---
title: "VSAQ: Vendor Security Assessment Questionnaire"
url: "https://www.arphie.ai/glossary/vsaq"
collection: glossary
lastUpdated: 2026-07-31T20:26:45.606Z
---

# VSAQ: Vendor Security Assessment Questionnaire

VSAQ stands for **Vendor Security Assessment Questionnaire**. Google created this open-source framework to collect and review information about a third party's security and privacy program. Its self-adapting questionnaires reveal follow-up questions based on earlier answers, so vendors see relevant branches instead of one fixed checklist.



The [Google VSAQ repository](https://github.com/google/vsaq) is now archived and read-only. It also states that VSAQ is not an official Google product. The framework remains a useful reference, but organizations should review its questions against current risks, technology, legal requirements, and assessment standards.



If you are answering VSAQ, [Arphie's AI agents](https://www.arphie.ai/platform) can provide the source and review layer around the requester's format. Arphie can draft from your knowledge base and connected company sources, show the sources used and an AI confidence level, and give owners, writers, and reviewers a shared place to comment and sign off. Arphie supports native import and export for Word and Excel questionnaires. Depending on the requester's required VSAQ format, confirm the handoff in advance; a final transfer step may still be needed.



## Which VSAQ does this definition cover?



This page covers Google's **Vendor Security Assessment Questionnaire**. Two other questionnaires are easy to confuse with it:



- **Vendor Security Alliance questionnaire:** The Alliance issues two questionnaires, [VSA-Full and VSA-Core](https://www.vendorsecurityalliance.org/downloadQuestionaire). [Vanta](https://www.vanta.com/collection/trust/vendor-security-alliance-questionnaire) and [UpGuard](https://www.upguard.com/blog/vendor-security-alliance-questionnaire) also call these Alliance questionnaires "VSAQ," using the same acronym used by the separate, now-archived [Google VSAQ application](https://github.com/google/vsaq) named Vendor Security Assessment Questionnaire. In a vendor-security request, VSA-Full, VSA-Core, or a vendorsecurityalliance.org link identifies the Alliance questionnaire. The bare label VSA is supporting context but may need confirmation if the request is otherwise unclear.



- **Veterans Specific Activity Questionnaire:** Medical literature also uses VSAQ for a [clinical questionnaire that estimates exercise tolerance](https://pmc.ncbi.nlm.nih.gov/articles/PMC5351828/). It is unrelated to vendor security.



## What does the Google VSAQ cover?



Google [open-sourced four generally applicable templates](https://opensource.googleblog.com/2016/03/scalable-vendor-security-reviews.html):



| Template | What it examines | Typical evidence to prepare |
| --- | --- | --- |
| **Web Application Security Questionnaire** | Application metadata, vulnerability handling, TLS, authentication and authorization, common web vulnerabilities, cryptography, testing, quality assurance, and post-launch monitoring. | Secure development standards, application architecture, vulnerability-management procedures, and testing summaries. |
| **Security & Privacy Program Questionnaire** | Governance, policies, privacy, incident handling, personnel practices, and the wider security program. | Security and privacy policies, assurance reports, risk records, incident plans, and training material. |
| **Infrastructure Security Questionnaire** | Systems, networks, access, hardening, monitoring, and other infrastructure controls. | Architecture and data-flow diagrams, access-control standards, encryption documentation, logging evidence, and backup procedures. |
| **Physical & Data Center Security Questionnaire** | Facilities, physical access, environmental protections, and data center operations. | Data center provider and location details, facility certifications, access-control procedures, entry logs, and environmental-monitoring records. |



These are extensible templates, not a certification standard. Select the templates relevant to the service under review. For example, a software-as-a-service assessment could draw on the program, web application, and infrastructure templates, while a hosting or colocation assessment could also require the physical and data center template.



That scope matters when reusing content. In Arphie, you can connect the organization-selected repositories and evidence files that should be available for drafting. Reviewers can then inspect which source informed an answer and confirm whether its scope matches the product, deployment model, region, and assessment period in question.



## How the VSAQ review workflow works



The [reference workflow in Google's repository](https://github.com/google/vsaq) has five steps:



- **The reviewer sends the applicable questionnaire links.** The scope should reflect the service, data, integrations, hosting model, and risks under review.



- **The vendor completes the questions.** Security, privacy, engineering, legal, people operations, and facilities contributors provide facts for the domains they own.



- **The vendor exports its answers.** In Google's reference implementation, the vendor uses the Save button to create an answer file.



- **The vendor returns the answer file.** The transfer method should match the sensitivity of the information.



- **The reviewer loads the answers for review.** The reviewer opens the same questionnaire and imports the answer file.



The loaded response supports the reviewer's assessment. The reviewer may then ask follow-up questions, request evidence, record exceptions, or require remediation.



The open-source client can run without a dedicated back end. Google recommended adding a custom server-side component for high-throughput programs that need to store answers and map questionnaires to users. Modern teams also need a reliable way to retrieve current sources, coordinate owners, track deadlines, and preserve review decisions.



[Arphie's questionnaire workflow](https://www.arphie.ai/features) supports the response work around steps two through four rather than replacing the VSAQ process. Use connected knowledge to prepare a first draft, inspect its sources and confidence level, coordinate exceptions through roles, comments, and teammate tags, and obtain human approval. Complete the final handoff in the format and channel the reviewer expects.



