Answering a Client Security Questionnaire
By Yong DuPublished Reviewed
A managed services provider is the vendor in their client's compliance assessment. What the questions ask, and what evidence answers them.
On this page
You are the finding
A client running a compliance assessment reaches a question about service providers. In ClearBreach's own generated sample it reads:
Do your arrangements with them require comparable protection of that information?
The provision: PIPEDA Schedule 1, Principle 1 (4.1.3), contractual or other means · Joint BC/AB OIPC Security Assessment (2020) s.4.17
When that comes back as a gap at your client, you are the arrangement it is about. The questionnaire on your desk is that finding, sent to you to close.
This is the useful way to read it. It is not procurement friction and it is not distrust. Your client has a duty under 4.1.3 and cannot discharge it without something from you in writing.
What the questions are really asking
Most questionnaires, whatever their length, circle six things.
Who is accountable. PIPEDA Principle 4.1, Alberta PIPA s.5(3), BC PIPA s.4(3): a designated individual. The question is whether one exists and whether they know it.
What is written down. A privacy policy staff can find and read is a duty in its own right. The written limb is PIPEDA clause 4.1.4(d), the findable one is 4.1.4(c), and Alberta PIPA s.6(1) and s.6(3), BC PIPA s.5(a). "We take security seriously" is not an answer to it.
Who can reach what, and how that is reviewed. Access control, joiners and leavers, privileged accounts.
How long you keep things, and what happens then. PIPEDA clause 4.5.3, Alberta PIPA s.35(2) and BC PIPA s.35(2) all require destruction or de-identification once the purpose is served. A retention answer with no disposal step is half an answer.
What happens after a breach. Not just detection, who you tell, how fast, and what you record. PIPEDA s.10.3(1) requires a record of every breach of security safeguards, including those found not reportable.
What the contract says. Comparable protection, and prompt notification in both directions.
The answer that saves the most time
Every one of those is a question your own compliance assessment already asks, of you, as an organization. A provider who has run one has the answers as artefacts rather than as prose written under a deadline: a written policy, a retention schedule, an incident response plan, an inventory of what is held and where.
That is the difference between an afternoon and a week. It is also the difference between an answer a client can file as evidence and an email they have to take on trust.
Answering a gap honestly
Some questions will land on something you do not have. The instinct is to soften it. Do not.
A stated gap with a date attached, "not yet documented; scheduled for Q4", is an ordinary answer. Clients accept them, record them, and move on. An overstated answer is a representation the client relies on when they tell their regulator that comparable protection is in place. When it turns out not to be, it is their problem first and yours immediately afterwards.
The questionnaire is a compliance record on both sides of the table.
What not to send
Your own clients' information. A named example from another engagement is a disclosure, and the fastest way to fail the questionnaire you are answering.
A certificate instead of an answer. An attestation is evidence of a scope somebody else defined. It supports an answer; it does not replace one.
More than was asked. Every extra claim is another thing that has to stay true.
Related
- Onboarding a client: the privacy questions worth asking in week one
- Offboarding a client: what happens to their privacy records
- A breach at a client, and who notifies whom
- All four guides for managed service providers
- How the ClearBreach MSP account works, including running the assessment that produces these answers
Frequently asked questions
Why is a client sending us a security questionnaire?
Because PIPEDA Schedule 1 clause 4.1.3 makes them responsible for personal information they transfer to you, and requires them to use contractual or other means to provide a comparable level of protection while it is with you. The questionnaire is how they satisfy that clause. It is not a formality and it is not distrust, it is the evidence they will be asked for if a regulator ever looks.
What is the fastest way to answer one?
Have the answers before you are asked. Almost every questionnaire circles the same ground: who is accountable, what is written down, how access is controlled, how long information is kept, what happens after a breach, and what the contract says. A provider with those documented answers a questionnaire in an afternoon; one without spends a week writing them for the first time under a deadline.
Do we have to answer questions about our own privacy compliance?
You are an organization holding personal information, so the underlying duties apply to you the same way they apply to your clients. A questionnaire asking whether you have a designated privacy officer, a written policy and a breach record is asking about your own obligations under PIPEDA, Alberta PIPA or BC PIPA, not only about your suitability as a supplier.
What if we cannot answer a question honestly?
Say so, and say what you are doing about it. A gap stated with a date attached is a normal answer that a client can accept and record. An overstated answer is a representation the client relies on, which becomes their problem and then yours when it turns out not to be true.
This guide is educational and does not constitute legal advice. It is grounded in the text of PIPEDA, Alberta PIPA, and BC PIPA and published guidance from the OPC, OIPC Alberta, and OIPC BC. If your situation involves regulatory investigation, litigation risk, or circumstances not addressed here, engage a qualified privacy lawyer.
See what a compliance assessment finds
A real assessment for a small clinic: every area scored, every gap against the provision behind it, and the documents that close them.
See a complete assessment →