- Home
- Skills
- Legal & Compliance
- Vendor Questionnaire Responder — CAIQ, SIG & Security Assess
Works with the AI tools you already use
Vendor Questionnaire Responder — CAIQ, SIG & Security Assess
The Vendor Questionnaire Responder skill automates the extraction and drafting of security questionnaire responses from trusted company documents.
$9.99
Vendor Questionnaire Responder — CAIQ, SIG & Security Assess
Example session with this skill installed
Act as the Vendor Questionnaire Responder skill. No files are uploaded — use ONLY the corpus and questionnaire below, both inlined. Run the full workflow (Steps 1–7) based on your instructions. Preserve the original question IDs and row structure exactly, produce the completed answer table, export the final result as CSV in the original column order, and generate the gap report.
CORPUS
[DOC 1 — Disaster Recovery Plan v1.0, 2024-01-15, §4] The organizational Recovery Time Objective (RTO) is 24 hours, and the Recovery Point Objective (RPO) is 12 hours.
[DOC 2 — Enterprise Resiliency Standard v3.2, 2026-02-10, §2.1] Core production systems are architected for high availability. The current RTO is 4 hours, and RPO is 1 hour.
[DOC 3 — Acceptable Use Policy v2.1, 2025-08-01, §5] Employees are restricted to standard privileges on company-issued workstations. Employees are strictly prohibited from installing unapproved or unlicensed software.
QUESTIONNAIRE (pasted from customer's Excel):
Customer: Apex Financial | Vendor: Meridian SaaS Inc.
| Q-ID | Domain | Question Text | Answer | Evidence / Comments |
|---|---|---|---|---|
| BCP-01 | Business Continuity | What are the organization's defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO)? | ||
| END-03 | Endpoint Security | Does the company technically enforce restrictions preventing the installation of unapproved software, hardware peripherals (e.g., USBs), and browser extensions? | ||
| LEG-01 | Legal & Privacy | I hereby certify on behalf of my organization that we comply with all applicable local, state, and federal privacy laws regarding customer data. |
- Read your context and instructions
- Compiled the vendor questionnaire responder
- Generated the data export
Step 1 — Answer Library
No answers/ directory or library file was provided. Treating this as a fresh library — all matches will be DOC_SUPPORTED, PARTIAL, GAP, or OUT_OF_SCOPE. Nothing is a LIBRARY_HIT.
Step 2 — Parsed Questionnaire
{
"questionnaire_id": "apex-financial_meridian-saas_2026-09-15",
"questions": [
{"q_id": "BCP-01", "control_domain": "Business Continuity", "question_text": "What are the organization's defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?", "response_type": "text"},
{"q_id": "END-03", "control_domain": "Endpoint Security", "question_text": "Does the company technically enforce restrictions preventing the installation of unapproved software, hardware peripherals (e.g., USBs), and browser extensions?", "response_type": "yes_no"},
{"q_id": "LEG-01", "control_domain": "Legal & Privacy", "question_text": "I hereby certify on behalf of my organization that we comply with all applicable local, state, and federal privacy laws regarding customer data.", "response_type": "yes_no_na"}
]
}
No parse errors. No prefilled cells present to verify.
Step 3 — Classification
| Q-ID | Class | Reason |
|---|---|---|
| BCP-01 | DOC_SUPPORTED (with conflict flag) | Two sources conflict on RTO/RPO values |
| END-03 | PARTIAL | Corpus documents a policy prohibition, not technical enforcement — these are distinct claims |
| LEG-01 | OUT_OF_SCOPE | Attestation requiring human signature on behalf of the organization |
Step 4 — Draft Answers
BCP-01: Doc 1 (Disaster Recovery Plan v1.0, 2024-01-15, §4) states one RTO/RPO; Doc 2 (Enterprise Resiliency Standard v3.2, 2026-02-10, §2.1) states a different, more current RTO/RPO for core production systems. Per guardrails, answering with the more recent/authoritative document while flagging the discrepancy.
END-03: The Acceptable Use Policy establishes a policy-level restriction (standard user privileges, prohibition on unapproved software) but does not describe a technical enforcement mechanism (e.g., endpoint allow-listing, USB port control, browser extension management). Answering "Yes" here would conflate policy with technical control — a guardrail violation. Drafted as partial with scope limit.
LEG-01: This is a first-person attestation ("I hereby certify... on behalf of my organization"). Per scope rules, this requires a human signature/formal certification and cannot be drafted on the organization's behalf.
