The Dutch insurers' supplier security questionnaire
If you want to supply software or services to a Dutch insurer, you may receive this questionnaire before there is a contract. Its Dutch name is vragenlijst leveranciersselectie informatiebeveiliging: 18 questions, version 1.0 from July 2023, published on the website of the Dutch Association of Insurers (Verbond van Verzekeraars). Your answers decide whether you move on to the next selection round.
What the questionnaire is for
It gives the buyer a quick view of how mature your information security is, before any contract. Based on your answers, the organisation decides whether to move on to selecting your service and then to a contract. The formal security agreements are only made in that contract.
The document itself proposes that insurers and financial institutions adopt the questions in full, so a supplier only has to answer them once. That is why it pays to write answers you can reuse with the next insurer.
What it covers
Each question refers to a control in ISO/IEC 27002:2022. The 18 questions cover:
- certifications and assurance statements
- information security and business continuity (BCM) policy
- the security organisation and reporting lines
- authorisation policy, logical access and agreements with your own suppliers
- your standard SLA and incident management
- IT continuity and disaster recovery
- privacy
- secure software development, including penetration testing
- awareness, physical security and configuration baselines
- network segregation, cryptography, separation of environments and change management
What evidence they ask for
Some questions ask for a document or a concrete fact, not just an answer:
- Question 1: which certifications and assurance statements you hold.
- Question 2: your information security and BCM policy, to share.
- Question 3: preferably a diagram of your security organisation and reporting lines.
- Question 4: your authorisation policy and process.
- Question 7: a template of your standard SLA.
- Question 9: whether your continuity and recovery plans were tested in the past 12 months.
- Question 11: assurance or audit reports showing at least one penetration test a year, with findings resolved according to severity.
If you do not have one of these documents, it shows straight away. It is better to be open about that up front than afterwards.
How to approach it
- Gather the documents. Certificates, policies, organisation chart, SLA template, your latest penetration test and the report of your latest continuity test.
- Answer each question with a reference. Name the document and the section. That makes your answer verifiable.
- Use the ISO reference. If you work with ISO 27001, link your answer to the same control. A reviewer recognises that immediately.
- Name what is still missing. No penetration test this year, or no tested recovery? Write what you will do and when.
- Keep your answers. Other insurers may use the same list.
Common mistakes
- A “yes” on penetration testing without a report to back it up
- Citing policies that were never approved or have not been reviewed for years
- Promising an SLA in the questionnaire that differs from your standard contract
- Skipping the questions about your own suppliers while you rely on hosting and third-party software
How Holdvero helps
We complete the questionnaire based on your own documentation, with the source for every answer. Where evidence is missing, we write an open item instead of a “yes”, with what is needed to close it. This questionnaire falls under Questionnaire Rescue: €695, returned within 3–5 working days after a complete intake. Holdvero does not provide certification or legal advice; you decide what goes to your customer.
Frequently asked questions
Is this questionnaire mandatory?
No. It is a tool for the pre-contract phase. An insurer can use it, adapt it or send its own list.
Do I need ISO 27001 certification?
No. Question 1 asks which certifications and assurance statements you hold. If you have none, you show how you have arranged things with policies, procedures and test results.
Where can I find the questionnaire itself?
The Dutch Association of Insurers publishes it in Dutch as a PDF and a Word file.
How long does it take?
Eighteen questions looks short, but almost every question asks for a document. Gathering the evidence usually takes most of the time.
Need help with this questionnaire?
Within 1 working day you'll hear the price and when you get it back. You only pay after agreeing the price.
Get a fixed price