Nobody owns the security questionnaire
It sits between sales, security and product, and falls through the gap. A real stage in your sales cycle, with a start date, an end date, and no owner.
Follow one through your company.
It arrives attached to a procurement email. A spreadsheet, or a portal login with a password that expired before anyone opened it. It lands on the rep, because the rep is the address the buyer has.
The rep can’t answer it — encryption at rest and in transit, retention windows, subprocessors, incident response, access reviews, breach notification — so it goes to security. Security can answer it, but security is not measured on your close date; they’re measured on being right, and being right takes as long as being right takes. Part of it goes to product, who own what the platform actually does but have never seen this buyer’s phrasing and have no idea which of these forty questions is the one that matters to the reviewer.
A real stage with no owner
So the questionnaire sits in the space between those three functions, and the only force moving it is a rep sending follow-ups.
That is a genuine stage in your sales cycle. It has a start date and an end date. These questionnaires are near-universal in enterprise deals, and security review is one of the longest stages in enterprise software procurement. It decides deals — a buyer’s security team can rank you below a competitor on completeness alone, without ever telling you that’s what happened.
It appears on no org chart. It’s in nobody’s goals. It shows up in no pipeline review, because there’s no field for it. When it goes badly, the deal is coded price, or timing, or went a different direction.
Here’s the tell. Ask three people at your company who owns the security questionnaire and you’ll get three different answers, none of them confident, and at least one of them will be a team rather than a person. “Security handles that.” “The RFP inbox.” “Whoever’s on the deal.”
A team is not an owner. A team is a place to send something.
What owning it actually involves
I’ve been that person. In B2B SaaS and life sciences since 2011, running Deal Desk and Sales Operations since 2018, and for a good stretch of that the security questionnaire was mine — not supervised, owned. It arrived, and it was mine until it was submitted, in front of buyers in clinical research, health systems, insurance and financial services.
Here’s what that involves, unglamorously.
Triage first. Read the whole thing before answering any of it. Sort what we can answer today from what we can’t, and be honest about which is which. The gaps are the real output of that first pass — the items where the truthful answer is uncomfortable, or unknown, or living inside one person’s head. Fill the known items. Then position everything else, question by question, for the specific expert who has to speak to it.
Positioning is not forwarding. Forwarding gets you a one-line reply that reads as evasive to a stranger with a scoring rubric. Positioning means handing someone the question, the context, what the buyer is actually testing for, and what a complete answer needs to contain — so the thing that comes back is usable.
Then the daily part. Every day I’d review the current state of the responses, meet the stakeholders, and do discovery to describe the response — what actually happens, who does it, how it’s evidenced — then tailor the language so the answer illustrated the control rather than merely asserting it. Every day, because a questionnaire left alone for two days doesn’t hold still. It decays.
And I chased. Daily. That’s the part nobody puts on a job description. Standing group meetings to hash out strategy where answers touched each other, because the hosting answer and the subprocessor answer and the retention answer all have to be true in the same direction. One-to-one follow-ups on the items nobody wanted to own.
The hardest part was driving people who don’t normally write, to write. Detailed, persuasive prose that was accurate and complete. A brilliant engineer can hold the entire control environment in their head and still hand you three sentences a reviewer will mark as incomplete. That isn’t a failing. Writing to be assessed by a stranger is a separate skill from doing the work well, and most technical experts have never been asked to develop it.
Then cross-checking. Refining one person’s draft against a colleague on their own team, because two people in the same function will describe the same control differently — both accurate, neither identical, and a reviewer reading both will notice.
Staying on track while producing high-quality output was always the challenge, because other people’s opinions and points of view creep in. Every review cycle invites a rewrite that’s a preference rather than a correction. Somebody wants a softer verb. Somebody wants a paragraph about the roadmap that answers a question the buyer didn’t ask. Somebody genuinely disagrees with a colleague about how a process works, and now you’re not editing, you’re adjudicating.
