questionnaire-analyzer

Identify red flags, gaps, and follow-up needs in vendor security questionnaires.

1|Updated Apr 25, 2026
One-click install
npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill questionnaire-analyzer-rifh2000
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: questionnaire-analyzer
Source: https://github.com/rifh2000/claude-grc-engineering./tree/main/plugins/grc-tprm/skills/questionnaire-analyzer
Command: npx skills add https://github.com/rifh2000/claude-grc-engineering. --skill questionnaire-analyzer-rifh2000

SYSTEM DOCUMENTATION & REQUIREMENTS

What problem does it solve?

Vendor security questionnaires are often lengthy and ambiguous. This Skill analyzes responses to identify red flags, gaps, and areas requiring follow-up to shorten cycle times and improve risk decisions.

Core Features & Use Cases

  • Red flag detection in SIG, CAIQ, and custom questionnaires
  • Gap analysis against baseline controls
  • Actionable follow-up questions and remediation suggestions
  • Use Case: Apply to a vendor's SIG questionnaire to surface missing evidence like incident response plans or encryption details.

Quick Start

Supply a vendor questionnaire response set and ask the tool to perform a red-flag and gap analysis.

Frequently Asked Questions about questionnaire-analyzer

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I analyze vendor security questionnaires for red flags and gaps?

You can analyze vendor security questionnaires for red flags and gaps by supplying the response set to the tool, which parses answers, detects risk indicators, and maps findings against baseline controls to produce structured follow-up actions.

Can I use this tool to perform gap analysis on SIG and CAIQ questionnaires?

Yes, you can perform gap analysis on SIG and CAIQ questionnaires, as well as custom questionnaires across various vendor domains, to surface missing evidence like incident response plans or encryption details and recommend follow-ups.

What is the best way to identify missing evidence in a vendor risk assessment?

The best way to identify missing evidence in a vendor risk assessment is to apply a gap analysis tool to the questionnaire responses, which maps answers to baseline controls and highlights areas requiring remediation or follow-up questions.

Does the tool generate remediation suggestions for questionnaire responses?

Yes, the tool generates remediation suggestions and actionable follow-up questions by parsing questionnaire responses and producing structured outputs that map to baseline controls to shorten cycle times and improve risk decisions.

What do I need to provide to start a vendor questionnaire analysis?

To start a vendor questionnaire analysis, you need to supply a vendor questionnaire response set, such as SIG or CAIQ data, and ask the tool to perform a red-flag and gap analysis to surface risk indicators.