Governance, Risk & Compliance

Answer the security questionnaire once.

A customer sends a 250-row spreadsheet and a deal stops moving until somebody fills it in. SemperWise One imports the file, answers what you have already answered, and shows you exactly which rows still need a human — with the control and the dated artefact behind every claim.

ISO 27001 SOC 2 DPDP HIPAA One control set · 31 mapped categories Access review Scan history Change log Training Evidence collected continuously, not before the audit
CAIQ · SIG · VSAFormats read directly
CitedEvery answer
ExpiresWith its evidence
HumanApproves everything

The part everyone automates, and the part nobody does

Answer libraries are not new. Every compliance platform has one: you answer a question once, and the next questionnaire that asks it gets the same text back. That part is genuinely useful and we do it too — import the file your customer sent, and the rows you have answered before fill themselves in, however differently they are phrased this time.

What almost nobody does is keep the library honest. A security answer is a claim about a control, and controls stop working. The access review that ran last March is not evidence in month fourteen. The penetration test you cited expired. The encryption standard changed. In most answer libraries none of that is visible: the text sits there, still confident, still filling questionnaires, quietly asserting something that stopped being true.

So we bind every answer to the evidence that makes it true. When that evidence expires, the answer stops filling questionnaires by itself and comes back to you with the reason attached. It is not deleted and not hidden — it is simply no longer allowed to speak for you unattended. That is the difference between an answer library and a library of things that used to be true.

Coverage

What the module does

Import, fill, review, export — with the receipts carried the whole way.

Reads the file your customer sent

CAIQ, SIG Lite, VSA and the spreadsheet a customer wrote themselves. .xlsx, .csv and pasted text. The question column is found by reading the header, so you are not mapping columns before you can start.

Answers from your own approved library

A local, deterministic match on the meaning-bearing words, so "do you encrypt customer data at rest" finds your answer whether they asked it that way or asked about industry-standard algorithms at rest.

Cites a control and an artefact

Each answer carries the framework clause and the dated evidence behind it. Those travel into the export as a "Backed by" column your customer can actually check.

Retires its own stale answers

When the evidence behind an approved answer expires, that answer stops auto-filling and the row is handed back with the expiry date named. Nothing re-asserts a control that quietly lapsed.

Drafts the rest, honestly

Where the library has nothing, the drafting pass is grounded in your real control state and told to answer "no" or "partial" where that is the truth. A questionnaire answer is a contractual representation; an AI that flatters you is worse than no AI.

Never sends anything by itself

Everything the fill produces is a draft. A person approves each one, and their name is recorded against it. Answers that came from the model are excluded from bulk approval on purpose — nobody has read them yet.

Learns as you go

Every answer you approve lands in the library with its citations, folded into the existing entry when the same question was asked in different words. The second questionnaire costs a fraction of the first.

Approach

How it runs

Four steps, and only one of them is yours.

  1. 01 · Import

    Upload the spreadsheet, or paste the questions from the email. Sections and the customer's own reference numbers are carried across so your response lines up with their sheet.

  2. 02 · Fill

    The library answers what it can. The result is itemised rather than totalled — how many came from your approved answers, how many were drafted, how many were held back as stale, how many nobody can answer honestly.

  3. 03 · Review

    You read the drafts. The rows that need you are marked, and the ones that are fine are visibly fine. Approving an answer puts your name on it and teaches the library.

  4. 04 · Export

    A CSV with your responses and the control reference and dated evidence behind each one. Send it back, or paste it into the customer's own template.

Deliverables

What you actually receive.

The report is the product. If it cannot be acted on by a developer and understood by a director, we have not finished.

A completed questionnaire

Exported with your answers, your short yes/partial/no column, and the citations behind each claim.

A reusable answer library

Your approved answers, each bound to a control and an artefact, ready for the next customer who asks.

A stale-answer report

Which of your standing answers have outlived their evidence — which is, in practice, a list of controls that stopped being evidenced.

An audit trail

Who approved which answer and when, because "who told the customer that?" is a question that eventually gets asked.

Is this for you?

Talk to us if any of these are true.

If none of them are, say so on the call and we will tell you honestly whether this is the right piece of work — or point you at the one that is.

Book a scoping call
  • A deal is waiting on a security questionnaire right now.
  • The same forty questions arrive from every enterprise customer, phrased differently each time.
  • Your answers live in a spreadsheet somebody maintains by hand, and nobody is sure which parts are current.
  • You have been asked to evidence an answer you gave last year and cannot find what backed it.
  • You are about to buy a compliance platform mainly to get its answer library.

How we work

Six steps, and no surprises.

The same engagement model applies to every piece of work we take on, so you always know what happens next.

01

Scope

A 30-minute call, then a written scope: what is in, what is out, what we need from you and what it costs. Nothing starts before you sign it.

02

Authorise

Rules of engagement, testing windows, escalation contacts and a signed authorisation. Out-of-hours windows where production cannot take the load.

03

Test

Automated coverage first, then manual testing where judgement is required. Critical findings are reported the day we confirm them, not at the end.

04

Report

One report a developer can act on and an executive can read, with evidence, reproduction steps, business impact and a fix for every finding.

05

Remediate

A walkthrough call with your engineers. We answer questions on the fix, not just the finding.

06

Retest

A free retest cycle to confirm the fixes hold, and a clean summary you can hand to a customer, auditor or board.

Questions

Questionnaire Automation — answered.

The questions clients actually ask during scoping. If yours is not here, ask it directly.

Which questionnaire formats can you import?

CAIQ, SIG Lite, VSA and any customer-written spreadsheet, as .xlsx, .csv or .tsv — plus pasted text for the short lists that arrive in the body of an email. The question column is detected from the header rather than assumed, so a sheet with a title block above it and a column called "Consensus Assessment Questions" works without configuration.

Does the AI send answers to our customers?

No. Everything the fill produces is a draft, and a person approves every answer before it goes anywhere. Answers drafted by the model are deliberately excluded from bulk approval, because a bulk-approve button over text nobody has read is how a company ends up warranting something untrue.

What does "answers expire" actually mean?

When you approve an answer you can attach the control it rests on and the evidence artefact that proves it. Evidence in SemperWise One carries a collection date and an expiry. When that expiry passes, the answer is marked stale: it stays in your library, but it will not fill a new questionnaire until the evidence is re-collected or you re-approve it deliberately. The row comes back to you with the expiry date named.

Can we use it without the AI features?

Yes, and it is worth knowing why that works. The matching is local and deterministic — no embeddings, no vector database, no external call — so your own approved answers fill questionnaires with the AI layer switched off entirely. The model only drafts the rows your library has never seen.

Does our data leave our environment?

On our hosted platform the drafting pass sends the question and your control state to the model provider. On an on-premises or private-cloud deployment you can point the AI layer at a model inside your own network, or turn it off and use the library alone. The library, the citations and the evidence never leave your tenant either way.

How is this different from Vanta or Sprinto's questionnaire automation?

Two ways that matter. Theirs produce text; ours produces text with a control reference and a dated artefact attached, carried into the export so the recipient can verify it rather than take it on trust. And theirs have no concept of an answer going out of date — ours stops using an answer the day the evidence behind it expires.

Next step

Get a written scope and a fixed price.

A 30-minute call, then a scope document with what is in, what is out and what it costs. No obligation, and no charge for the conversation.