A corporate client sends a security questionnaire with 140 questions and a two-week deadline. The managing partner forwards it to the administrator, who forwards it to IT, who forwards back questions that only a partner can answer. Two weeks later, a rushed answer set goes out, containing a few claims no one can quite verify.
This cycle repeats at firms of every size, and clients, particularly in financial services, health care, energy and technology, send these more often each year. The fix is not to answer faster but to stop starting from scratch.
Why questionnaires matter
Clients are responsible for vendors that hold their data, and law firms are vendors. A questionnaire is how they document diligence. Outside counsel guidelines often add specific requirements for encryption, breach notice, data location or AI use. Answering well builds trust, and answering sloppily can lose work or create contractual exposure when an answer proves untrue.
Build an answer library
The core idea is to write each answer once, verify it, and reuse it.
Step 1: Gather past questionnaires
Collect every questionnaire the firm has completed, along with insurance applications. Group questions by topic, such as access control, encryption, backup, incident response, vendor management, physical security, personnel, privacy, and AI.
Step 2: Write canonical answers
For each recurring question, write a clear answer in plain language. Include:
- The answer itself. Short, factual, no marketing language.
- The evidence. A policy document, screenshot, report or log that backs it up.
- The owner. The person responsible for keeping the answer true.
- The last verified date. Answers older than a year should be rechecked.
Step 3: Keep it in one place
A shared spreadsheet or a simple document works. Restrict edit access and keep a change history. If the firm grows, specialized tools exist, but a tidy spreadsheet beats an expensive tool no one maintains.
Create a standard security packet
Many clients will accept a concise packet in lieu of, or alongside, their own form. Consider assembling:
- A short security overview describing your controls in plain language.
- A list of your key policies, with excerpts or summaries.
- A description of your incident response process.
- Evidence of training and testing.
- A summary of your cyber insurance coverage, with the policy details your broker confirms you can share.
Confidentiality of the packet itself matters. Share it under appropriate terms.
Handle gaps honestly
Questionnaires often ask about controls the firm lacks. The temptation is to round up. Resist it. Better options are:
- Answer "no" and describe compensating controls.
- Answer "partially" and give a realistic date for completion, then meet it.
- Ask the client whether a specific requirement applies given the nature of the work.
Honest answers also create useful internal pressure. A requirement that appears in several questionnaires is a strong argument for investing in a fix.
Typical questions and where answers come from
Access and authentication
MFA enforcement, role-based access, access reviews, termination procedures. Evidence: MFA coverage report, offboarding checklist.
Data protection
Encryption at rest and in transit, data location, retention and secure deletion. Evidence: encryption settings, retention policy.
Resilience
Backup frequency, offsite and immutable copies, restore testing. Evidence: restore test log.
Monitoring and response
Logging, endpoint detection, incident response plan and testing. Evidence: plan document, tabletop notes.
People
Background checks, training, confidentiality agreements. Evidence: training records.
Third parties
Vendor review, subcontractors, contractual protections. Evidence: vendor inventory.
AI use
Many clients now ask whether and how the firm uses generative AI. Have a written position that aligns with your policy and with the concerns raised in ABA Formal Opinion 512.
Streamline the workflow
- Assign one coordinator for all questionnaires.
- Log each request with its deadline and client.
- Pre-fill answers from the library, then route only new questions to subject owners.
- Have a partner approve before submission.
- Add new answers to the library.
- Track common follow-up requests such as penetration test results or SOC reports and decide your policy on them.
Common mistakes
- Answering from memory without verification.
- Letting different people answer the same question differently across clients.
- Failing to track commitments made in answers, such as a promised date for adopting a control.
- Sending internal documents without confidentiality protection.
Where we help
Counsel Cyber helps firms create the answer library, supply technical evidence, and complete client questionnaires with accurate answers. If your last questionnaire felt like a fire drill, we can help set up a process so the next one takes a fraction of the effort.