Match security questionnaire questions to approved answers
Matches each question to the fitting approved answer in your library and flags ones asking for documents or commitments. A person reviews every match.
Try it on this example
Section heading: 4. Data Protection
Questionnaire question, one row
- Does the row ask a question clear enough to answer?Yes95%
- Which approved answer in the library answers this questionnaire question?ENC-01 Encryption at rest58%
- Does one approved answer in the library answer everything the question asks?No61%
- Does the question ask more than one thing?Yes98%
- Does the question ask for a document, report, certificate or policy to be attached or sent?No90%
- Does the question ask Quillstack to agree to a contractual term rather than describe a practice?No92%
- Which security area does the question belong to, for routing to the right expert?Encryption100%
These are real answers stored from one run on this example.
The prism behind it
Match security questionnaire questions to approved answers
Fields
- Questionnaire question, one row
- Section heading
Context
Security questionnaires sent to Quillstack, a business software company, by customers and prospects. Each row of a questionnaire is read here on its own, with its section heading. The options of the approved answer question are the entries of our answer library. Each entry was written and approved by the security and legal teams, is named by its library id, and is described by what it says. When an entry is chosen, code copies its approved text into the questionnaire. Nothing here writes or changes answer text. A person reviews every questionnaire before it goes back. Rows no single entry fully answers go to the security expert for the row's topic. Rows that ask Quillstack to agree to a contractual term go to legal, because contract terms are agreed only in the contract. Rows that ask for a document are answered from the trust centre.
Questions
Does the row ask a question clear enough to answer? Yes / No
Some rows are headings, instructions to the vendor, or fragments such as "See above" or "Other (please specify)". Yes: The row asks something Quillstack could answer, however it is worded. No: The row is a heading, an instruction, a fragment or otherwise asks nothing that can be answered.
Which approved answer in the library answers this questionnaire question? Choice
Read the question and its section heading, and compare them with what each library entry says. Choose the entry that answers the question. When the question asks several things, choose the entry that answers the most of it; other questions record what is left. Do not choose an entry only because it shares words with the question. When no entry answers any part of the question, none of the listed options fits.
Does one approved answer in the library answer everything the question asks? Yes / No
Compare every part of the question with what the library entries say. Yes: A single entry, as described, answers every part of the question. No: Answering the whole question needs more than one entry, or some part is answered by no entry.
Does the question ask more than one thing? Yes / No
Count separate requests for facts, such as whether something is done, how, and by whom. A question with a follow-up such as "if yes, describe" asks two things. Yes: The question asks two or more separate things. No: The question asks one thing, however long it is.
Does the question ask for a document, report, certificate or policy to be attached or sent? Yes / No
Yes: The question asks for a copy of a document, a report, a certificate, a policy or evidence such as a screenshot. No: The question asks only for a description or an answer.
Does the question ask Quillstack to agree to a contractual term rather than describe a practice? Yes / No
Count questions that ask Quillstack to agree, accept, commit or warrant: an audit right, a notice period, a liability, an indemnity, insurance cover or a service level. A question about what Quillstack does today is a practice, not a commitment. Yes: The question asks Quillstack to agree to a term of this kind. No: The question asks only what Quillstack does or has.
Which security area does the question belong to, for routing to the right expert? Choice
Choose by what the question asks about, not by the section heading alone.
Lens columns
enough_information, enough_information_probability, approved_answer, approved_answer_probability, fully_answered, fully_answered_probability, compound, compound_probability, asks_for_document, asks_for_document_probability, asks_commitment, asks_commitment_probability, topic, topic_probability
Run it on your own text
Add this prism in the app, change any question, and test it on a file of your own.