internal audit. In some institutions it is visible to the regulator during a supervisory review. And crucially, the person who writes it has to be able to defend every conclusion in it — possibly years later, possibly after something has gone wrong.

This changes everything about what “a good answer” means.

A reviewer cannot write “the vendor assured us their access controls are strong.” They need something they can point to: a policy with an approval date, an attestation, a certification, a test result, a named owner. Your confident prose is not usable. Your evidence is.

Once you internalize that the reviewer is assembling a defensible file rather than forming an impression, most of what follows becomes obvious.

Who actually reads it

Rarely one person. Typically three groups, with different incentives.

The third-party risk analyst owns the file and the timeline. They are managing dozens of assessments simultaneously and are measured on throughput and quality. They are not a technology specialist. They triage your responses, route the technical sections to subject-matter reviewers, and chase whatever is missing. Ambiguity in your answers becomes work for this person, and work for this person becomes delay for you.

The subject-matter reviewers — information security, technology risk, business continuity, privacy, sometimes model risk or compliance — each read a slice. They are specialists, they can tell immediately when an answer was written by someone who doesn’t understand the control being described, and they are the source of most follow-up questions.

The business sponsor — the person inside the institution who wants to buy your product — is your ally, and this is the relationship vendors most underuse. They have a deadline, a budget cycle, and often a problem your product solves. They cannot influence the risk conclusion, but they can and do escalate when the process is stalling, and they will absolutely notice if the delay is your fault. Keep them informed about your submission status; do not let them learn from the risk team that you’re the bottleneck.

What happens after you hit send

Roughly this, at most institutions:

Your responses are scored against the institution’s control expectations. Gaps are identified and rated. For each gap, the analyst determines whether there’s a compensating control, whether it can be remediated, and on what timeline. The result is a residual risk position — with a rating that determines what happens next.

Low residual risk: the assessment closes, and you’re re-assessed on a cycle tied to your tier.

Moderate: gaps are documented, sometimes with remediation commitments written into the contract or a side letter, and often with a shorter re-assessment cycle.

High: the assessment escalates. Depending on the institution and the criticality of what you provide, that can mean a risk committee, a named executive accepting the risk in writing, or the deal not proceeding. Executives are generally reluctant to put their name on an accepted risk for a vendor that isn’t strategically essential — which is why “high” so often quietly becomes “no.”

The rating matters more than any individual answer, and it is driven far more by the pattern of your responses than by any single gap.

Why your questionnaire was 240 questions and your competitor’s was 40

Before the questionnaire was sent, someone completed a criticality assessment on the service you’re providing: what data you touch, whether you’re in the path of a critical business process, what happens to the institution if you disappear for a week, whether you have access to their environment, and how easily you could be replaced.

That assessment set your tier, and the tier set the depth of the diligence. It also set your ongoing obligations — re-assessment frequency, monitoring, reporting, audit rights, contract terms.

Two practical consequences. First, if the questionnaire seems disproportionate to your contract value, the institution has likely concluded you’re more embedded than you think — usually because of data access or process criticality, not revenue. Second, the tiering happened before anyone read a word of your answers, so it is not a verdict on you. It’s a description of the institution’s exposure.

Worth knowing: if you genuinely believe you’ve been mis-tiered — you’re being assessed as if you hold customer data when you process only anonymized aggregates, say — that is a conversation you can have, through the business sponsor, early. It is a much better conversation than answering ninety questions that don’t apply to you.

The four ways vendors lose points they didn’t need to lose

Most vendors don’t fail on control substance. They fail on presentation, in four recognizable ways.

Marketing language where evidence belongs. “Bank-grade security,” “enterprise-ready,” “industry-leading encryption.” These phrases have no assessable content, and to a reviewer building a defensible file they read as evasion. Replace every one with a specific, checkable fact: the standard, the configuration, the frequency, the owner, the document.

