Another questionnaire, another long spreadsheet
A new banking partner, a card scheme programme manager, a large business customer or an investor sends a due diligence questionnaire. It asks about your ownership, your policies, your information security, your incident history, your outsourcing, your business continuity, your complaints handling and your financial position. It is a spreadsheet with hundreds of rows, or a web portal with free text boxes.
The founder or head of compliance opens last year's answers to a different partner's questionnaire and starts copying. Half the questions are worded differently. Some answers are now out of date. Security questions go to the CTO, who is busy. Three weeks later it is submitted, and a month after that another one arrives.
Why each questionnaire feels new
The questions are similar. The wording, format and level of detail are not, and your answers live in many places.
- Past answers are in old spreadsheets named after the partner who asked.
- Nobody knows which answer is the latest approved one.
- Policies have changed since some answers were written.
- Specialist answers, such as security and continuity, depend on one or two people.
- Supporting documents, such as policies and certificates, are attached from wherever they were last saved.
Senior time, and the risk of stale answers
Questionnaires take senior people away from running the business, often at the moment a new partnership is time-sensitive. Copying old answers risks sending something no longer true, which is worse than a slow answer. Inconsistent answers to different partners can come back to you if they compare notes or ask follow-up questions.
What you say about your controls must be true and approved by the people accountable. The build makes sure the approved answer is the one used.
An answer library and a drafting tool
What we build turns past questionnaires into a maintained library, and uses it to draft new ones.
- Past questionnaires are imported, and repeated questions are grouped into topics.
- For each topic, the owner writes or approves a current answer, with a review date and links to supporting documents.
- When a new questionnaire arrives, each question is matched to the closest approved answers, using search and an AI model such as Anthropic Claude.
- The tool drafts a response for each question from the approved answer, adjusted to the question's wording, and marks how close the match was.
- Questions with no good match go to the right owner as a task.
- The owner reviews the full draft before submission. New answers they write are added to the library for next time.
- The completed questionnaire is exported in the partner's format and a copy is kept with the date and approver.
| Question area | Typical owner | Kept current by |
|---|---|---|
| Company and ownership | Founder or company secretary | Review when anything changes |
| Policies and procedures | Compliance lead | Policy review dates |
| Information security | CTO or security lead | Scheduled review |
| Operations and continuity | Head of ops | Scheduled review |
| Financial information | Finance lead | Each reporting period |
The next questionnaire
The library also shows what is going stale. An answer about your continuity testing that was last reviewed a year ago is flagged to its owner before the next questionnaire arrives, not while it is being filled in.
When a questionnaire arrives, it is loaded and drafted from the library straight away. Owners see only the questions that need them. The compliance lead reviews a complete draft rather than a blank sheet. Answers are consistent across partners because they come from one library.
Signs you need an answer library
- Each questionnaire starts from last year's spreadsheet.
- Nobody is sure which answers are current.
- The CTO answers the same security questions again and again.
- Questionnaires take weeks and delay partnerships.
- Supporting documents are hunted down each time.