Questionnaires

Leverage Security Assistant's AI-powered automation to complete vendor questionnaires efficiently

Written By Micah

Security questionnaires are a critical but time-consuming part of the sales process. Whether you're responding to a prospect's security assessment or completing vendor due diligence forms, these questionnaires can contain hundreds of questions that traditionally require hours of manual work to complete.

With Questionnaire you can leverage Security Assistant to automate the heavy lifting. Simply upload your questionnaire, and let Security Assistant analyze the questions and generate comprehensive responses by intelligently pulling from your existing evidence repository.

How Questionnaire works

When you upload a questionnaire, Strike Graph's Security Assistant:

  1. Analyzes the file to identify questions

  2. Searches your evidence repository for relevant documentation

  3. Generates draft responses based on your security policies and controls

  4. Provides references to source documents used

You then review and refine these responses before downloading the completed questionnaire.

Supported file formats

The Questionnaires feature supports:

  • CSV files - Standard comma-separated values format

  • XLSX files - Excel workbooks with single or multiple sheets

Questionnaires often come in many file shapes and sizes, sometimes containing complex formulas or specific formatting. While we do our best to support a broad range of questionnaires, Security Assistant will perform best when your questionnaire has a clear structure with questions in one column and a designated column for responses.

Submitting a new Questionnaire

Step 1: Upload

  1. Navigate to Questionnaires in the main Strike Graph menu

  2. Click Upload Security Questionnaire

  3. Enter a name for your questionnaire (this is for internal reference)

  4. Drag and drop your file or click to browse and select your CSV or XLSX file

  5. Click Submit to proceed

Step 2: Select sheets (Excel Files Only)

If you uploaded an Excel file with multiple sheets:

  1. Review the list of available sheets

  2. Select which sheets that contain questions you need to answer

  3. Make sure that any sheets that contain instructions, examples, or other non-question content are unselected

  4. Click Submit to proceed

Step 3a: Question extraction

Once submitted, Security Assistant will process your file to:

  • Identify and extract all questions

  • Organize questions by their original order

  • Preserve any question numbering or categorization

This initial extraction typically takes 10-30 seconds. You'll see the status listed as 'Submitted' while the questions are being extracted.

Step 3b: Response generation

Once questions are extracted, the system automatically begins generating responses. During this phase, Security Assistant:

  • Analyzes each question to understand the information requested

  • Searches your Evidence Repository for relevant policies, procedures, and documentation

  • Synthesizes responses based on your evidence

This step can take 1-5 minutes depending on the number of questions and other activity on the system. Once the responses are complete, you will receive an email notification.

Step 5: Review and edit responses

Once Security Assistant has taken it's first pass, you can review the responses and make edits where necessary.

Statuses:

  • Resolved: Designates that Security Assistant was able to find enough evidence to confidently answer the question

  • Not Resolved: Indicates that Security Assistant couldn't find enough relevant information to produce a response

To edit responses:

  1. Read through each response

  2. Click the Edit button to modify any response

  3. In the edit modal, you can:

    • Review the question

    • Correct any inaccuracies

    • Update the response status

  4. Click Save to update the response

Step 6: Download completed questionnaire

Once you've reviewed all responses:

  1. Click the Download button in the top toolbar

  2. Choose your preferred format:

    • Download Original - Returns the questionnaire in its original format with your responses filled in

    • Download CSV - Exports questions and answers as a simple CSV file

The downloaded file will contain all your responses in the appropriate columns, ready to send back to your customer or vendor.

Tips and troubleshooting for best results

Optimize your Evidence Repository

Security Assistant will only use the attachments provided in your Evidence Repository to generate responses. Some things to consider to get the best results:

  • Security Assistant ignores evidence that is marked as sensitive. This is helpful if you want to ensure certain information is excluded, such as sensitive PII or other confidential information.

  • It only will reference the most recent attachment per evidence. If you're using a single general evidence item to handle multiple effective attachments, consider duplicating that evidence into more specific evidence items.

  • Evidence does not need to be mapped to a control to be referenced by Security Assistant. This means you can create evidence items for almost anything that you want Security Assistant to be aware of.

Questionnaire formatting

For optimal question extraction:

  • Use clear column headers (e.g., "Question", "Response")

  • Maintain consistent formatting throughout the file

  • Avoid merged cells that might hide questions

  • Remove password protection on sheets that need to be responded to before uploading

Review generated responses

While Security Assistant's responses are generally accurate, always:

  • Verify technical details match your current implementation

  • Add company-specific context where appropriate

  • Ensure the tone matches your organization's communication style

  • Check that responses fully address multi-part questions

If questions are not extracted

If questions aren't properly identified:

  • Verify the file format is supported (CSV or XLSX)

  • Check that questions are in a clear column structure

  • Try selecting specific sheets if using Excel

  • Remove any complex formatting or merged cells

Missing or generic responses

If Security Assistant's responses seem incomplete:

  • Check your Evidence Repository contains relevant documentation

  • Consider creating additional evidence items or uploading additional policies or procedures

  • Manually add responses for highly specific questions

Download issues

If you can't download the completed questionnaire or the responses aren't injected into the correct cells:

  • Ensure all required questions have responses

  • Try the alternative download format (CSV vs Original)

  • Check your browser's download permissions

  • Clear browser cache if problems persist