A questionnaire is a schema in a spreadsheet costume.
Upload the workbook you already use. TruOps turns it into a real instrument, with questions, branching, and scoring, instead of a file someone retypes.
| Workbook column | Mapped to | Example | Confidence |
|---|---|---|---|
| B: Domain | Section | Access Control | 0.99 |
| C: Question Text | Question | Is MFA required for remote access? | 0.98 |
| D: Response Options | Answer type + options | Yes / No / Partial / N/A | 0.95 |
| F: Weight | Question weight | 3 | 0.93 |
| G: Ref | Control mapping | ISO A.5.17 · SOC 2 CC6.1 | 0.78 · review |
| H: If "No" | Conditional rule | show 4.3a–4.3c | 0.74 · review |
The TruOps questionnaire builder imports an assessment workbook and produces a structured questionnaire: sections, questions, answer types and options, weighted scoring, required evidence, conditional logic, and a mapping from each question to controls with a confidence score and citation. Questions it can already answer from your evidence are pre-filled.
- Your real assessment is a workbook the GRC tool cannot ingest
- SIG/CAIQ/custom all need to become scored, branching instruments
- Control mapping is a consultant exercise
The actual challenge
Questionnaires are schemas wearing spreadsheet costumes. Retyping them into a GRC tool is why new assessments take a quarter.
- The current tool starts empty, or only works for one framework.
- Evidence, vendors, and risk do not share a record.
- AI, if it exists, suggests; it does not do the work with sources.
What you are probably using today
This module is usually replacing a folder, a suite module, or a point tool, not a blank page.
| What you use now | Where it breaks | With TruOps |
|---|---|---|
| Spreadsheets, shared drives, and email | The program lives in folders named after last year's audit. Owners paste screenshots the week before fieldwork. Nothing is dated, so you cannot show what was true last quarter. | Upload those same files. TruOps pre-fills the assessment from them, cites every answer, and keeps technical checks running so evidence exists for the whole period. |
| Survey tools that cannot map to controls | You get answers, not coverage. | Import the workbook; TruOps infers types, scoring, logic, and cited control maps for review. |
| Enterprise GRC suites | They can model almost anything. That flexibility usually comes through implementation partners and administrators, so a change can become a project. | AI reads your existing documents and sets up the program. The first assessment opens pre-filled from them, with sources. Changes are a request in plain language, not a project. |
Bring one real document. Watch the program get set up from it.
What an upload configures
| Part | What TruOps sets up |
|---|---|
| Sections | Section names and weights, mapped to controls |
| Questions | Question text and order |
| Answer types | Yes/no, single or multiple choice, rating, number, and more, inferred from the column and its options |
| Scoring | Question and answer weights, control credit, and score bands |
| Control mapping | Each question mapped to controls, with a confidence score and citation |
| Evidence rules | Required, comment-required, and evidence-required flags with instructions |
| Conditional logic | Show, hide, or require questions based on earlier answers |
| Pre-answers | Standing answers pre-filled from documents already in the Data Room |
Built from your workbook, checked by you
The importer maps common columns directly (section, question, answer type, options, weight, control, required, comment required, evidence required, guidance). Everything else, including control mappings, scoring bands, conditional logic, and pre-answers, is derived by agents and presented for review. Standard libraries such as SIG Lite, CAIQ, NIST CSF, ISO 27001, and CIS are available as starting points.
Versions that stay put
Each assessment locks the questionnaire version it started with, so changing a questionnaire mid-cycle does not change the rules of a run already under way.
How TruOps helps
- Workbook import
- Bring your existing questionnaire; AI proposes how each column maps.
- Conditional logic
- Branching questions that show, hide, or require based on answers.
- Weighted scoring
- Weights, bands, and maturity levels you control.
- Control mapping
- Every question tied to the controls and frameworks it informs.
- Evidence requirements
- Say which questions need proof, and what kind.
- Version locking
- Runs keep the version they started on.
Questions
Can I import my existing questionnaire?
Yes. Upload the workbook; TruOps proposes the mapping for each column and derives scoring, logic, and control mappings for you to review.
Does TruOps include standard questionnaires?
Yes. Standard instruments such as SIG Lite, CAIQ, NIST CSF, ISO 27001, CIS, HIPAA, and CMMC are available as starting points, and you can edit them.
Can questions branch based on answers?
Yes. Conditional rules can show, hide, or require questions depending on earlier answers.
Do we have to rip out the tools we already use?
No. Connectors are read-only: they observe cloud, identity, endpoint, vulnerability, and code tools; they do not change them. Spreadsheets, prior reports, and policies upload into the Data Room. If you are on a SOC 2 automation tool or an enterprise GRC suite, you migrate the program (frameworks, evidence, vendors, risks), not the business.
Can we bring our existing assessments, control lists, and vendor files?
Yes. Upload workbooks, reports, policies, and vendor exports. TruOps turns them into structured questionnaires, controls, and register entries, each cited back to the file they came from, for you to review.
Related
One engine for compliance, risk, vendor, and customer assessments.
→PlatformQuestionnaire responseAnswer customer security questionnaires from your own evidence.
→LearnSecurity questionnaireWhat customer security questionnaires are and how to answer them.
→FrameworksCustom frameworksBring your own internal standard; TruOps maps it.
→See it run on your own data.
Thirty minutes with a GRC expert, not an SDR. Bring one real document (a SOC 2 report, a risk register, a vendor list; redacted is fine) and watch TruOps set up a live program from it, with an assessment already pre-filled.