Client Security Questionnaires: What DFW Professional Firms Are Being Asked

A client security questionnaire is now a routine part of winning professional services work in Dallas-Fort Worth, and the firms that lose on it usually lose for answering badly rather than for being insecure.
It arrives as a spreadsheet attached to an otherwise friendly email. Forty questions, sometimes three hundred. Your client’s procurement or compliance team needs it back in two weeks. Nobody at your firm has seen most of these terms before, and the engagement is worth more than anything else in the pipeline.
This is the newest pressure on professional firms, and it is not going away. It is a direct consequence of regulation flowing downhill: covered institutions are required to oversee their service providers, so they oversee you.
This guide covers what these questionnaires are actually testing, which answers quietly disqualify a firm, and how to get to a position where the next one takes an afternoon instead of a fortnight.

What Is a Client Security Questionnaire and Why Are Firms Receiving Them?
A client security questionnaire is a structured assessment a client sends to verify that your firm protects their data adequately before or during an engagement. Professional firms receive them because regulations like SEC Regulation S-P and the GLBA Safeguards Rule require covered institutions to oversee their service providers, and your firm is a service provider. The questionnaire is how that obligation gets discharged on paper.
Understanding that origin changes how you read the document. It is not your client doubting you. It is your client creating a record that they performed diligence, because someone will eventually ask them to produce it.
Why the Volume Jumped This Year
Three rules push these downstream, and you do not need to know them in detail. You just need to know that your client is being asked, so they are asking you.
- SEC Regulation S-P. Both compliance dates passed this year, which is why the volume jumped. Covered firms must oversee their service providers, and you are one. More in what Reg S-P now requires firms to evidence.
- The GLBA Safeguards Rule. Accounting and tax practices count as financial institutions under it, with IRS Publication 4557 as the yardstick.
- ABA Model Rules 5.1 and 5.3. Law firms must supervise their storage vendors, so corporate clients ask outside counsel to prove it.
The practical effect is a chain. Your client is asked by their regulator. They ask you. You should be asking your IT provider. Firms that cannot complete the third link tend to discover it at the worst moment.

