ABA Model Rule 1.6 aligned24/7 security operations monitoringAustin, TX ยท Serving TX, AR, LA, OK & KS
(737) 325-2520

Answering Client Security Questionnaires Without Starting Over

How to build a reusable answer library for client security questionnaires and outside counsel guidelines, with evidence, owners and honest gap handling.

3 min readBy Counsel Cyber Team

A corporate client sends a security questionnaire with 140 questions and a two-week deadline. The managing partner forwards it to the administrator, who forwards it to IT, who forwards back questions that only a partner can answer. Two weeks later, a rushed answer set goes out, containing a few claims no one can quite verify.

This cycle repeats at firms of every size, and clients, particularly in financial services, health care, energy and technology, send these more often each year. The fix is not to answer faster but to stop starting from scratch.

Why questionnaires matter

Clients are responsible for vendors that hold their data, and law firms are vendors. A questionnaire is how they document diligence. Outside counsel guidelines often add specific requirements for encryption, breach notice, data location or AI use. Answering well builds trust, and answering sloppily can lose work or create contractual exposure when an answer proves untrue.

Build an answer library

The core idea is to write each answer once, verify it, and reuse it.

Step 1: Gather past questionnaires

Collect every questionnaire the firm has completed, along with insurance applications. Group questions by topic, such as access control, encryption, backup, incident response, vendor management, physical security, personnel, privacy, and AI.

Step 2: Write canonical answers

For each recurring question, write a clear answer in plain language. Include:

  • The answer itself. Short, factual, no marketing language.
  • The evidence. A policy document, screenshot, report or log that backs it up.
  • The owner. The person responsible for keeping the answer true.
  • The last verified date. Answers older than a year should be rechecked.

Step 3: Keep it in one place

A shared spreadsheet or a simple document works. Restrict edit access and keep a change history. If the firm grows, specialized tools exist, but a tidy spreadsheet beats an expensive tool no one maintains.

Create a standard security packet

Many clients will accept a concise packet in lieu of, or alongside, their own form. Consider assembling:

  1. A short security overview describing your controls in plain language.
  2. A list of your key policies, with excerpts or summaries.
  3. A description of your incident response process.
  4. Evidence of training and testing.
  5. A summary of your cyber insurance coverage, with the policy details your broker confirms you can share.

Confidentiality of the packet itself matters. Share it under appropriate terms.

Handle gaps honestly

Questionnaires often ask about controls the firm lacks. The temptation is to round up. Resist it. Better options are:

  • Answer "no" and describe compensating controls.
  • Answer "partially" and give a realistic date for completion, then meet it.
  • Ask the client whether a specific requirement applies given the nature of the work.

Honest answers also create useful internal pressure. A requirement that appears in several questionnaires is a strong argument for investing in a fix.

Typical questions and where answers come from

Access and authentication

MFA enforcement, role-based access, access reviews, termination procedures. Evidence: MFA coverage report, offboarding checklist.

Data protection

Encryption at rest and in transit, data location, retention and secure deletion. Evidence: encryption settings, retention policy.

Resilience

Backup frequency, offsite and immutable copies, restore testing. Evidence: restore test log.

Monitoring and response

Logging, endpoint detection, incident response plan and testing. Evidence: plan document, tabletop notes.

People

Background checks, training, confidentiality agreements. Evidence: training records.

Third parties

Vendor review, subcontractors, contractual protections. Evidence: vendor inventory.

AI use

Many clients now ask whether and how the firm uses generative AI. Have a written position that aligns with your policy and with the concerns raised in ABA Formal Opinion 512.

Streamline the workflow

  1. Assign one coordinator for all questionnaires.
  2. Log each request with its deadline and client.
  3. Pre-fill answers from the library, then route only new questions to subject owners.
  4. Have a partner approve before submission.
  5. Add new answers to the library.
  6. Track common follow-up requests such as penetration test results or SOC reports and decide your policy on them.

Common mistakes

  • Answering from memory without verification.
  • Letting different people answer the same question differently across clients.
  • Failing to track commitments made in answers, such as a promised date for adopting a control.
  • Sending internal documents without confidentiality protection.

Where we help

Counsel Cyber helps firms create the answer library, supply technical evidence, and complete client questionnaires with accurate answers. If your last questionnaire felt like a fire drill, we can help set up a process so the next one takes a fraction of the effort.