Where questionnaires live
Open Configuration and choose Questionnaires, or go straight to/questionnaires. The page opens on the Inherent Risk tab. Each tab is one questionnaire type, with the templates of that type listed down the left and the selected template on the right.
follow_up) have no tab. They are generated from assessment issues, and you reach their submissions from the assessment. Their template page only lists the submissions made on them.

The Questionnaires page. Type tabs across the top, templates of that type down the left, the selected template's Submissions and Template tabs on the right.
Creating a template
Click Create Inherent Risk Questionnaire (the label changes with the tab) above the list. The new template opens with no questions. On the Inherent Risk tab you can instead click IRQ Library and copy a packaged template. On the Assessment tab the button is a menu with a second choice, Create Questionnaire from Control Set, which derives a questionnaire from a control set of type policy or questionnaire.questionnaire:create permission. Editing one needs questionnaire:update, and deleting needs questionnaire:archive. See Permissions and roles.
Building the template
The Template tab is an editor with a Save and Cancel bar. Nothing reaches the server until you click Save, and most of the Actions menu is disabled while you have unsaved changes. If someone else saves the same template while you are editing, a Questionnaire changed dialog asks you to Reload now; your local edits are discarded.Title, sections, and order
The fields at the top are Questionnaire title and Questionnaire description. Both are shown to the respondent. Click New Section to add a section. A section has a Section Name, an optional description, a Section Index, and a Risk Domain. The risk domain matters on an IRQ: it decides which domain a section’s questions score into, and it is what domain weighting and per-domain review are keyed on. Drag sections and questions to reorder them. Actions → Number Questions fills in a question index for every question, either Sequential (1, 2, 3) or By section (1.1, 1.2, 2.1), and can leave questions that already have an index alone.Adding a question
Click Add and choose a response type. When the template has sections, the menu asks which section first.0, so weight them before the first send. An option’s Score override sets a Minimum score override: when that option is selected, the questionnaire’s overall score cannot fall below the percentage you enter, and the highest override among the selected answers wins.

A question's settings panel. Required question, Internal only, Response Type, comments, document attachments, and the write-back action.
Question settings
Open a question’s settings to find these switches. Select several questions and use the bulk actions bar to set the first five at once.Internal-only questions
An internal-only question is a fact your team wants recorded about the vendor without asking the vendor. The portal strips the question and any answer to it. Autofill answers it like any other question, and the reviewer sees it, with its answer and the model’s reasoning, on the submission. Marked Required, it blocks both Accept and Deny until someone answers it; the buttons show how many are outstanding. Two things to know before you use one:- It scores like any other question. Leave option values at
0on a question that is context rather than risk. - It can only show other internal-only questions through conditional logic. A respondent-facing question can show an internal-only one (the vendor answers, the rule decides whether your reviewer is asked the follow-up), but not the other way round, because the vendor would be blocked on a question they cannot see.
Conditional logic
Actions → Configure Conditional Logic opens the rule list for the template. A rule shows one or more sections, questions, or options when a trigger question’s answer matches. Anything a rule targets is hidden until a rule for it fires, and the rules for one target read when ANY of these rules is met, so two rules on the same section are an OR. Inside a rule, each condition is a trigger question plus is any of or is not any of and the options it compares against. A rule can combine up to ten questions, all of which must be true (when ALL of the following are true), and each must be a different question. Only single select, multi select, country, and currency questions can be triggers, and a question cannot show the section it sits in. An unanswered trigger counts as not met, never as skipped.
Configure Conditional Logic. Rules are grouped by what they show; a rule with several conditions requires all of them.
Write-back: answers that update the record
Configure write-back on a question makes its answer write a value onto the vendor, or onto the assessment for an assessment questionnaire. The panel asks for:
The write-back panel on a single select question, with one fixed rule per answer.
Spreadsheet import and export
Actions → Bulk Import Questions opens a dialog that takes an Excel file. Download blank template gives you the column layout with example rows; Download current questions exports what is already on the template so you can edit and re-import it. The columns cover question text, type, required, pipe-separated options and weights, instructions, guidance, the comment and document switches, internal only, section name and order. Rows that fail come back in a Download Errors sheet with an Error column. Actions → Export → Export Template as XLSX downloads the template. Export Submissions as XLSX appears once the template has submissions and downloads every answer on the current page of the submissions table. A single submission has its own Export as XLSX in its actions menu.Other template actions
Assigning reviewers
Two different things are called the reviewer. Keep them apart.Template reviewers
Submission reviewer
Sending a questionnaire
A questionnaire reaches a vendor through a portal: a branded page with a due date, your message, and the questionnaire as a required item. Which button you use depends on the type.Informational and Know-Your-Vendor: send from the template
Inherent risk: send from the vendor page or collect at intake
Assessment: send through the assessment plan
portal:create permission. The vendor receives the portal invitation email described in Email notifications.
What the vendor sees
The portal shows your message, the due date, and a list of required items on the left. Each question shows its title and instructions, a red marker with the tooltip Required where you set it, a comment box labeled Comments (Optional) or Comments (Required), and a Supporting Documents picker where attachments are allowed. Sections and questions hidden by conditional logic do not appear. Internal-only questions do not appear. Answers are Auto-saved as the vendor types. The Submit button stays disabled until every required question is answered, with the count of incomplete items shown. Optional questions left blank do not block submission. After submitting, the vendor sees Thank you and the portal is closed to them; a vendor who returns later sees This portal is closed.Reading the submissions list
Open a template and its Submissions tab lists every send. The tab is the default whenever there is at least one submission. Search by vendor or respondent email.
The Submissions tab. Status, reviewer, and completion at a glance; click a row to open the submission.
Reviewing a submission
Click a row to open it. The header carries the Assign reviewer picker, the Accept and Deny buttons while the status is Ready for review, and an actions menu. Two tabs do the work.
A submission on its Summary tab: the Suggested Inherent Risk Profile, the Suggested updates panel, and the decision buttons.
Read the Summary tab
Check the answers on the Review Questionnaire tab
Decide
Questionnaire history on the vendor page
A vendor’s Questionnaires tab lists every questionnaire that vendor has ever been sent: from the vendor page, from intake, from an assessment, from a workflow, or for a service. Submissions on a template that was later deleted still appear, because deleting a template does not undo the sends made from it.
The vendor's Questionnaires tab. Sent and Submitted are separate columns, and rows that were never submitted sort last.
Versioning: edits are not retroactive
Saving a template after changing a question’s text, instructions, guidance, response type, required flag, or scoring mode, or an option’s name, description, value, or score override, creates a new version of that question. Existing submissions keep the version they were answered against, and the submission page renders each one against the questions it was asked. Conditional logic rules move to the new version with it. Changing a question’s settings (comments, documents, internal only, intake switches) or its position edits the question in place, because none of those invalidate an answer already given. What this means in practice:- Re-weighting an IRQ does not rescore vendors already accepted. Send a new IRQ, or run a reassessment, to apply the new weights.
- A vendor who is mid-way through a portal keeps the questions they started with. Use Reopen Submission after they submit if you need them to see questions you added.
- Deleting an option archives it. Submissions that selected it still show it.