What the Questionnaire Is Really Testing
Most questionnaires draw on a small number of standard instruments: the Standardized Information Gathering (SIG) questionnaire, the Cloud Security Alliance’s Consensus Assessments Initiative Questionnaire, or a bespoke form built from the NIST Cybersecurity Framework or the CIS Critical Security Controls.
Whatever the format, they cluster into six things:
- Access control. Who can reach client data, how they authenticate, and how access is removed when someone leaves.
- Encryption. Data at rest and in transit, and whether you can say which systems are covered.
- Incident response. Whether a written plan exists, who owns it, and how fast you would notify them.
- Backup and recovery. Not whether you back up. Whether you have restored, and when.
- Subcontractors. Who else touches their data, including your IT provider and any offshore support.
- Training and governance. Whether staff are trained, and whether anyone reviews any of this on a schedule.
Have a questionnaire sitting on your desk right now? We complete these for client firms as a standard deliverable, and we will review one with you at no cost. Call (888) 352-4832 or send it over.
Turn a Thin Answer Into an October Project
If a questionnaire has landed and you already know which rows are weak, give the gaps a deadline. October is Cybersecurity Awareness Month, which makes it an easy window to get the work scheduled.
We have written the four-week version we run at professional firms: identity, email, recovery, then evidence, with every item finishable in an afternoon. See Prep for a Secure Firm.
The Answers That Quietly Lose Engagements
Reviewers are rarely looking for perfection. They are looking for signals that a firm has thought about this before today. These are the responses that read badly.
| What firms write | How it reads | Better |
|---|---|---|
| “Yes” with no detail, across every row | Nobody verified any of this | Yes, plus the mechanism and who owns it |
| “We use a firewall and antivirus” | Stopped paying attention around 2015 | Name the identity controls; that is where breaches start now |
| “Our IT company handles that” | The firm has outsourced its own accountability | Name the provider, the control, and your oversight of them |
| “N/A” on incident response | No plan exists | A short written plan is better than a sophisticated absent one |
| Backups described, restore never mentioned | Untested backups | Give the date of your last successful restore test |
| Leaving subcontractor questions blank | Either hiding something or does not know | A current vendor list with owners and review dates |
The single most common disqualifier is inconsistency. A firm claims annual access reviews in one row and cannot name who performs them in another. Reviewers notice, because catching that is the job.
How to Answer Well
Build the evidence pack once
Nearly every questionnaire asks for the same underlying facts. Assemble them once and maintain them: a current network and data inventory, your written incident response plan or WISP, the date of your last restore test, your access review records, a subcontractor list, and your training completion records. After that, each new questionnaire is a mapping exercise.
Never overstate
A questionnaire response is a representation to a client, and in a regulated relationship it can end up in front of an examiner. If a control is partial, say it is partial and give the remediation date. Reviewers accept gaps with plans far more readily than they accept claims that collapse under a follow-up question.
Answer the subcontractor questions honestly
Your IT provider is a subcontractor with access to client data. Naming them is expected. What reviewers want to see is that you oversee them, which means you should be able to produce their security documentation on request. If your provider cannot supply it, that is worth knowing before a client asks.
Put one person in charge
Questionnaires that get routed to whoever is least busy produce inconsistent answers. One owner, with your IT provider supplying the technical rows, produces a document that holds together. For firms without an obvious owner, a vCISO arrangement covers the role without a full-time hire.
Frisco, Plano and Irving: Who Is Getting Asked
Irving and Las Colinas firms face this earliest and hardest. The corridor’s corporate and institutional tenant base runs mature vendor due diligence, so a Las Colinas firm often fields an enterprise-grade questionnaire while still small enough that nobody owns security. Our Managed IT Irving practice works from an office at 7301 State Hwy 161, and our Managed IT Irving team spends a disproportionate share of its time on exactly these responses.
Plano firms tend to receive them from long-standing clients whose own compliance posture has tightened, which makes the request feel like a change in a relationship rather than a new one. Our Managed IT Plano team handles these for advisory and accounting practices, and our Managed IT Plano security practice supplies the technical evidence.
Frisco firms are newer and more often growing into their first questionnaires as they move upmarket. The good news is that cloud-native firms usually have better underlying controls than they realize and simply lack the documentation. DKBinnovative is headquartered in Frisco; our Managed IT Frisco and Managed IT Frisco teams cover this work.
Frequently Asked Questions
What is a client security questionnaire?
A client security questionnaire is a structured assessment a client sends to verify that your firm protects their data adequately before or during an engagement. Professional firms receive them because regulations like SEC Regulation S-P and the GLBA Safeguards Rule require covered institutions to oversee their service providers, and your firm is a service provider.
Why are we suddenly getting so many?
Because both Reg S-P compliance dates have now passed, in December 2025 for larger entities and June 2026 for smaller ones. Covered institutions that were preparing are now executing, and service provider oversight is one of the obligations they execute by sending questionnaires downstream.
Do we have to answer them?
Not legally, in most cases. Commercially, declining to answer usually ends the engagement, because your client cannot discharge their own oversight obligation without your response.
What if we cannot answer yes to everything?
Almost nobody can. Say the control is partial, describe what exists, and give a remediation date. Reviewers routinely accept gaps with credible plans. What they do not accept is a claim that fails on a follow-up question, because that damages the whole submission.
Should our IT provider complete it for us?
They should complete the technical sections and supply their own security documentation, but the firm should own the submission. The questionnaire is a representation your firm makes to a client, and answers you have not read are answers you cannot stand behind.
How can we use Cybersecurity Awareness Month at a professional firm?
Treat a client security questionnaire as the exercise. Answer a real or blank questionnaire honestly as a firm during October, and you finish the month with a ranked gap list, a reusable evidence pack, and a named owner for security. CISA’s baseline steps for the month each map to a row on a client questionnaire.
How long does a questionnaire take to complete?
The first one commonly takes two to three weeks of intermittent work. Once the underlying evidence pack exists, subsequent questionnaires typically take a day or two, because most of the work is mapping existing answers to a new format.
Working With DKBinnovative
We have supported professional firms across Dallas-Fort Worth since 2004, which is 22 years, and we complete client security questionnaires as a standard deliverable rather than a favour. Today that spans 2,632+ end users across 55+ companies, with a 78% first-call resolution rate and 98.14% client satisfaction. Our infrastructure standardizes on Microsoft Azure and Microsoft 365, and we deploy Hatz.AI where firms need governed AI that keeps client material inside their own tenant.
If a questionnaire is sitting on your desk, send it to us. We will tell you which rows you can already answer, which need work, and how long that work takes.
Call (888) 352-4832 or send us the questionnaire.
Related reading: Investment & Professional Firms · IT Support for Law & Accounting Firms · Reg S-P Is Now in Force · IT Due Diligence · Financial Services IT
External references: 17 CFR Part 248, IRS Publication 4557, Shared Assessments SIG, CSA Cloud Controls Matrix, NIST CSF, CIS Controls, CISA Cybersecurity Awareness Month.
Serving the DFW Metroplex
