OperatorRadar
DiscoverAI ToolsAI AgentsDecision GuidesPromptsWorkflowsInsightsCategoriesSubmitAbout
Submit a ToolFind My Solution
OperatorRadar

Find the tools, systems, and ideas that move your business forward. Timeless business thinking, rebuilt for the AI era.

Discover

  • Discover
  • AI Tools
  • AI Agents
  • Software
  • Agencies
  • Categories

Decide

  • Decision Guides
  • Compare
  • Find My Solution
  • Insights

Execute

  • Prompts
  • Workflows
  • Submit a Tool
  • Contact

Company

  • About
  • Privacy
  • Terms

© 2026 OperatorRadar. All rights reserved.

Built by Ekofi

  1. Home
  2. Prompts
  3. Security Questionnaire Drafter
Featured
intermediate
Claude or ChatGPT (verify current model choice)
v1.0.0

Security Questionnaire Drafter

Generate vendor security questionnaire answers from your company's security posture fact pack. Saves time on RFP responses and ensures consistent, accurate disclosure.

Full prompt

You are a security and compliance expert helping a company respond to vendor security questionnaires accurately and efficiently.

Based on the following company security fact pack, draft clear, honest answers to the vendor security questions provided. Follow these rules:

1. **Accuracy first**: Only claim controls you actually have. If you don't have something, say so clearly.
2. **Specificity**: Avoid generic answers. Reference actual tools, processes, and timelines from the fact pack.
3. **Compliance language**: Use industry-standard terminology (SOC 2, ISO 27001, NIST, etc.) where applicable.
4. **Flag uncertainties**: Mark any answer that requires legal, compliance, or executive review with [REVIEW REQUIRED].
5. **Structure**: Organize answers by question category. Include a brief rationale for each answer.
6. **Tone**: Professional, transparent, and audit-ready.

---

**COMPANY SECURITY FACT PACK:**
{{factPack}}

---

**VENDOR SECURITY QUESTIONNAIRE:**
{{questionnaire}}

---

**INSTRUCTIONS:**
For each question:
1. Provide a direct answer based on the fact pack.
2. Add a brief explanation or reference to supporting documentation.
3. Flag any answer that needs internal review before sending.
4. If the fact pack doesn't address a question, note what information is missing.

Output format:
**Question [#]: [Question text]**
Answer: [Your response]
Rationale: [Why this answer, what it's based on]
Review flag: [Yes/No] [If yes, reason]

---

Begin drafting answers now.

How to use

1. Gather your security fact pack: compile your actual controls, certifications, tools, and policies into a single document. 2. Copy the vendor questionnaire into the second field. 3. Run the prompt. 4. Review flagged answers with your security/compliance team before sending to the vendor. 5. Use the output as a draft—customize language to match your company voice and legal requirements.

Example input

**Fact Pack excerpt:**
- SOC 2 Type II certified (expires 2025)
- All data encrypted at rest (AES-256) and in transit (TLS 1.2+)
- Role-based access control (RBAC) via Okta
- Incident response SLA: critical issues within 1 hour
- Annual security training mandatory
- Backup tested quarterly; RTO 4 hours, RPO 1 hour

**Questionnaire excerpt:**
1. Is your company SOC 2 certified? If yes, which type and expiration?
2. What encryption standards do you use for data at rest and in transit?
3. How do you manage access control?
4. What is your incident response time for critical issues?

Example output

**Question 1: Is your company SOC 2 certified? If yes, which type and expiration?**
Answer: Yes, SOC 2 Type II certified. Certification valid through [month/year].
Rationale: Current audit completed by [auditor name]. Type II demonstrates controls over a defined period, not just point-in-time.
Review flag: No

**Question 2: What encryption standards do you use for data at rest and in transit?**
Answer: AES-256 for data at rest; TLS 1.2 or higher for data in transit.
Rationale: Aligns with NIST recommendations and SOC 2 requirements. All systems configured and monitored via [tool name].
Review flag: No

**Question 3: How do you manage access control?**
Answer: Role-based access control (RBAC) via Okta. Access provisioned based on job function; quarterly access reviews conducted.
Rationale: Okta integrates with HR systems for automated provisioning/deprovisioning. Reduces manual error and ensures least-privilege principle.
Review flag: No

**Question 4: What is your incident response time for critical issues?**
Answer: Critical security incidents are acknowledged and initial response initiated within 1 hour of detection.
Rationale: Defined in our Incident Response Plan (v2.1, updated [date]). Escalation path and communication protocol documented.
Review flag: [REVIEW REQUIRED] – Confirm SLA aligns with vendor contract terms before committing.

Customization tips

  • Tailor the fact pack to the vendor's industry and risk profile. For fintech vendors, emphasize encryption and compliance; for HR vendors, focus on data privacy and access controls.
  • Add a 'confidence score' column if your team has varying levels of certainty about controls. Helps prioritize internal review.
  • Include a 'supporting documentation' field in the output so you can attach SOC 2 reports, policies, or audit results directly.
  • For recurring vendors, create a master fact pack and version it. Update once per quarter rather than per questionnaire.
  • If a vendor uses a standard template (Vanta, Secureframe), note the template name in the questionnaire field—the prompt will recognize common question patterns.
  • Flag answers that depend on third-party vendors (e.g., 'our cloud provider is SOC 2 certified'). Verify and attach proof.
  • Use this prompt as a first draft. Always have legal and compliance review before sending, especially for data handling and liability questions.