What are the questionnaires actually asking?

A typical supplier-assurance questionnaire from a large Australian enterprise customer in 2026 covers seven or eight broad areas, and the shape and weight of the questions has shifted measurably in the last 18 months.

Identity and access: the questions used to be, do you have multi-factor authentication? They are now: is MFA enforced for all users on all critical systems? What MFA factors do you accept, and crucially, do you allow SMS? What is your offboarding SLA when an employee leaves, and how is it evidenced? The shift matters because the answers your business gave in 2023 may not hold up in 2026. SMS-based MFA in particular is increasingly disqualifying for sensitive customer relationships, following well-documented exploitation in 2024 and 2025.

AI use: this is the area that has changed most. Two years ago, AI questions barely appeared in supplier questionnaires. Today they are routine: what AI tools does your team use? Is customer data permitted to enter AI tools? What is your AI use policy? Do you maintain an AI inventory? Is generative AI used in any part of the service you provide to us? The questions reflect customer concern about their own data flowing through commercial AI services without governance, and the shift in enterprise procurement: suppliers without an AI policy are not differentiated from competitors in the same category, they are excluded.

Third-party and supply chain: customers are increasingly asking about your suppliers, not just yourself. Who do you depend on for hosting, identity, payment processing, AI capability, customer support? What assurance do you have on each of them? When did you last review these relationships? The implication is uncomfortable: when a customer asks about your supply chain, they are signalling that incidents in your suppliers will be treated as your incidents in their procurement record. The Optus, Medibank and Latitude breaches earlier this decade established the public precedent. The questionnaires are catching up.

Incident response: the questions used to ask, do you have an incident response plan? They now ask: what is your incident notification SLA to us, what triggers it, who from your organisation makes the call, and how do you preserve evidence? Some customers go further: they reserve the right to participate in incident response, including forensic activity, with the supplier. The supplier-assurance questionnaire that used to be a back-office formality is now an executive-level conversation.

What does this mean commercially?

Three commercial dynamics now run alongside the technical questions, and they shape how a business should respond: security has become a sales asset, standards have become a threshold, and customer contracts now carry incident clauses.

Security has become a sales asset. The businesses that have an opinion on security and AI governance, backed by documented policies, evidence of controls, and ready answers, close commercial deals faster than businesses with comparable products that are still scrambling to fill in the questionnaire. The questionnaire is increasingly the deciding artefact, not the product demo. A measurable share of mid-market deals now hinge on the security wrapper rather than the underlying offer. The businesses that recognise this are using their security posture as a sales asset, sharing policies proactively, having a named contact for assurance questions, and making the answers part of the commercial pitch.

Standards have become threshold. Three frameworks come up consistently in Australian enterprise questionnaires: ASD Essential Eight, ISO 27001, and SOC 2. Full certification of any of these is a meaningful investment for a growth-stage business, but the underlying controls, implemented well and documented honestly, typically pass most customer-assurance processes without formal certification. The pragmatic path is usually to build toward the controls in priority order, document the maturity honestly, and certify when the commercial case justifies it. Premature certification effort is one of the most common ways growth-stage businesses overspend on security.

Customer contracts now carry incident clauses. Increasingly, enterprise customers are inserting incident-notification clauses into supplier contracts on timelines that mirror what regulators ask of regulated entities. Forty-eight or seventy-two hour notification clauses are now common, and the contractual position is now closer to the regulatory position than it was three years ago. This matters because it changes what an incident costs: beyond the operational and reputational impact, an incident now risks contract breach with named enterprise customers, and sometimes triggers chain-reaction notifications to other customers in the same portfolio.

Practical implication: the work is not to scale enterprise security programs down. It is to identify the specific controls that customers actually ask about, build them well, document them honestly, and treat the documentation itself as a commercial artefact. A supplier-ready security pack, short, specific, evidence-based, wins more deals than a 200-page policy library.

What is the deeper shift?

Regulators set baselines. Customers set thresholds. For most Australian growth-stage businesses, the customers are now setting the higher bar.

The work is to understand what that bar actually is, by reading the questionnaires the team is being asked to fill in, and to build toward it deliberately, in order, without consuming the rest of the business in the process.

The good news is that the requirements are well-defined and the controls are well-understood. The harder work is making them visible to customers in a form that turns the questionnaire from a deal-stopper into a deal-accelerator. That is what we work on with our clients in this part of the market.

Action

What we would do this quarter

  1. Build a supplier-ready security packShort, specific, current. Information security policy, AI use policy, incident response plan, MFA enforcement evidence, and a one-page summary that pre-answers the most common questionnaire questions. Maintain it as a living artefact.
  2. Make MFA enforcement non-negotiable across the teamIncluding SaaS, code repositories, payment systems, and AI tools. Where SMS-based factors are still in use for critical systems, plan the migration off them.
  3. Document the AI inventoryWhat tools the team uses, what data is permitted to enter them, who is responsible. The questionnaire question on AI is now routine, and a credible answer requires more than "we don't use AI."
  4. Treat the incident response plan as a commercial artefactIt needs to be specific to your environment, tested against scenarios that match your risk profile, and documented in a form a customer's assurance team can read in ten minutes.
Martin Barnier
Principal Consultant · Lumaris Consulting
View LinkedIn profile