Security Questionnaire Fatigue
Security Questionnaire Fatigue
The receiving-end phenomenon that pairs with Compliance Cascade: when every enterprise customer sends a supplier its own 200–400 question security assessment (DDQ, SIG, CAIQ, custom), suppliers report 300+ DDQs/yr and "four dozen questionnaires, 200+ questions each" on three-person IT teams. r/cybersecurity ↑139, 123 comments.
The corpus reports responses ranked by effectiveness — practitioner-tested, not vendor claim:
- Trust portal + pre-completed SIG/CAIQ so customers self-serve — anchored on CSA STAR, Google VSAQ
- Answer bank + LLM drafting with mandatory human proofread — most-endorsed
- Push back / escalate when the engagement doesn't warrant it ("100% success rate" — u/moose1882)
- Charge professional services — reported as backfiring commercially
The legal caveat that changes the game — sharpest note in the thread
"Our legal folks cautioned us that these answers can be legally admissible and the risk of inaccurate information could be quite damaging if we had a claim made against us." — u/kielrandor [↑70]
This is why "LLM-drafted + no proofread" is a career-ending mistake. Each answer is a contractual representation the enterprise can be held to when a breach happens.
The contract-language escape hatch that self-defeats
A proposed clause: "informational purposes only… not representations, warranties, or contractual commitments." Immediately flagged as commercially self-defeating:
*"If I saw this in a contract, I'd definitely raise the issue. This tells me that the answers are meaningless."* — u/lawtechie
The customer will not accept a supplier telling them the entire security assessment is non-binding.
The receiving-end scale
- One respondent reported 300 DDQs last year.
- Another "four dozen questionnaires, 200+ questions each" on a three-person IT team.
- "Every customer sends 200–400 questions… half of them are basically the same questions reworded."
The redundancy is what trust portals + standardized frameworks (SIG, CAIQ, VSAQ, STAR) are designed to compress; the enterprise reality is that customers frequently want their own format even when a standard one exists.
Practitioner pattern
The stable pattern the corpus converges on:
- Maintain a canonical answer bank — versioned, owned, quarterly-reviewed for accuracy.
- Front-load it into a trust portal so 70% of customers never send the questionnaire.
- LLM-draft the remaining 30% from the answer bank, then human-proofread every answer for legal admissibility.
- Push back on questionnaires that don't match the engagement's risk shape — the "100% success rate" observation is that customers accept the pushback when the escalation is framed as "you're asking us to sign representations about controls that don't apply to what you're buying."
Cross-links
- Compliance Cascade — the upstream mechanism sending these questionnaires in the first place. Fatigue is what the cascade produces at scale.
- Security Obligation Propagates Via Revenue and Contract — this is the specific paper-flow the commerce mechanism uses.
- Audit Evidence Bar — the escalation the answers face when a customer's audit checks them against reality.
Follow-ups
- Watch for LLM-drafting vendors (Vanta, Drata, RealCISO were named in the source-report) to publish acceptance data — has customer-side acceptance of LLM-drafted answers stabilized or degraded?
- Watch for a legal precedent enforcing questionnaire answers as contractual representations in a real breach case — would harden u/kielrandor's caveat from anecdote to case law.
- Watch for a standards body to publish a rank order of which frameworks (SIG-Lite vs SIG-Core vs CAIQ vs custom) hold up in different regulatory contexts, ideally a decision matrix a CISO can hand to sales.