Most of what any client security questionnaire asks falls into five areas. Work through this checklist before you answer: confirm each item is genuinely true, and use the phrasing notes to write answers that are clear, provable, and honest. If an item isn't in place yet, that's fine — say so, with a plan. Never check a box you can't back up.
1. Access & identity
The most-asked area, and the one insurers weight most heavily.
- Multi-factor authentication (MFA) is on for everyoneEmail, file storage, and any admin login. Answer: "Yes — MFA is enforced on all accounts; we can provide a configuration export."
- Every person has a unique login — no shared accountsShared logins are an automatic red flag. If you have any, note the plan to remove them.
- Access is removed the day someone leavesHave a documented offboarding step. Reviewers ask how fast, not just whether.
- Admin access is limited to who needs itLeast privilege. Note who holds admin and why.
2. Devices
Every laptop that touches client work — Macs included.
- Devices are centrally managedOne system enforces settings across the fleet, not device-by-device trust.
- Disk encryption is onFileVault on Mac, BitLocker on Windows. A lost laptop shouldn't mean a data breach.
- Malware/endpoint protection is runningActive protection, not just the OS default, with visibility if something fires.
- Updates and patches are enforcedOut-of-date software is the most common way in. Confirm it's automatic.
- A lost device can be locked or wiped remotelyEspecially for freelancers and travel.
3. Threat detection & response
Proof you'd catch a bad day and act.
- Something malicious would be detectedMonitoring on email and devices — describe how you'd know.
- There's a written incident-response planWho does what, and who gets notified, if there's a breach. Attach it.
- You can meet a breach-notification timelineMany contracts require notice within a set window. Know yours.
4. Data & backup
Where their work lives, and whether you could get it back.
- You know where client data is storedName the systems. "Scattered across email and an unmanaged drive" fails.
- Sharing with freelancers is controlledTime-boxed access that's removed when the project ends.
- Backups exist and have been testedRecoverable after ransomware or a mistake — and you've actually restored one.
- Subprocessors/vendors are trackedThe tools you use on client data (including AI tools) — clients increasingly ask.
5. Process & policy
The documents that turn "we do this" into evidence.
- Written security policies existAcceptable use, access control, data handling, incident response. Many questions map straight to "attach your [X] policy."
- Security-awareness training happensPeople are the top attack vector; show you train them.
- Answers are reviewed before they go backOne owner signs off so nothing overstated leaves the building.
- You keep your answers to reuseThe next client's questionnaire is ~70% the same. Save the work.
That's the core. For the step-by-step on how to actually run a questionnaire from inbox to sent, read what to do when a client sends a security questionnaire, or the fuller guide to passing an enterprise security review.