The short answer: Never start by drafting from memory. Start with evidence, keep each answer within the source's scope, and leave unsupported questions open for a named reviewer.
The workflow at a glance
| Stage | Output | Owner |
|---|---|---|
| Scope | Due date, customer, product, environment, and questionnaire version | Deal or security lead |
| Evidence | Approved policy, control proof, trust material, and prior answer set | Control owners |
| Draft | Each question marked Supported, Needs review, or Unknown | Questionnaire owner |
| Approval | Conflicts, exceptions, dates, and claims checked | Security, legal, or product owner |
| Export | Original format plus a record of sources and open items | Submitter |
Fill it out in five controlled steps
Freeze the scope before answering
Record which product, deployment, region, and customer request the questionnaire covers. A control may be true for production and false for a sandbox or legacy product.
Build a small approved evidence set
Collect current policies, control descriptions, audit reports, architecture notes, data-flow records, incident procedures, and contract terms. Assign an owner and effective date to each source.
Answer only what a source supports
Use the narrowest accurate wording. Cite the exact document and section. If the source partly answers the question, mark it for review instead of filling the gap with a likely answer.
Review scope, conflicts, and freshness
Check whether another source disagrees, whether the control still operates as written, and whether the answer overstates the evidence. Route exceptions to the person who owns the control.
Submit the original file with an exception trail
Keep the buyer's format intact. Save the reviewed source map and list every unanswered or qualified item so the next revision starts from known facts, not memory.
A safe synthetic example
Fictional company, redacted-style evidence
Question: Do you rotate encryption keys every 90 days?
Evidence: “Production encryption keys are rotated annually.” Security Standard, section 4.4.
Needs review Answer: “Production encryption keys are rotated annually. The evidence does not support a 90-day rotation claim.”
This answer is useful because it states the verified control and exposes the mismatch. It does not turn “annually” into “every 90 days.”
Common mistakes
- Copying an old answer without checking its source or scope.
- Answering “yes” when the evidence proves only part of the requested control.
- Using a certification or cloud provider's control as if it were your own.
- Hiding unknowns in vague language instead of assigning an owner.
- Changing the buyer's file structure and creating avoidable review work.
How SaneCite handles this
SaneCite drafts from the documents you approve, cites the source behind each supported answer, and flags anything the evidence does not support. You review the result before exporting it back into the questionnaire.
Questions people ask
- Who should own the questionnaire?
- One person should own the deadline and file. Control owners should approve claims in their areas rather than passing the whole document around without clear decisions.
- Can prior answers count as evidence?
- They can help, but only when they still link to a current approved source. An uncited old answer is a lead, not proof.
- What if the buyer forces yes or no?
- Choose the truthful option and use the comment field for scope or an exception. If no comment field exists, ask the responsible owner before submitting.
Primary sources
- NIST SP 800-53A Rev. 5, Assessing Security and Privacy Controls (accessed July 26, 2026).
- Shared Assessments, Standardized Information Gathering questionnaire FAQ (accessed July 26, 2026).
- NIST Cybersecurity Framework 2.0 (accessed July 26, 2026).
Published July 26, 2026. No material revisions yet.
Answer from evidence.
Upload the questionnaire and the documents your team trusts.