Use cases

Vendor security questionnaires between customer and vendor agents

How customer and vendor agents could exchange SIG and CAIQ answers, SOC 2 reports and security contacts without spreadsheets, and what must stay with people.

How it works today

Security questionnaires exist because regulated buyers must assess their suppliers. In the US, the Federal Reserve, FDIC and OCC issued final joint guidance on third-party relationships on 6 June 2023. It covers the whole life cycle: planning, due diligence and third-party selection, contract negotiation, ongoing monitoring and termination. In Canada, OSFI’s Guideline B-10 on third-party risk management, dated April 2023, expects federally regulated financial institutions to apply it in proportion to the risk and criticality of each arrangement. It names the third party’s information management, data, cyber security and privacy practices among the things to assess, and says the agreement should give the institution and OSFI the right to evaluate the related risk management practices. B-10 reaches the practices of the third party’s subcontractors too, so the questions travel down supply chains.

The formats are familiar to every vendor security team:

Artifact Publisher What it is
SIG (Standardized Information Gathering) Shared Assessments A licensed questionnaire covering 21 risk control areas, regularly updated; SIG EV is its cloud-based version
CAIQ v4 Cloud Security Alliance Yes/no questions a customer or auditor can ask a cloud provider about compliance with the Cloud Controls Matrix v4; also used for STAR Level 1 self-assessments
SOC 2 report AICPA framework, issued by a CPA An assurance report from an examination of controls relevant to security, availability, processing integrity, confidentiality or privacy
ISO/IEC 27001:2022 certificate Accredited conformity assessment bodies Certification of an information security management system; optional for the organization
security.txt (RFC 9116) IETF A file at /.well-known/security.txt with required Contact and Expires fields; a digital signature is recommended

The workflow is mostly documents in motion. The customer sends a spreadsheet or a portal invitation. The vendor’s security team answers from last year’s responses, attaches its SOC 2 report once an NDA is in place, and handles follow-up questions by email. The cycle repeats at renewal, and each customer may ask the same questions in a different layout.

The agent-to-agent version

Illustrative. A customer’s third-party risk agent asks a vendor’s trust agent for its current CAIQ responses and SOC 2 report. The vendor’s agent confirms that an NDA covers the requesting company, then completes the task with two artifacts, in A2A v1.0 shapes:

{
  "id": "task-sq-1207",
  "contextId": "ctx-vendor-review-2026",
  "status": {
    "state": "TASK_STATE_COMPLETED",
    "timestamp": "2026-10-09T18:40:00Z"
  },
  "artifacts": [
    {
      "artifactId": "art-caiq-v4",
      "name": "CAIQ v4 responses",
      "parts": [
        {
          "url": "https://trust.vendor.example/share/caiq-v4-2026.xlsx",
          "filename": "caiq-v4-2026.xlsx",
          "mediaType": "application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"
        }
      ]
    },
    {
      "artifactId": "art-soc2",
      "name": "SOC 2 report",
      "parts": [
        {
          "data": {
            "reportType": "SOC 2",
            "categoriesInScope": ["security", "availability", "confidentiality"],
            "reportDate": "2026-07-31",
            "ndaReference": "NDA-2026-118",
            "linkExpires": "2026-10-16T18:40:00Z"
          },
          "mediaType": "application/json"
        },
        {
          "url": "https://trust.vendor.example/share/soc2-2026.pdf",
          "filename": "soc2-2026.pdf",
          "mediaType": "application/pdf"
        }
      ]
    }
  ]
}

Follow-up questions arrive as new messages on the same contextId. When the customer asks for something the approved material does not cover, such as a commitment to add a control by a date, the vendor’s agent moves the task to TASK_STATE_INPUT_REQUIRED and a security engineer answers.

What has to be true

Identity. The vendor is about to share confidential audit material, so it must know which company’s agent is asking and that this company signed the NDA. The customer must know the answers came from the vendor’s own agent. A2A lets providers sign Agent Cards (section 8.4) and serve an authenticated extended card with more detail to known clients. A Signed Agent Card proves who holds the key; mapping that key to the vendor in the customer’s inventory is the customer’s job.

Authority. An answer in a security questionnaire can become a contractual representation. The vendor’s agent should answer only from material the security team approved, and should label anything it infers. Commitments to change controls belong to people.

Record. Regulators expect ongoing monitoring, so the customer needs to show what the vendor said and when. The vendor needs the same record in case an answer is disputed after an incident.

Freshness. Every answer should carry the date it was approved and the evidence it rests on, such as the audit report it cites. security.txt shows the idea in miniature: RFC 9116 makes Expires a required field, so a reader can tell when the information is stale. An agent answering from last year’s material should say so, and a customer’s agent should reject answers older than its policy allows.

Accuracy of claims. Wording matters. A company has a SOC 2 report for a defined scope and date. It is certified to ISO/IEC 27001:2022 only if a certification body issued a certificate, and ISO notes that a certificate from an accredited body adds confidence. An agent that says “SOC 2 certified” is making a claim no auditor issued.

Security of the channel. Agents that hand out audit reports are attractive targets for impersonation and prompt injection. Section 13 of the A2A specification covers security considerations for agent deployments, and document links should expire.

Where Emissar fits

  • Front Door (Open to design partners): a hosted A2A endpoint where a vendor exposes a trust skill that answers from approved material and passes the rest to its team.
  • Verify (In development): checks which company’s agent is asking before any confidential report leaves the vendor.
  • Ledger (Spec in progress): a signed record of which answers and documents were shared, with whom and when.
  • Handoff (In development): routes new commitments and exceptions to the vendor’s security team with the exchange attached.

Open questions

  • Will SIG and CAIQ publishers define machine-readable answer formats that agents can exchange directly, beyond spreadsheets?
  • Could a vendor publish a signed, machine-readable security profile next to its Agent Card and security.txt, so routine questions need no exchange at all?
  • How should an agent flag answers that are older than the latest audit report?
  • Who is accountable when an agent gives an inaccurate answer that a customer relied on?

Questions

Is a SOC 2 report a certification?
No. SOC 2 is an examination that a CPA performs, and the output is an assurance report on a service organization's controls relevant to security, availability, processing integrity, confidentiality or privacy. Certification is the right word for ISO/IEC 27001, where certificates come from accredited conformity assessment bodies.
Can an agent answer a whole questionnaire on its own?
It can answer from approved material, such as a current CAIQ, a policy library and the latest audit report. New commitments, exceptions and anything the approved material does not cover should go to the vendor's security team.

Sources

  1. Shared Assessments: SIG (Standardized Information Gathering) and SIG EV (accessed )
  2. Cloud Security Alliance: STAR Level 1 Security Questionnaire (CAIQ v4) (accessed )
  3. AICPA & CIMA: System and Organization Controls (SOC) Suite of Services (accessed )
  4. ISO/IEC 27001:2022 Information security management systems (accessed )
  5. RFC 9116: A File Format to Aid in Security Vulnerability Disclosure (accessed )
  6. Federal Reserve Board: Agencies issue final guidance on third-party risk management (6 June 2023) (accessed )
  7. OSFI Guideline B-10: Third-Party Risk Management (accessed )
  8. A2A Protocol Specification (sections 7.6, 8.4 and 13) (accessed )
  9. A2A protocol definition (a2a.proto): Task, Artifact, Part (accessed )