# Supplier Assurance Questionnaire

**Supplier legal name:** ____________________  **ABN/ACN:** ____________
**Contact name and role:** ____________________  **Email / phone:** ____________
**Goods or services supplied:** ____________________________________________
**Assurance tier:** ☐ Tier 1 (on-site audit) ☐ Tier 2 (desktop assessment) ☐ Tier 3 (self-assessment)
**Completed by:** ____________________  **Date:** ____________

---

## Section A — Company and governance

1. How long has the organisation traded under its current entity?
2. List directors and any parent or related entities.
3. Are there any current or pending legal, regulatory or insolvency proceedings? Provide details.
4. Who is accountable for quality, security and WHS? Provide names and roles.
5. Attach a current organisation chart.

## Section B — Insurance and certification

| Item | Held (Y/N) | Insurer / certifying body | Policy or certificate number | Expiry |
|---|---|---|---|---|
| Public liability | | | | |
| Professional indemnity | | | | |
| Workers compensation | | | | |
| ISO 9001 (Quality) | | | | |
| ISO 27001 (Information security) | | | | |
| ISO 45001 (WHS) | | | | |
| Other (specify) | | | | |

## Section C — Quality management

6. Is a documented quality management system in place? Attach the scope statement.
7. How are nonconformities recorded, investigated and closed?
8. Provide the number of external audit findings raised in the last 12 months and their closure status.
9. How is inspection and test activity evidenced for the work you would perform for us?

## Section D — Personnel security

10. What pre-employment checks are conducted (identity, right to work, police check, referee)?
11. Do any personnel hold Australian Government security clearances? State levels and count.
12. How are access rights removed when a worker leaves or changes role, and within what timeframe?
13. Are confidentiality or non-disclosure agreements in place with all personnel?

## Section E — Information and cyber security

14. How is our information classified, stored, transmitted and destroyed?
15. Is data stored or accessed offshore? List all countries and providers.
16. Describe your multi-factor authentication, patching and backup practices.
17. Have you experienced a reportable data breach in the last 24 months? Provide details and remediation.

## Section F — Subcontracting

18. Will any part of the work be subcontracted? Identify each subcontractor and scope.
19. How are the obligations in this questionnaire flowed down to subcontractors?
20. What assurance do you perform over your own suppliers, and how often?

## Section G — Incident notification and continuity

21. Within what timeframe will you notify us of a security, quality or privacy incident affecting our work?
22. Attach your business continuity and disaster recovery summary, including last test date.
23. What are your record retention periods for work performed for clients?

---

## Declaration

I confirm the information provided is accurate and complete at the date of signing, and undertake to notify the client of any material change within 14 days.

**Name:** ____________________  **Position:** ____________________
**Signature:** ____________________  **Date:** ____________

---

## For client use only

| Assessment element | Rating (Acceptable / Conditional / Not acceptable) | Comment |
|---|---|---|
| Governance and financial standing | | |
| Insurance and certification currency | | |
| Quality system maturity | | |
| Personnel security | | |
| Information security | | |
| Subcontractor control | | |
| Incident and continuity readiness | | |

**Overall outcome:** ☐ Approved ☐ Approved with conditions ☐ Not approved
**Conditions / actions:** ____________________________________________
**Assessor:** ____________  **Date:** ____________  **Next review:** ____________

---
Template provided by Jd Global Quality & Security Solutions Pty Ltd, Canberra.