Most of that job is follow-up and judgement. Very little of it is typing.
The job didn’t go away, the bottleneck moved
Which is exactly why the tooling didn’t solve it.
- Drafting. A model turns a source document into a serviceable first pass in seconds
- Triage — which of the forty questions this reviewer actually cares about, and which three you can’t answer cleanly
- The chase — nobody has automated getting a senior engineer to confirm, on the record, that what you wrote about their system is true
- Judgement — when the honest answer is uncomfortable, saying it accurately without handing the reviewer a reason to stop reading
- Consistency — across answers, across deals, across quarters
- Tailoring — the same fact lands differently for a health system than for a financial services buyer, and nothing in a source document knows that
Faster drafting against an unowned process gives you more answers, sooner, with the same number of people checking them. Which is worse, not better. An unverified sentence that took an hour to write at least got read by the person who wrote it.
The typing was never the bottleneck. It just looked like the bottleneck, because it was the only part anyone could see.
The question underneath it: which source?
When that rep finally gets an answer together, it came from somewhere. That somewhere is the thing nobody can name.
Not which document it was pasted from — which authority it rests on. The policy. The current audit report. The architecture record. The named person who confirmed it. An answer with no source behind it isn’t an answer. It’s a sentence that worked once.
I built and personally maintained a library of more than 2,000 vetted questions and answers, and across my career I’ve built and audited over 5,000 responses. Here’s what I’d tell you about search boxes: type two words into any response library and you will get several results that don’t agree with each other. Not because anyone was careless. Because each one was written once, under a deadline, for one buyer’s phrasing, by someone who had no reason to think there’d be a next reader.
The rep on tonight’s deadline has no way to tell which of those is canonical. There’s no marker on it. So they pick the one that looks most recent, and recent is doing an enormous amount of load-bearing work in that sentence.
And the cost of picking wrong doesn’t arrive as a correction. Reviewers cross-check. Against your public documentation, against last year’s response, against what a peer at another company told them. When two of your own answers disagree, the question quietly stops being about hosting or retention and becomes whether anything you sent can be relied on. Nobody tells you that’s what happened. You get more follow-ups, a longer review, a quieter champion.
Won on merit. Killed in the paperwork.
Whether an answer is still true is a related problem and a different one — it’s the subject of a separate piece on expiry dates. This one is narrower: even where the fact hasn’t changed, most teams cannot say which version of the sentence is the real one.
What ownership actually looks like
Not a bigger library. Three things, and none of them are exotic.
A named person per content domain
Not a committee, not a shared inbox, not a function. One name against security, one against privacy, one against infrastructure. The person whose job it is to say that the current answer is the current answer — and who can be wrong, on the record, which is what makes it real.
One canonical entry per question, with its source attached
Not the sentence alone. The thing the sentence rests on. So the next reader inherits the reasoning rather than guessing at it, and so “which source?” has an answer that takes four seconds instead of four emails.
One owner of the stage itself
Separate from the content owners, and this is the one almost nobody has. Somebody who owns the questionnaire as a process — intake, triage, assignment, review, submission — so it stops being a thing that happens to whoever’s nearest. That’s the gap sales, security and product each correctly declined.
It’s the same discipline a deal desk runs over pricing and approvals, pointed at content instead. I built one of those from scratch governing a $25M+ pipeline, and I’ll say plainly that content is the easier of the two problems. It just never had anyone assigned to it.
And speed, since it’s what everyone asks for first: speed is the output of that structure, not a substitute for it. Answer faster without the layer underneath and you’re shipping unverified answers on a shorter timeline, which makes them harder to catch rather than easier.
Every questionnaire your company has ever returned got triaged by somebody. Somebody chased the experts, decided which sentence went out, and carried it to submitted. That work is being done right now, on a deal in your pipeline, by a person who probably wasn’t chosen for it and definitely isn’t measured on it.
On the deal you most want to close this quarter — who is that person?