PDRIGHT Book a fit call

Home / Insights / Questionnaire checklist

The Agency Security Questionnaire Response Checklist

Checklist · Free resource · 5 min

Most of what any client security questionnaire asks falls into five areas. Work through this checklist before you answer: confirm each item is genuinely true, and use the phrasing notes to write answers that are clear, provable, and honest. If an item isn't in place yet, that's fine — say so, with a plan. Never check a box you can't back up.

1. Access & identity

The most-asked area, and the one insurers weight most heavily.

  • Multi-factor authentication (MFA) is on for everyoneEmail, file storage, and any admin login. Answer: "Yes — MFA is enforced on all accounts; we can provide a configuration export."
  • Every person has a unique login — no shared accountsShared logins are an automatic red flag. If you have any, note the plan to remove them.
  • Access is removed the day someone leavesHave a documented offboarding step. Reviewers ask how fast, not just whether.
  • Admin access is limited to who needs itLeast privilege. Note who holds admin and why.

2. Devices

Every laptop that touches client work — Macs included.

  • Devices are centrally managedOne system enforces settings across the fleet, not device-by-device trust.
  • Disk encryption is onFileVault on Mac, BitLocker on Windows. A lost laptop shouldn't mean a data breach.
  • Malware/endpoint protection is runningActive protection, not just the OS default, with visibility if something fires.
  • Updates and patches are enforcedOut-of-date software is the most common way in. Confirm it's automatic.
  • A lost device can be locked or wiped remotelyEspecially for freelancers and travel.

3. Threat detection & response

Proof you'd catch a bad day and act.

  • Something malicious would be detectedMonitoring on email and devices — describe how you'd know.
  • There's a written incident-response planWho does what, and who gets notified, if there's a breach. Attach it.
  • You can meet a breach-notification timelineMany contracts require notice within a set window. Know yours.

4. Data & backup

Where their work lives, and whether you could get it back.

  • You know where client data is storedName the systems. "Scattered across email and an unmanaged drive" fails.
  • Sharing with freelancers is controlledTime-boxed access that's removed when the project ends.
  • Backups exist and have been testedRecoverable after ransomware or a mistake — and you've actually restored one.
  • Subprocessors/vendors are trackedThe tools you use on client data (including AI tools) — clients increasingly ask.

5. Process & policy

The documents that turn "we do this" into evidence.

  • Written security policies existAcceptable use, access control, data handling, incident response. Many questions map straight to "attach your [X] policy."
  • Security-awareness training happensPeople are the top attack vector; show you train them.
  • Answers are reviewed before they go backOne owner signs off so nothing overstated leaves the building.
  • You keep your answers to reuseThe next client's questionnaire is ~70% the same. Save the work.

That's the core. For the step-by-step on how to actually run a questionnaire from inbox to sent, read what to do when a client sends a security questionnaire, or the fuller guide to passing an enterprise security review.