web
You’re offline. This is a read only version of the page.
close

What can we help you with?


KA-11420


1

07/24/2026 22:17 PM

1.0

Overview

This article explains how to submit vendor questionnaires, due diligence requests, and other compliance-related assessments to Authorize.net. These requests are separate from Statement on Standards for Attestation Engagements No. 18 (SSAE-18) and Service Organization Controls (SOC) report requests, and require review by internal compliance, security, risk, or regulatory teams. Use this article when your organization needs Authorize.net to complete a formal risk or compliance assessment as part of your vendor management process.

Examples of Requests

The following request types are commonly submitted:

  • Vendor Risk Assessment
  • Security Questionnaire
  • Due Diligence Package
  • Supplier Review
  • Compliance Questionnaire
  • Audit Survey
  • Third-Party Risk Assessment

Submitting a Request

To submit a vendor questionnaire or due diligence request, submit a Support Case and include the following information:

  1. Providing your full name.
  2. Providing your job title (Senior Manager or above).
  3. Providing your company name, including DBA if applicable.
  4. Specifying the due date.
  5. Including a description of the requested information.
  6. Attaching the questionnaire or assessment document.

Providing complete information helps expedite review and routing of the request.

What Happens Next

After you submit the Support Case:

  1. Support reviews the request.
  2. The request is routed to the appropriate internal team for evaluation.
  3. The assigned team reviews the request and determines the appropriate response.

Some requests may require coordination across multiple internal teams depending on the information being requested.

Important Notes

  • Vendor questionnaires and due diligence requests are not SSAE-18 or SOC report requests.
  • Requests should include all required attachments and supporting information when submitted.
  • Incomplete submissions may require additional follow-up before review can begin.

Common Questions

  • Can I request completion of a security questionnaire?
    • Yes. Submit a Support Case and include the completed questionnaire, due date, and a description of the requested information.
  • Is a vendor questionnaire the same as an SSAE-18 or SOC report request?
    • No. Vendor questionnaires and due diligence requests are handled separately from SSAE-18 and SOC report requests.
  • What information should I include with my request?
    • Include your company name, contact information, due date, questionnaire or assessment attachment, and a description of the requested information.
  • Who reviews these requests?
    • Requests are reviewed by Support and routed to the appropriate internal compliance, security, risk, or regulatory team for evaluation.
  • What happens if my submission is incomplete?
    • Incomplete submissions may require additional follow-up before review can begin, which can delay processing.

Glossary

  • SSAE-18 – Statement on Standards for Attestation Engagements No. 18
  • SOC – Service Organization Controls

Related Resources

 



Was this article helpful?


Articles Recommended for You