Platform

A questionnaire is a schema in a spreadsheet costume.

Upload the workbook you already use. TruOps turns it into a real instrument, with questions, branching, and scoring, instead of a file someone retypes.

Questionnaire builder · VendorAssessment_2026.xlsxmapping columns
Workbook columnMapped toExampleConfidence
B: DomainSectionAccess Control0.99
C: Question TextQuestionIs MFA required for remote access?0.98
D: Response OptionsAnswer type + optionsYes / No / Partial / N/A0.95
F: WeightQuestion weight30.93
G: RefControl mappingISO A.5.17 · SOC 2 CC6.10.78 · review
H: If "No"Conditional ruleshow 4.3a–4.3c0.74 · review
312questions structured14sections27mappings for review
Illustrative example
In short

The TruOps questionnaire builder imports an assessment workbook and produces a structured questionnaire: sections, questions, answer types and options, weighted scoring, required evidence, conditional logic, and a mapping from each question to controls with a confidence score and citation. Questions it can already answer from your evidence are pre-filled.

This page is for you if
  • Your real assessment is a workbook the GRC tool cannot ingest
  • SIG/CAIQ/custom all need to become scored, branching instruments
  • Control mapping is a consultant exercise

The actual challenge

Questionnaires are schemas wearing spreadsheet costumes. Retyping them into a GRC tool is why new assessments take a quarter.

  • The current tool starts empty, or only works for one framework.
  • Evidence, vendors, and risk do not share a record.
  • AI, if it exists, suggests; it does not do the work with sources.

What you are probably using today

This module is usually replacing a folder, a suite module, or a point tool, not a blank page.

What you use nowWhere it breaksWith TruOps
Spreadsheets, shared drives, and emailThe program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter.Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period.
Survey tools that cannot map to controlsYou get answers, not coverage.Import the workbook; TruOps infers types, scoring, logic, and cited control maps for review.
Enterprise GRC suitesThey can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project.AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project.

Bring one real document. Watch the program get set up from it.

What an upload configures

PartWhat TruOps sets up
SectionsSection names and weights, mapped to controls
QuestionsQuestion text and order
Answer typesYes/no, single or multiple choice, rating, number, and more, inferred from the column and its options
ScoringQuestion and answer weights, control credit, and score bands
Control mappingEach question mapped to controls, with a confidence score and citation
Evidence rulesRequired, comment-required, and evidence-required flags with instructions
Conditional logicShow, hide, or require questions based on earlier answers
Pre-answersStanding answers pre-filled from documents already in the Data Room

Built from your workbook, checked by you

The importer maps common columns directly (section, question, answer type, options, weight, control, required, comment required, evidence required, guidance). Everything else, including control mappings, scoring bands, conditional logic, and pre-answers, is derived by agents and presented for review. Standard libraries such as SIG Lite, CAIQ, NIST CSF, ISO 27001, and CIS are available as starting points.

Versions that stay put

Each assessment locks the questionnaire version it started with, so changing a questionnaire mid-cycle does not change the rules of a run already under way.

How TruOps helps

Workbook import
Bring your existing questionnaire; AI proposes how each column maps.
Conditional logic
Branching questions that show, hide, or require based on answers.
Weighted scoring
Weights, bands, and maturity levels you control.
Control mapping
Every question tied to the controls and frameworks it informs.
Evidence requirements
Say which questions need proof, and what kind.
Version locking
Runs keep the version they started on.

Questions

Can I import my existing questionnaire?

Yes. Upload the workbook; TruOps proposes the mapping for each column and derives scoring, logic, and control mappings for you to review.

Does TruOps include standard questionnaires?

Yes. Standard instruments such as SIG Lite, CAIQ, NIST CSF, ISO 27001, CIS, HIPAA, and CMMC are available as starting points, and you can edit them.

Can questions branch based on answers?

Yes. Conditional rules can show, hide, or require questions depending on earlier answers.

Do we have to rip out the tools we already use?

No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.

Can we bring our existing assessments, control lists, and vendor files?

Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.

See it run on your own data.

Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.