Classify the supplier, tick what they have access to and keep the questions that actually matter. Each one comes with the control it derives from in ISO 27001, NIST CSF 2.0, ENS, TISAX, GDPR, the AI Act and ISO 42001. At the end you take away a PDF with fillable fields, so the supplier can answer without printing anything.
The bottled water supplier does not need the same questions as whoever administers your ERP with privileged access. Sending them both the same hundred-question form wastes your time, burns the relationship with the supplier and dilutes your attention on the few that genuinely matter. This tool does what has to happen before you ask anything: classify.
Legal notice
This tool generates an indicative questionnaire for educational purposes. It is not legal advice and does not replace a third-party risk management programme, which on top of the questionnaire needs an inventory, documented classification, contractual clauses, treatment of results, reassessment and an exit process. The mapping to each framework's controls is a working reference: the precise scope is set by each standard in its own text.
Everything runs in your browser: neither your selection nor the PDF leaves your device. There are no cookies, third-party resources or usage measurement: downloads and your interactions with the tool are not recorded. Regulatory content last reviewed: .
Two decisions. The first sets how deep the questionnaire goes; the second, which topic blocks make sense. This is phase 2 of the methodology: classify before you ask.
Pick a criticality level to see how many questions I suggest.
They come preselected from what you ticked. Remove the ones that are no use to you and add any you want: the ones marked mandatory stay. The rule is simple: do not send a question whose answer you are not going to analyse.
This is what you have built and what it covers. The two fields below are optional: if you fill them in, they are printed in the PDF; if you leave them blank, they stay as fillable fields for whoever receives it.
The number of distinct controls your selection touches in each reference framework. It is not a measure of compliance: it is the traceability of the questionnaire.
The PDF carries fillable fields: the supplier answers in the document itself and sends it back, with no printing and no scanning. If you would rather paste it into an email, copy the text.
The PDF is generated in your browser. Nothing is sent to any server.
Most supplier assessment programmes are abandoned by the third round because nobody does this part. With the answers on the table, four things should come out.
Rated by likelihood and impact on your business, not on the supplier's. It is your operation that stops.
What should exist given their criticality tier and does not. What is missing, not what is surplus.
With an owner and a date, agreed with the supplier. A finding with no owner does not get fixed.
Accept, accept with conditions, require mitigation before signing, or reject. In writing, and by someone with the authority to do it.
Every question available, with its regulatory anchor and the criticality tier from which I suggest it. You can read them here as a reference or build your questionnaire and take the PDF away.
«Mandatory» means it goes into every questionnaire, including those for low-risk suppliers. «Tier 2+» and «Tier 3+» are suggested from significant and critical suppliers respectively, and those carrying an applicability criterion only appear if that criterion is ticked in step 1.