HomeResources › Guides
Guide

Which documents a vendor assessment needs

Four documents carry most of a review: questionnaire, evidence, contract and policies. Everything else supplements them. This list shows what each document proves and what to do when one is missing.

Leapfacto editorial · 16 September 2026

The four documents

1

Questionnaire

What the provider claims about itself: controls, responsibilities, subprocessors, deletion periods.

2

Certificates and audit reports

What a third party confirms: scope, review period, validity.

3

Contract including data processing

What is binding: term, termination, subprocessing, deletion.

4

Policies and procedures

How the provider works: access rules, incident plan, reporting paths.

Supporting documents

  • A list of subprocessors, with role and location.
  • Results of penetration tests or vulnerability scans.
  • Incident response and recovery plan.
  • The scope of certifications: a certificate without a scope says little.
  • Contacts and escalation paths for the incident case.

When a document is missing

A missing document is the normal case, not the exception. What matters is how it is handled: the gap is reported, not estimated. Filling a missing data point with a probability gives you one more problem in an audit, not one less.

Then comes the request, with a deadline. If the document does not arrive, the item stays open and goes to a decision: accept it with a reason, or block it. Both are fine as long as they are documented.

The third option is the most common one: the document exists, just somewhere else. That is exactly what a review set with sources is for.

How the documents stay current

  • Record expiry dates, not just files: a certificate without a date says nothing.
  • Derive review dates from the evidence instead of setting them freely.
  • Request updates on change: new subprocessors, new location, new version of a questionnaire.

Short checklist

  • The provider questionnaire, complete and dated.
  • Evidence with scope and validity.
  • Contract and data processing agreement in the current version.
  • Policies that match the review.
  • Open points as a list, not as a note.

Note

This article explains how we work. Regulatory duties and their interpretation are for your compliance function to settle.