Professional services vendor questionnaire
Questions for consultants, agencies and outsourced service providers: who you are contracting with, how they handle your information, conflicts of interest, insurance, and who actually does the work.
69 questions in 10 sections. Each has the kind of answer you need and a one-line reason you can keep in the questionnaire, so suppliers understand why you ask.
1. Company and ownership (8)
- What is your company's full legal name and registration number?
- Who are your ultimate beneficial owners (holding 25% or more)?
- In which countries do you have operations that would serve us?
- How many years has the company been trading?
- How many employees do you have?
- Please provide a current certificate of registration or trade licence.
- Has the company changed ownership in the last 3 years?
- Who will be our main contact, and who is their backup?
2. Financial stability (7)
- Please share your last two years of financial statements.
- What was your annual revenue in the last financial year?
- What share of your revenue would our business represent?
- Are you subject to any insolvency, restructuring or major debt proceedings?
- Have your audited accounts ever been qualified by the auditor?
- Are there any outstanding legal claims above 5% of your annual revenue?
- Which bank(s) do you use for operations?
3. Business continuity (5)
- Do you have a written business continuity plan?
- When did you last test the plan, and what was the result?
- Which of your own suppliers could stop your service to us if they failed?
- What is your recovery time and recovery point objective for systems we rely on?
- How will you notify us of a disruption, and how quickly?
4. Quality (5)
- Which quality management certifications do you hold (for example ISO 9001)?
- What was your on-time delivery rate for the last 12 months?
- How do you handle non-conforming products or services and corrective actions?
- How do you measure and report service quality to clients?
- Have you had any product recalls or major customer complaints in the last 3 years?
5. Cyber security and data protection (11)
- Will you store, process or access any of our data or systems?
- Which security certifications or reports do you hold (for example ISO 27001, SOC 2)?
- Do you enforce multi-factor authentication for all staff with access to our data or systems?
- Where (which countries) will our data be stored and processed?
- Is our data encrypted in transit and at rest?
- Have you had a security incident affecting customer data in the last 3 years?
- How quickly will you notify us of a security incident affecting our data?
- Which subcontractors or cloud providers will have access to our data?
- How will our data be returned or deleted when the contract ends?
- How often do you run independent penetration tests, and can you share a summary?
- Do staff receive security awareness training at least yearly?
6. AI use on your data (8)
- Do you use AI tools or AI agents in the work you do for us?
- Will any of our data be entered into AI tools? If so, which tools?
- Is our data used to train or improve any AI model, yours or a provider's?
- Do you keep an inventory of the AI agents and tools your staff use?
- Are consequential AI decisions or actions reviewed by a person before they take effect?
- Can you show which AI actions were taken on our data, and when?
- Do you have a written AI use policy for staff?
- Do AI agents in your service hold credentials that can act in our systems?
7. ESG and responsible sourcing (7)
- Do you have a supplier code of conduct or responsible sourcing policy?
- Do you measure your greenhouse gas emissions (scope 1 and 2 at least)?
- How do you check for forced or child labour in your operations and supply chain?
- Do you hold any environmental certifications (for example ISO 14001)?
- What share of your workforce and spend is local to the countries you serve us from?
- Do you have targets to reduce emissions, energy use or waste? Please describe them.
- Do workers in your operations have written contracts, fair working hours and a way to raise grievances?
8. Compliance and ethics (7)
- Do you have an anti-bribery and corruption policy, and do staff receive training on it?
- Do you screen your company, owners and partners against sanctions lists?
- Are you, your owners or directors subject to any sanctions or debarment?
- Do any of your owners or staff have a relationship with our employees that could be a conflict of interest?
- Do you have a whistleblowing channel for staff and third parties?
- Have you been subject to regulatory fines or investigations in the last 5 years?
- Do you hold all licences and permits required for the work you'd do for us?
9. Insurance (5)
- Please provide certificates for your current insurance policies.
- What is your general / public liability cover limit?
- What is your professional indemnity cover limit?
- Do you hold cyber insurance, and what is the limit?
- Will you name us as an additional insured where appropriate?
10. Sub-suppliers (6)
- Will you subcontract any part of the work for us? If so, which parts?
- Will you ask for our approval before adding or changing a subcontractor?
- Do you apply the same requirements (quality, security, ethics) to your subcontractors?
- How do you monitor the performance and risk of your key suppliers?
- Please list the subcontractors and key suppliers you would use for our work, with their countries.
- Which subprocessors or cloud providers will store or process our data?
Track the answers, not just the questions
Once suppliers reply, Qeluntra keeps due-diligence evidence, remediation owners and deadlines in one place, linked to your contracts.
Track answers and evidence in Qeluntra, free How Qeluntra handles supplier risk
Free plan: no card, no expiration, one company workspace.
This questionnaire is a starting point, not legal or compliance advice. Adapt it to your contracts, your sector and the laws that apply to you. Question bank last reviewed 2026-09-25.