Hi everyone, I’ve been tasked with helping my team evaluate Vanta for our own compliance needs, but we also have a potential enterprise client asking if we can meet specific security controls. My manager suggested I create a custom questionnaire for them, pulling from Vanta’s capabilities, to demonstrate our posture.
I’ve seen that Vanta has a lot of pre-built templates and integrations, which is great. But I’m a bit unsure about the actual step-by-step process for building something bespoke. Does it start from duplicating an existing framework like SOC 2 and then modifying it? Or is there a completely blank slate “custom questionnaire” builder somewhere?
Specifically, I’m curious about a few things:
- How do you map your client’s specific questions to Vanta’s existing tests or evidence? Do you just link to a control, or can you write a new test for a one-off question?
- If a client asks for something Vanta doesn’t automatically monitor, how do you typically handle that? Do you upload manual evidence into that custom section?
- Is there a way to share just this custom questionnaire with the client, or do they see your whole Vanta workspace?
I’m trying to avoid over-promising or creating a ton of manual work for our team. Any guidance or lessons learned from those who’ve done this would be super helpful. 😅