Vendor Questionnaires and Due Diligence Requests
KA-11420
1
07/24/2026 22:17 PM
1.0
Overview
This article explains how to submit vendor questionnaires, due diligence requests, and other compliance-related assessments to Authorize.net. These requests are separate from Statement on Standards for Attestation Engagements No. 18 (SSAE-18) and Service Organization Controls (SOC) report requests, and require review by internal compliance, security, risk, or regulatory teams. Use this article when your organization needs Authorize.net to complete a formal risk or compliance assessment as part of your vendor management process.
Examples of Requests
The following request types are commonly submitted:
- Vendor Risk Assessment
- Security Questionnaire
- Due Diligence Package
- Supplier Review
- Compliance Questionnaire
- Audit Survey
- Third-Party Risk Assessment
Submitting a Request
To submit a vendor questionnaire or due diligence request, submit a Support Case and include the following information:
- Providing your full name.
- Providing your job title (Senior Manager or above).
- Providing your company name, including DBA if applicable.
- Specifying the due date.
- Including a description of the requested information.
- Attaching the questionnaire or assessment document.
Providing complete information helps expedite review and routing of the request.
What Happens Next
After you submit the Support Case:
- Support reviews the request.
- The request is routed to the appropriate internal team for evaluation.
- The assigned team reviews the request and determines the appropriate response.
Some requests may require coordination across multiple internal teams depending on the information being requested.
Important Notes
- Vendor questionnaires and due diligence requests are not SSAE-18 or SOC report requests.
- Requests should include all required attachments and supporting information when submitted.
- Incomplete submissions may require additional follow-up before review can begin.
Common Questions
- Can I request completion of a security questionnaire?
- Yes. Submit a Support Case and include the completed questionnaire, due date, and a description of the requested information.
- Is a vendor questionnaire the same as an SSAE-18 or SOC report request?
- No. Vendor questionnaires and due diligence requests are handled separately from SSAE-18 and SOC report requests.
- What information should I include with my request?
- Include your company name, contact information, due date, questionnaire or assessment attachment, and a description of the requested information.
- Who reviews these requests?
- Requests are reviewed by Support and routed to the appropriate internal compliance, security, risk, or regulatory team for evaluation.
- What happens if my submission is incomplete?
- Incomplete submissions may require additional follow-up before review can begin, which can delay processing.
Glossary
- SSAE-18 – Statement on Standards for Attestation Engagements No. 18
- SOC – Service Organization Controls
Related Resources
- Requesting SSAE-18 SOC Reports
- Is Authorize.net PCI DSS compliant?
- Authorize.net Data Security and Compliance
Was this article helpful?