## How vendors should prepare for a VSAQ



Start with a governed evidence set rather than the nearest completed questionnaire. Useful sources often include:



- Security and privacy policies.



- Current assurance reports and certificates, including scope and validity dates.



- Architecture and data-flow diagrams.



- Access control, encryption, key management, logging, and monitoring standards.



- Secure software development and vulnerability management procedures.



- Incident response and breach-notification procedures.



- Business continuity and disaster recovery plans, including tested recovery objectives.



- Subprocessor, hosting, and data-location information.



- Penetration test summaries and remediation status.



- Named owners who can validate claims in each domain.



For every reusable source or answer, record its owner, applicable product or region, review date, and permitted audience. A claim can be accurate for one service and false for another. If your evidence lives across policy libraries, SharePoint, Confluence, or Google Drive, [Arphie lets your organization control which repositories and files are connected](https://www.arphie.ai/platform). Reviewers still confirm the product, region, validity date, and permitted audience before relying on that evidence.



## A reliable process for completing VSAQ answers



Follow these steps in order. Each one closes a different source of error before the response reaches the reviewer.



- **Confirm the assessment scope.** Identify the product, deployment model, data types, integrations, hosting locations, and services covered. Mark a question not applicable only when the reason is clear. **Why it matters:** Without an explicit scope, a fact that is accurate for one service, region, or deployment can become a false claim about another.



- **Retrieve current sources before drafting.** Use current policies, control evidence, and product documentation from the systems selected for the assessment instead of relying on memory or an old submission. **Why it matters:** This reduces stale, conflicting, or out-of-scope answers before they enter the review cycle.



- **Draft with traceability.** State the control directly, then add the scope, frequency, or exception needed to make the answer accurate. Arphie's AI agents show the exact sources used and a confidence level, so reviewers can trace a draft before approving it. **Why it matters:** Traceability lets reviewers verify claims quickly and spend more time on weakly sourced or low-confidence answers. A high confidence level is still not approval.



- **Route each claim to its factual owner.** Engineering should validate application and infrastructure controls, privacy and legal should review data-use and contractual statements, and people operations may own screening and training. Arphie's owner, writer, and reviewer roles, question comments, and teammate tags can coordinate those contributors. **Why it matters:** Visible ownership keeps polished wording from bypassing the subject-matter expert who is accountable for the underlying fact.



- **Attach evidence deliberately.** Share only the material required for the assessment, use an appropriate secure channel for sensitive reports, diagrams, or test results, and let the accountable owner decide what the requester may receive. **Why it matters:** Evidence makes the response verifiable without exposing more sensitive information than the review requires.



- **Review commitments, exceptions, and final wording.** Record compensating controls, open remediation, and target dates instead of hiding an exception behind vague language. Use comments and reviewer roles in Arphie to resolve exceptions and obtain sign-off from the accountable owner. **Why it matters:** A final commitment review prevents ambiguous language or an AI-polished draft from creating obligations the organization cannot support.



- **Complete the response in the required VSAQ format.** Google's reference workflow uses its interactive questionnaire and exported answer file. After the wording is validated and approved, confirm how it will enter that workflow and complete any required transfer step before saving and returning the answer file. **Why it matters:** An accurate answer is not useful to the requester if it is delivered in the wrong file, workflow, or channel.



- **Preserve only approved reusable knowledge.** After submission, capture corrected language, new evidence, and the owner's approval in the response knowledge base rather than treating every submitted answer as reusable. **Why it matters:** Governed reuse speeds up the next assessment without spreading one-off wording, expired evidence, or an answer tied to the wrong scope.



## What VSAQ does not prove



A completed VSAQ is information for an assessment. It is not a security certification, penetration test, legal opinion, or guarantee that a vendor has no risk. The reviewer still evaluates the answers, evidence, service scope, exceptions, and any additional testing or contractual requirements.



The public framework also reflects the period in which its templates were maintained. Because the repository was archived on November 25, 2022, organizations should consider whether their current assessment needs newer questions about artificial intelligence, cloud architecture, software supply chains, privacy obligations, operational resilience, or industry-specific requirements.



Other frameworks may fit some programs better. The [Cloud Security Alliance CAIQ](https://cloudsecurityalliance.org/artifacts/cloud-controls-matrix-v4-1) focuses on cloud controls, while the [Shared Assessments SIG](https://sharedassessments.org/sig/) spans a broad set of third-party risk domains. A customer may also send a proprietary questionnaire. Vendors should answer the instrument requested rather than assume that one completed framework replaces the others.



## Where Arphie fits in a VSAQ response



Arphie helps with the knowledge and collaboration work around the questionnaire. Our AI agents can retrieve relevant company content and draft traceable answers with sources and confidence signals. Owner, writer, and reviewer roles, comments, and teammate tags give contributors a shared place to resolve exceptions and sign off.



Arphie does not certify the vendor, choose the evidence a customer may receive, or replace final human approval. For Google's VSAQ workflow, use Arphie to prepare and approve source-backed wording, then confirm the handoff required by the requester. A final transfer step may still be needed. Your team remains responsible for validating scope and claims, approving evidence disclosures, and signing off on the submission.



For a wider view of the category, compare [security questionnaire automation tools](https://www.arphie.ai/blog/best-ai-tools-security-questionnaire-automation) and review [Arphie's security program](https://www.arphie.ai/security).