We use essential cookies to run this site. Analytics & marketing cookies load only with your consent — see our Cookie Policy and Privacy Policy.

Free download · Vendor questionnaire & scoring model

Vendor security questionnaire & scoring model

A ready-to-send third-party security questionnaire with a built-in scoring model — so vendor risk becomes a number you can tier and act on, not a folder of unread PDFs. Aligned to RBI outsourcing expectations and common enterprise reviews.

Questions
68
Domains
12
Format
Excel
Scoring
Weighted
Get the vendor questionnaire & scoring model

Enter your work email and we’ll send it straight to your inbox.

Open download \u2014 no form, CC BY 4.0
\u2b07 Download Vendor questionnaire & scoring model

Licensed CC BY 4.0 \u2014 reuse and share with attribution to CyberSigma.

What’s included

Send-ready questionnaire
68 questions across governance, access, data protection, resilience, cloud and sub-processor risk.
Weighted scoring model
Automatic risk score and tier from the responses, so critical vendors surface immediately.
Evidence prompts
What evidence to request for high-risk answers, so questionnaires are verified not just collected.
Tiering & cadence
A tiering rubric and re-assessment cadence to run an ongoing programme.

Who it’s for

  • Banks and NBFCs meeting RBI outsourcing/TPRM expectations
  • Security and procurement teams assessing suppliers
  • Anyone drowning in unscored vendor questionnaires

Inside the vendor questionnaire & scoring model

  • 68 questions across 12 domains
  • Weighted scoring and auto-tiering
  • Evidence-request prompts
  • Vendor tiering rubric
  • re-assessment cadence and register
Sharwan Jha, Founder & Chief Executive Officer
Written by Sharwan Jha · 20+ years in cybersecurity and information security
Reviewed by Abhay Singh · Updated July 2026

Want us to run your vendor programme?

We tier your vendors, assess the critical ones and leave you with a scored, monitored TPRM programme aligned to RBI outsourcing norms.

Book a 20-minute review →Third-party risk assessment