One hundred buyers, one hundred spreadsheets, the same forty facts
The security questionnaire is the clearest example of work that is repeated because information has no shared shape. The facts a vendor asserts are stable and already audited — what changes each time is only the format of the question.
Last updated:
A vendor selling B2B software to enterprises will, over a year, answer the same question about encryption at rest several dozen times. Same fact, same evidence behind it, same person writing it out — in a different spreadsheet each time, in a slightly different phrasing, into a cell of a different width.
This is not a story about lazy buyers or disorganised vendors. Both sides are behaving rationally. It is a story about what happens when stable information has no shared shape.
The facts do not change; the container does
Consider what a security questionnaire actually asks. Where is data stored. How is it encrypted in transit and at rest. Who are the subprocessors. What is the incident-response commitment. Is there a SOC 2 report, and what is its scope. Is there ISO/IEC 27001 certification, and what does the Statement of Applicability cover.
For any given vendor, these answers are stable for months at a time. They are also already documented — in the audit report, in the certificate scope, in the subprocessor list on the trust page. The vendor is not composing new information. It is transcribing existing information into whatever container arrived this week: one buyer's Excel workbook, another's procurement portal, a third's bespoke PDF with a signature block.
The transcription is where the cost sits, and it is a peculiarly bad kind of cost. It consumes senior security time, because the answers are contractual representations and cannot safely be delegated to sales. It produces nothing reusable, because next week's container will be different. And it is error-prone in the specific way that copying is error-prone: the questionnaire that says "AES-256" in one buyer's file and "industry-standard encryption" in another's is describing the same system, but a careful buyer comparing two vendors cannot tell that.
Standard frameworks help, partially
SIG and CAIQ exist precisely to solve this, and where a buyer accepts a completed standard questionnaire the saving is real. In Japan, buyer-specific チェックシート derived from ISMS control lists play a similar consolidating role.
Adoption is partial, though, and the reason is not obstinacy. A buyer's questionnaire encodes its own risk posture, its own regulator, its own past incidents. The bank that got burned by a subprocessor in 2019 now asks four questions about subprocessors that no standard framework includes. Those additions are legitimate — and each one re-fragments the format.
So the equilibrium holds: mostly-overlapping questions, asked in incompatible containers, answered by hand.
What structure changes
The alternative is not a better spreadsheet template. It is for both sides to exchange structured claims rather than prose.
A vendor maintains one set of assertions — encryption method, data residency, subprocessor list, audit scope and date, breach-notification window — each with the evidence behind it. A buyer asks its own questions, including the four idiosyncratic ones about subprocessors. Where a question maps onto a claim the vendor already maintains, it is answered from the source rather than retyped. Where it does not, a human writes an answer once, and that answer becomes a maintained claim too.
Two things follow. The vendor stops transcribing. And — more valuable to the buyer — the answers arrive already comparable, because every vendor was asked in the same shape. Comparability today is manufactured after the fact, by someone reading five differently-worded PDFs and deciding what counts as equivalent. That reconciliation is not analysis; it is data cleaning that happens to be done by an expensive person.
This is the same pattern we found when we read ten vendors' pricing pages: the information was public and mostly plain, and the work was entirely in putting it on a common footing.
What should not be automated
The judgement. Whether a vendor's data-residency answer is acceptable for your regulator. Whether a SOC 2 scoped only to Security is sufficient for what you are buying. Whether an answer that is technically true is evasive — "we follow industry best practice" is a sentence, not a control.
Those questions need someone accountable for the answer. What they do not need is for that person to spend the preceding three weeks reformatting other people's PDFs so the comparison can begin.
That division — machines normalise, humans decide — is the premise AgentDoor is built on, and the security questionnaire is where the argument is easiest to see: nobody defends the current process on its merits. It persists because no one buyer can fix a format problem that exists between all of them.