You’ve Answered Forty Security Questionnaires. Do Your Answers Still Agree?
The first security questionnaire is a project. The fortieth is a filing system. Somewhere between them, the answers stop being written fresh and start being copied — from the last deal, from a spreadsheet, from whoever answered it last time. Each answer may create a customer-specific commitment or representation, depending on the deal documents and how the response was provided. Over enough deals, those customer-facing statements and commitments can quietly stop agreeing with each other, and with the product.
This is not a compliance-theater problem. Security addenda and DPA schedules often form part of the contract. Questionnaire responses may also be incorporated by reference, attached to the agreement, or otherwise relevant to the parties’ commitments, depending on the documents and circumstances. When the written description and the product’s actual practices diverge, the gap may surface during a renewal, a customer audit, or diligence.
Key takeaways
- Questionnaire answers can be more than marketing. Depending on the deal documents, they may be incorporated into the agreement, attached as an exhibit, or relevant as pre-contractual representations.
- Drift is cumulative and quiet. It can arise even where no individual answer was inaccurate when given. The inconsistency appears across deals and across time, which is why internal review rarely catches it.
- The product moves faster than the paper. A new subprocessor, a region change, a retention adjustment, or an added AI component can make an accurate answer inaccurate without anyone editing a document.
- Different customers may hold different promises. Bespoke negotiated terms mean the same company can owe materially different obligations to different customers on the same feature.
- The remedy is ownership, not volume. One reviewed source of truth generally beats a larger library of unreviewed answers.
The Fortieth Questionnaire Is a Different Problem From the First
A company answering its first enterprise security questionnaire has one job: answer accurately. There is no history to contradict, no prior deal to reconcile against, and usually one person who knows the whole system.
A company answering its fortieth has a different job, and it is rarely recognized as a different job. The task is no longer “what is true?” It is “what have we already told everyone else, and is this consistent with that?” Those questions get answered by different people, at speed, under deal pressure, often by whoever is closest to the sales cycle rather than closest to the system.
The failure mode is not dishonesty. It is that nobody owns the aggregate.
What Actually Drifts
Drift shows up in predictable places. These are the categories where answers most often stop matching each other or the product:
- Subprocessor and third-party disclosures. A vendor added after a questionnaire was returned may not appear in that customer’s copy, even if a published list was updated later.
- Data residency and processing location. A region commitment made when infrastructure was simpler may not describe where processing occurs now, particularly where a model provider or analytics tool processes elsewhere.
- Retention and deletion timelines. Different customers may be promised different windows, while the platform may operate on a single standard retention setting.
- Encryption and key management specifics. Answers written at one level of detail may not match a later architecture, even where the security posture improved.
- Subcontracting and personnel access. Commitments about who can access customer data may not account for a later support model, contractor arrangement, or offshore team.
- Training and machine learning use. A “we do not use customer data to train models” answer may predate an AI feature that introduces a vendor whose default terms differ.
- Certification and audit scope. A report referenced in an answer may have a defined scope or coverage period that does not include a later-added system component.
- Incident notification timelines. Negotiated windows can vary customer by customer. In practice, the shortest applicable window may become the internal response benchmark, even though the contractual obligation remains customer-specific.
None of these necessarily means anyone made a mistake. They can emerge as a company keeps shipping and its product, vendors, and customer commitments change over time.
Why the Drift Is Invisible Until Someone Asks
Three structural reasons account for most of it.
The answers are not stored where the obligations are. Questionnaire responses tend to live in a sales tool, a shared drive, or a vendor portal. The contract lives somewhere else. Nothing joins them, so nothing compares them.
The reviewer changes. Early answers may be written by a founder or an engineer with whole-system knowledge. Later answers may be written by a sales engineer or a customer success manager working from precedent. Precedent is exactly what propagates a stale answer.
Nothing triggers a re-read. Product changes have release processes. Contract commitments generally do not have a corresponding process that asks which previously returned answers the change affects.