Step 5 — Assembled Outputs
Completed Answer Table
| Q-ID | Domain | Question Text | Answer | Evidence / Comments |
|---|---|---|---|---|
| BCP-01 | Business Continuity | What are the organization's defined RTO and RPO? | Per the most current governing document, RTO is 4 hours and RPO is 1 hour for core production systems. Note: an older document specifies RTO 24h/RPO 12h — see Gap Report for discrepancy. | (Source: Enterprise Resiliency Standard v3.2, §2.1, 2026-02-10) — conflicts with Disaster Recovery Plan v1.0, §4, 2024-01-15 |
| END-03 | Endpoint Security | Does the company technically enforce restrictions preventing installation of unapproved software, hardware peripherals, and browser extensions? | Partially supported. Policy prohibits unapproved software installation and restricts employees to standard privileges. No documentation confirms technical enforcement (e.g., device/USB control, browser extension management, allow-listing). NEEDS OWNER for the technical-enforcement portion. | (Source: Acceptable Use Policy v2.1, §5, 2025-08-01) — policy-level only |
| LEG-01 | Legal & Privacy | Certification of compliance with applicable privacy laws | HUMAN REQUIRED — attestation on behalf of the organization; requires authorized signatory, not a drafted answer. | N/A |
Gap Report
| Q-ID | Flag Type | Issue | Suggested Owner |
|---|---|---|---|
| BCP-01 | Source Conflict | DR Plan v1.0 (2024) states RTO 24h/RPO 12h; Resiliency Standard v3.2 (2026) states RTO 4h/RPO 1h for core production systems. Answered using the more recent, more authoritative document per guardrails, but the older DR Plan appears stale and unreconciled. | BC/DR Program Owner — should confirm DR Plan v1.0 is retired/superseded or clarify scope differences (e.g., "core production" vs. broader environment) |
| END-03 | Partial / Terminology Precision | Corpus supports a policy restriction, not a technical enforcement control. These are distinct security concepts per guardrails and cannot be conflated. | Endpoint Security / IT Security Owner — needs to supply evidence of technical controls (MDM/EDR policy, USB blocking config, browser extension management) if they exist |
| LEG-01 | Out of Scope | First-person attestation requiring authorized signature; not answerable by drafted content. | Legal/Compliance — requires named signatory |
Follow-up Question Handling
No follow-up branches (followups_if_yes) were present in the source questionnaire structure, so none apply.
Change Log
- BCP-01: Newly drafted (
DOC_SUPPORTEDwith conflict) — awaiting approval. - END-03: Newly drafted (
PARTIAL) — awaiting approval; technical-enforcement gap flagged for owner. - LEG-01: Marked
HUMAN REQUIRED— not drafted, no library action. - No stale library answers (library was empty prior to this run).
CSV Export## Step 6 — Library Update & Staleness Check
No prior library existed, so there's nothing to mark stale. Writing 2 new draft entries (BCP-01, END-03) to a fresh library; LEG-01 is not added since it's out-of-scope, not an answerable question.
Step 7 — Review Summary
## Review Summary
- Total questions/rows processed: 3
- Answered from approved library: 0
- Newly drafted (awaiting approval): 2 (BCP-01, END-03)
- Gaps requiring owner input: 1 partial (END-03 technical-enforcement portion) → see Gap Report
- Out-of-scope (human/legal): 1 (LEG-01)
- Parse errors (unrecoverable): 0
- Stale answers flagged: 0
- **Action required:** review and approve 2 draft answers; resolve the BCP-01 RTO/RPO document conflict; route LEG-01 to an authorized signatory; source technical-enforcement evidence for END-03 if it exists.
Note on END-03: I did not answer "Yes" here even though the policy language sounds close — enforced policy and enforced technically are different claims, and only the former is documented. Answering "Yes" would be the kind of assessor-facing overstatement the guardrails exist to prevent.
Q-ID,Domain,Question Text,Answer,Evidence / Comments
BCP-01,Business Continuity,"What are the organization's defined Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?","Per the most current governing document, RTO is 4 hours and RPO is 1 hour for core production systems. Note: an older document specifies RTO 24h/RPO 12h -- see Gap Report for discrepancy.","(Source: Enterprise Resiliency Standard v3.2, Section 2.1, 2026-02-10) -- conflicts with Disaster Recovery Plan v1.0, Section 4, 2024-01-15"
END-03,Endpoint Security,"Does the company technically enforce restrictions preventing the installation of unapproved software, hardware peripherals (e.g., USBs), and browser extensions?","Partially supported. Policy prohibits unapproved software installation and restricts employees to standard privileges. No documentation confirms technical enforcement (e.g., device/USB control, browser extension management, allow-listing). NEEDS OWNER for the technical-enforcement portion.","(Source: Acceptable Use Policy v2.1, Section 5, 2025-08-01) -- policy-level only"
LEG-01,Legal & Privacy,"I hereby certify on behalf of my organization that we comply with all applicable local, state, and federal privacy laws regarding customer data.","HUMAN REQUIRED -- attestation on behalf of the organization; requires authorized signatory, not a drafted answer.","N/A"
vendor-questionnaire-responder-caiq-sig-.csv
CSV · data export
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
The Vendor Questionnaire Responder skill automates the extraction and drafting of security questionnaire responses from trusted company documents. It guarantees strict compliance by refusing hallucinated claims, handling conflicting sources, flagging missing evidence for human review, and maintaining the structural integrity of exported CSV files.
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 17 days ago
- Passed all security checks, Safe to install