Setting up your Third-party Security Questionnaire

Last updated: March 21, 2026

  • Accessed through: Third-party Risk Management > Questionnaire Settings

  • Set up security questions that power your third-party risk assessments

  • Set up options:

    • Mycroft Template: Start with our pre-made set of 20 questions, designed to meet SaaS best practices

    • Upload a file: Import a CSV or PDF of your questionnaire

    • Copy & paste questions: Paste your list of questions in plain-text format

    • Start from scratch: Start with a blank questionnaire and add questions using the questionnaire manager

  • Configure internal assessment criteria for each question. These fields are not shared with the vendor and help your team and AI agent evaluate responses

    • Importance: Rank how critical this question is to your overall assessment.

    • What would be considered a Finding?: Describe answers or conditions that would indicate risk or non-compliance. Used by the AI agent to identify findings and draft recommendations.