The result is that the first comprehensive read of a company’s own commitments is often performed by someone outside the company — a customer’s auditor, a buyer’s diligence team, or counsel reviewing the relationship.
Security Questionnaire Answers Can Be Commitments, Not Just Marketing
How much weight a questionnaire answer carries depends on how the deal was papered. Commonly, one or more of the following applies:
- the response is attached as an exhibit or schedule and incorporated by reference into the agreement;
- the security addendum or DPA restates the substance of the answers as commitments;
- the agreement includes a representation that information provided during procurement is accurate;
- the answers are not incorporated at all, and function as pre-contractual statements.
These are materially different positions, and a company frequently occupies several of them at once across its customer base. That is worth knowing before an inconsistency is discovered rather than after, because the significance of a given mismatch may depend on which category that customer’s paperwork falls into.
Determining which category applies to a specific agreement is a question for counsel reviewing that agreement. The point here is narrower: the answers should not be treated as disposable sales artifacts; their significance depends on the applicable agreement and the circumstances in which they were given.
Where Your Commitments Actually Live
Before anything can be reconciled, it has to be found. In most growth-stage and mid-market SaaS companies, commitments about data handling are distributed across:
- executed MSAs and their security exhibits;
- DPAs, including customer paper accepted during procurement;
- completed security questionnaires returned by email or through a portal;
- the published subprocessor list and any notice mechanism referenced in the DPA;
- the public privacy notice and any product-specific data documentation;
- trust-center or security-page content, which customers or their auditors may rely on during procurement and diligence;
- sales collateral and RFP responses;
- audit, attestation, and certification reports and their stated scope.
A company does not need all of this in one system. It needs to know that all of it exists, and which of it is authoritative when two sources disagree.
Building a Single Source of Truth
The practical remedy is unglamorous. A practical governance approach generally has four parts:
- One maintained answer set with a named owner, reviewed on a stated cadence rather than only when a deal requires it.
- A record of what was sent to whom, and when. Without this, a company cannot answer the question a customer will eventually ask, which is what it was told and on what date.
- A change trigger. Adding a subprocessor, changing a processing region, altering retention, or introducing an AI component prompts a review of which returned answers the change affects.
- An exception log for customers who negotiated something bespoke, so the non-standard commitments are visible rather than buried in an executed PDF.
This is closer to an operational discipline than a legal deliverable. Counsel’s role is usually to establish what the commitments actually are and what the applicable agreements require, so the operational process is built around accurate inputs.
What to Check Before Your Next Renewal Cycle
Renewals and customer audits are where drift surfaces. A focused review ahead of that window generally covers:
- whether the subprocessor list reflects every vendor currently processing customer data, including any added for AI functionality;
- whether returned answers about training, retention, residency, and access still describe the product;
- whether the shortest notification window promised to any customer is the one operations is actually built to meet;
- whether certification scope covers the components customers are asking about;
- whether any customer negotiated terms that differ from the standard set, and whether those are tracked anywhere other than the signed document;
- whether the public trust page and the executed paper say the same thing.
If You Have Already Found a Mismatch
Finding a mismatch does not, by itself, determine the contractual consequences. What matters is the response.
The first step is scope: identifying which customers received the affected answer, what each of their agreements requires, and whether the applicable agreement specifies a notice or update process. That analysis is contract-specific, and the right sequence depends on what the paperwork says. Nothing here suggests deferring a notice or disclosure that an applicable agreement requires.
Subject to any applicable notice or disclosure requirement, a broad unilateral communication issued before anyone has determined what each agreement requires, or a quiet correction to a public page with no record of what changed, may create additional issues beyond the underlying inconsistency.
This is a situation where the order of operations matters, and where an attorney reviewing the specific agreements should assess and plan the appropriate approach.
How Accord & Shield Legal Helps
Accord & Shield Legal works with SaaS and technology companies in Arizona, California, and Texas on the contract side of this problem: reading what the executed agreements actually require, identifying where returned commitments and current operations diverge, and structuring a standard answer set and exception log that a growing company can maintain.
