Questionnaires

Hold the security questionnaires you receive and the ones you send, import a supplier's spreadsheet, answer question by question, route a questionnaire to a colleague or a vendor, and export the finished answers.

A questionnaire is a structured list of questions, usually about security or compliance. Two situations call for one. Inbound: a customer or an auditor sends you a long list of questions about your controls. Outbound: you are assessing a supplier. Aegis stores each question with its text, an optional category and an optional answer, counts a completion figure as you go, tracks who owns the questionnaire and who it has been routed to, and exports the set to a spreadsheet.

A licensed module

Questionnaires are gated behind the QUESTIONNAIRE_AUTOMATION licence flag, and the QUESTIONNAIRES module has to be provisioned for your tenant. If the module is not in your plan, /questionnaires shows a short “not available” message instead of the table. The AI actions further down need the separate AI_ASSIST flag as well.

Who uses it

What's on this screen

Open /questionnaires from the Compliance group in the left menu. The header reads Questionnaires over the line Manage vendor security questionnaires and compliance assessments, with three buttons at its right: Sync now, Import and the dark primary Create Questionnaire. Below sits the filter bar — a Search questionnaires… box, a Search button, and the All Statuses and All Follow-up Statuses dropdowns. Under that the table carries Title, Source (with a Connector chip on synced rows), Status, Follow-up status, Owner, Assigned to, Questions and Created. In the capture the table area is empty and no columns are drawn — the demo instance held no questionnaires.

  1. Select Sync now to ask a connected source for questionnaires. With a schedule configured, Aegis queues the import and confirms; with none, it says so and asks you to add a Questionnaires schedule to a SharePoint connector first.
  2. Select Import to upload a supplier's spreadsheet. A dialog opens where you pick the format and let Aegis parse the questions.
  3. Select Create Questionnaire to start an empty one by hand. A small dialog opens over the table.
  4. Type in the search box to narrow the table to matching titles, then set either dropdown to narrow it further.
  5. With nothing created yet, the table area reads Nothing here yet — No items have been created yet. Create, import or sync one and rows replace it.
The questionnaire list on a fresh instance — the three header actions, the search box and status filters, and the empty state where the table will be — /questionnaires.
The questionnaire list on a fresh instance — the three header actions, the search box and status filters, and the empty state where the table will be — /questionnaires.

Creating a questionnaire by hand

The create dialog is deliberately small: a title and an optional source label, nothing more. Use it to start an outbound assessment and add or import the questions afterwards.

  1. Select Create Questionnaire in the header. The page dims and a dialog opens in the centre.
  2. The dialog is titled Create Questionnaire and holds two fields — Title, marked with a red asterisk because it is required, and Source — above Cancel and Create.
  3. The × in the corner closes the dialog, as does Cancel. Nothing is saved.
  4. Type a clear Title — the placeholder shows the shape, e.g. ISO 27001 Vendor Assessment — and, optionally, a Source such as the vendor name or framework. Select Create: the dialog closes and the questionnaire appears in Draft with no questions yet. Leave the title blank and the field turns red.
The Create Questionnaire dialog — a required Title, an optional Source, and Cancel and Create — /questionnaires.
The Create Questionnaire dialog — a required Title, an optional Source, and Cancel and Create — /questionnaires.

Importing a questionnaire from a spreadsheet

Import reads a supplier's own spreadsheet and creates a draft with the questions loaded, so you need not reshape the columns first.

  1. Select Import. The Import Questionnaire dialog opens.
  2. Choose the Format that matches your file: Generic (xlsx/csv) for a question-per-row layout, SIG (Standardized Information Gathering) for the Shared Assessments questionnaire, or CAIQ (Consensus Assessments Initiative) for the Cloud Security Alliance one.
  3. Choose the File.xlsx or .csv, up to 10 MB. Optionally set a Title; leave it blank and Aegis names the questionnaire after the file.
  4. Select Import. Aegis parses the file, creates the questionnaire in Draft with its questions, and confirms. If your file has a Required or Mandatory column, a second note tells you that column is not stored and was ignored.

The import dialog was not captured for this edition, so there is no figure of it.

Opening a questionnaire

Selecting a row opens the detail over the list. At the top sit the status badge and, once there are questions, a completion line such as 14/47 answered (30%), with the action buttons along the right. Overview follows with the source, question count, source file, who created it, the Owner, who it is Assigned to and when, and the Follow-up status; a synced questionnaire also shows its connector and last-synced time. Questions lists each question with its number, text, an optional category chip and any answer in a green panel, with a confidence figure on AI drafts. Metadata shows the created and last-changed times.