Over-claiming. Answering “yes” to a control you operate informally is the single most expensive mistake in the process, because it doesn’t stay contained. When the evidence request arrives and you can’t produce the artifact, the reviewer doesn’t just correct that one answer — they lose confidence in all of them. A “yes” that unravels converts a control gap into a credibility problem, and credibility problems are much harder to remediate. “No, but here’s what we do instead, and here’s our roadmap” costs you almost nothing by comparison. Reviewers are used to gaps. They are not used to being misled, and they remember it.

Silence. Blank cells, “N/A” without explanation, “will provide on request.” Every one of these generates a follow-up, and follow-ups are where timelines die. If a question genuinely doesn’t apply, say why in one line. If you can’t answer yet, say when.

Inconsistency across the document. Different people fill different tabs, and the security tab says logs are retained twelve months while the operations tab says ninety days. Reviewers cross-reference — it’s the fastest way to find where a response set is weak. One person should read the whole thing before it goes back, specifically looking for contradictions.

Notice that none of these four require you to have better controls. They require you to describe the ones you have accurately and consistently.

Where deals actually die: the contract, not the questionnaire

The questionnaire produces a risk rating. The contract is where the institution’s obligations get pushed onto you, and it’s where negotiations most often stall.

Expect to be asked for: audit and inspection rights, including on-site; breach notification within a defined window, often 24 to 72 hours; disclosure of your own material subcontractors — your fourth parties — and notice before you change them; data residency commitments; specified service levels with remedies; business continuity and disaster recovery obligations with tested recovery objectives; and exit assistance, meaning a defined process for getting the institution’s data back in usable form if the relationship ends.

That last one surprises vendors most, and it is not negotiable at most institutions. Supervisors expect regulated firms to have credible exit plans for material arrangements. A vendor who resists exit provisions is, from the institution’s side, demonstrating precisely the concentration risk the provision exists to manage.

The vendors who move fastest through this stage have thought about these terms before they appear in a redline — and have a documented position on each, rather than discovering their own limits during negotiation.

Build the pack once

The highest-leverage thing a vendor can do is stop answering questionnaires from scratch.

Assemble a due diligence pack: your information security policy set with approval dates and owners; your most recent independent assessment (a SOC 2 Type II, an ISO 27001 certificate, or a penetration test summary with remediation status); your business continuity and disaster recovery plans with the date of the last test and its results; your incident response process with notification commitments; a data flow description covering what you hold, where it resides, and who can reach it; your subcontractor list; your access management and change management procedures; and a short architecture overview.

That set answers most of any questionnaire you will ever receive. Maintain it as a living thing with a named owner and a review date, and the fourteen-day turnaround stops being a crisis. It also does something less obvious: a vendor who responds quickly, completely and consistently gets a materially better rating than one with identical controls who responds late and in fragments — because responsiveness is itself read as a signal of operational maturity.

If you have never had an independent assessment, that is the highest-value single investment. It converts a hundred assertions into one piece of third-party evidence, and it shortens every assessment you will ever go through.

What good actually looks like

The vendors who sail through are not the ones with perfect controls. They’re the ones who can describe their control environment accurately, evidence it quickly, name their gaps before being asked, and show a credible plan for closing them.

That combination is rarer than it should be, and it is entirely achievable for a firm of forty people. It is also, not incidentally, the same discipline that keeps you out of trouble when something actually goes wrong.

If you’d like a second pair of eyes on your due diligence pack from someone who has assessed vendors from the institution’s side, that is precisely the work we do.

Bunmi Makinde · Founder, Hosmak Solutions

FCA (Nigeria) — see designation note · CISA · CRISC · AAIR · CFSA

Twenty-five years in financial services technology risk: eleven years in Big 4 advisory at PwC and EY, and nearly a decade building enterprise technology risk governance and board reporting inside one of Canada’s five largest banks. Hosmak Solutions advises small and medium-sized financial services firms and their vendors on AI governance, technology GRC and internal controls.

This article is general information about industry practice and regulatory expectations, not legal advice. Firms should confirm their specific obligations against the source instruments and with their own advisors.

Start with a conversation

Bring the questionnaire, the finding, or the board question. Thirty minutes, no cost, and you’ll leave with a straight view of what answering it would take — whether or not you work with us.

Book a 30-minute consultation

Or email hello@hosmaksolutions.ca