The firm also works with companies on an ongoing outside general counsel basis, which may be a workable arrangement where the review needs to recur, because it is not a one-time project — it recurs every time the product changes.
Related reading: AI Subprocessor Notice: What Your Customer DPAs Require; Your First Enterprise Customer Sent a 50-Page MSA; Diligence-Grade Contracts.
This article provides general information, not legal advice. Whether a given questionnaire answer is contractually binding, and what any inconsistency requires, depend on the specific agreements a company has signed, the categories of data involved, the relevant data flows and vendor configuration, the customer base, and the laws applicable to those customers. Reading this article does not create an attorney-client relationship. For guidance on a specific situation, consult qualified counsel.
New laws, before they catch you off guard.
Monthly. New Arizona, California, and Texas business-law changes, the deadlines attached to them, and what they mean in practice. No spam — unsubscribe anytime.
By subscribing you agree to receive emails from Accord & Shield Legal, PLLC. This is general information, not legal advice.
Frequently asked questions
Is a security questionnaire answer legally binding?
It depends on how the deal was papered. Questionnaire responses are sometimes attached as an exhibit and incorporated by reference into the agreement, sometimes restated in a security addendum or DPA, and sometimes addressed by a representation that information provided during procurement is accurate. In other deals they are not incorporated at all. Because the same company often occupies several of these positions across its customer base, the weight a particular answer carries is a question for counsel reviewing that specific agreement.
What is commitment drift?
It describes what happens when the security and data-handling commitments a company has made across many customers gradually stop agreeing with each other and with the product. It can arise even where no individual answer was inaccurate when given. The inconsistency accumulates as the product changes and as answers are copied from prior deals.
How often should we review our security questionnaire answers?
A stated cadence generally works better than reviewing only when a deal requires it. Many companies pair a periodic review with a change trigger, so that adding a subprocessor, changing a processing region, adjusting retention, or introducing an AI component prompts a review of which previously returned answers the change affects.
What happens if we discover an answer is no longer accurate?
Before communicating externally, identify the applicable agreement, the statement at issue, the current product practice, and any timing or notice provisions. The appropriate next step, including whether and how to communicate with the customer, is contract-specific. Nothing here suggests deferring a notice or disclosure that an agreement in fact requires. A broad unilateral notice issued before that analysis, or a quiet edit to a public page with no record of what changed, may create additional issues beyond the underlying inconsistency.
Do we have to tell a customer if a past answer has changed?
That depends on the applicable agreement. Some agreements include notice or update mechanisms that address changes to security commitments or subprocessors; others do not address it directly. Whether notice is required, and on what timeline, needs to be determined from the specific paperwork with that customer.
Who should own security questionnaire answers internally?
A named owner matters more than which function it sits in. In practice the answer set is usually maintained by security, legal, or a dedicated GRC function, with input from engineering on what the system actually does. A common failure mode is having no clear owner, which can allow answers to be written from precedent under deal pressure.
Does a SOC 2 report cover this?
Not by itself. A SOC 2 report has a defined system scope and reporting period, and describes the service organization’s controls within that scope. It does not reconcile what a company told individual customers in negotiated paperwork, and a component added after the report period may fall outside its scope. Customers may ask about the relationship between the two.
How does this relate to subprocessor notice obligations?
They are adjacent problems. Adding a subprocessor may trigger notice obligations under an applicable DPA, and it can simultaneously make previously returned questionnaire answers inaccurate. A company handling only the notice obligation may still be carrying stale answers with customers who were not part of that notice.
We are a smaller company with only a few enterprise customers. Does this apply?
The operational and contractual complexity often scales with the number of separately negotiated commitments, not headcount. A company with a handful of enterprise customers on bespoke paper can still have materially different commitments to reconcile, while a company with many customers on one standard form may have very little. The question is how many different sets of promises exist, not how large the company is.