  1. If the list is empty, create, import or sync a questionnaire first — there has to be a row before there is a detail to open.
  2. Narrow the list with the search box and the status dropdowns until you see the one you want.
  3. Select the row. The detail opens over the list, and closing it returns you to the table with your filters intact.
This capture fell back to the empty list: with no questionnaires on the demo instance there was no row to open, so the detail view is not shown — /questionnaires.
This capture fell back to the empty list: with no questionnaires on the demo instance there was no row to open, so the detail view is not shown — /questionnaires.
No screenshot of the detail view

The detail view, the forward dialog and the AI dialogs could not be captured for this edition. What follows names the real controls, but claims no screenshot for them.

Answering the questions

With the update permission — Manager and Admin — every question carries its own answer box.

  1. Scroll to Questions. The list scrolls inside its own panel, so a long questionnaire does not push the rest of the detail off screen.
  2. Type into the answer box under a question; the placeholder reads Enter your answer….
  3. Select Save answer. The button reads Saving…, then Aegis confirms, the answer appears in the green panel, and the completion figure at the top moves up.

The two status cycles

Each questionnaire carries two independent statuses — two columns in the table, two dropdowns in the filter bar. The answering status tracks how far the answers have come: Draft (created, imported or synced), In Progress (some answered), Completed (all answered and reviewed) and Archived (kept for reference; forwarding and the AI drafting actions are hidden in this state).

The follow-up status tracks a questionnaire you have routed to someone else. It moves one step at a time, with a step back allowed for correction, so the dropdown only ever offers the moves valid from where you are now.

Follow-up status Can move to
None — no follow-up in progress (the default) Pending response, In review
Pending response — routed, awaiting their answers In review, Escalated, Resolved, None
In review — answers received and being checked Pending response, Escalated, Resolved
Escalated — review stalled and raised for attention In review, Resolved
Resolved — the follow-up is complete In review

Changing the owner and the follow-up status

Both live in Overview in the detail view, and both are dropdowns for a Manager or Admin and plain read-only text for everyone else.

  1. Open the questionnaire and find Owner in Overview. The dropdown lists Aegis users; pick one and Aegis saves the transfer and confirms.
  2. Open the Follow-up status dropdown beside it. It shows the current value and only the moves allowed from it — the table above lists them. Pick one and Aegis records the move and confirms.
  3. Close the detail view. The Owner and Follow-up status columns in the table show the new values.

Forwarding to a colleague or a vendor

With the forward permission, the detail view shows a Forward button — hidden once the questionnaire is archived.

  1. Select Forward. The dialog opens with a Forward to choice of Aegis user or External email.
  2. For a colleague, keep Aegis user, search by name or email and pick someone. For a supplier, switch to External email and enter the recipient's email and, optionally, their name.
  3. Add an optional message of up to 500 characters and select Forward. The recipient becomes Assigned to, the follow-up status moves to Pending response, and the time is recorded.

An external recipient gets a one-time link to a page outside the application — no sign-in, no menu, nothing but the questionnaire. The link is used up only after at least one matching answer has been saved. An empty or mismatched submission leaves the link available for correction. An invalid, expired or already-used link shows the same neutral “link unavailable” page, so it never reveals which it was, and search engines are told not to index it.

Exporting the questions and answers

Anyone who can read a questionnaire can export it, once it has questions.

  1. Open it — the export buttons appear only when there are questions.
  2. Select Export Excel for an .xlsx file or Export CSV for a .csv. The button reads Exporting… while the file is built, then the browser downloads it.

The export includes the original external response separately from the current review draft. Human edits do not erase that original response.

The AI assist

Where AI Assist is licensed, the detail view offers three actions.

AI Autofill and Regenerate answers need the update permission and are hidden on an archived questionnaire; Review readiness needs only read access. AI Autofill and Review readiness also appear only once the questionnaire has questions, while Regenerate answers is shown even on an empty draft — where it has nothing to redraft.

Always read the drafts before they leave the building

Suggested answers are drafts drawn from your own records. They change no policy and no other record, and Aegis never sends a questionnaire to a customer or a vendor on its own. A person reads each answer, corrects it and decides what is appropriate to share — most carefully for a low-confidence answer headed to an outside party.

Tips and limits

Where this connects

Questionnaires are one way to assess the suppliers you track in Vendors, and the AI drafts its answers from your Policies, control monitoring and Evidence. Files can also arrive through Connectors, and what you publish outwards sits alongside your Trust Center. For a supplier assessed end to end, see the vendor scenario; for who can do what, see Roles overview.