How to answer the security questions in a collections RFP
Creditors send the same forty questions to every agency. Here is what each one is really asking, what a strong answer looks like, and where most agencies lose points.
Creditors send the same forty questions to every agency. Here is what each one is really asking, what a strong answer looks like, and where most agencies lose points.
If you have answered a creditor's vendor-security questionnaire, you know the format: a spreadsheet, somewhere between forty and four hundred rows, that asks about encryption, access control, incident response and a dozen frameworks by name. Most agencies treat it as a form to get through. It is actually a filter, and the answers decide whether your bid gets read.
The questions are more predictable than they look. They come in seven groups, and each group has a real question underneath the jargon.
What they're asking: has a third party checked your controls, and are you handling the categories of data we'll send you? What a strong answer looks like: name the report, its type and period, who issued it, and offer it under NDA. If your platform vendor holds the certification, say so and attach their report; then explain what you control on top of it. Where agencies lose points: writing "compliant" without a report, or claiming HIPAA "certification," which does not exist. Say "we operate as a business associate under a signed BAA and our controls are assessed for the HIPAA Security Rule."
What they're asking: location, tenancy and access. Strong answer: the hosting provider and region, whether their data is logically separated from other clients', the role-based access model, and how many of your staff can see raw consumer data (the number should be small and you should know it). Say how you handle a departing employee's access on their last day. Lose points: "only authorized personnel," which is a tautology.
Strong answer: in transit (TLS 1.2 or higher on every connection, including SFTP for files) and at rest (which algorithm, who holds the keys). If cards are tokenized by a PCI-validated processor and never stored in your system, say that; it is the answer they want. Lose points: describing encryption of the website while file transfers still go by email attachment.
What they're asking: do you have an incident-response plan and will we hear about it? Strong answer: the plan exists, it names roles, it has been exercised in the last twelve months, and the notification commitment to the client is a number of hours, not "promptly." Lose points: no exercise, no number, and no mention of your state breach-notification obligations.
Strong answer: a list of subprocessors (platform, print vendor, dialer, payment processor, skip-trace, letter vendor) with what each receives, and the contract terms that flow your obligations down to them. Lose points: forgetting the print vendor, who sees the most PII of anyone.
Strong answer: every access to a consumer record is logged with who, when and what; logs are retained for a defined period; the client may audit on notice. Say what your retention schedule is for consumer data after an account closes, and how deletion is executed and confirmed. Lose points: an audit trail that exists only for edits, not for views.
Strong answer: recovery time and recovery point objectives as numbers, backup frequency and location, the last restore test with its date, and what happens to work in progress if your office is unavailable (remote work policy, dialer failover). Lose points: backups that have never been restored.
The questionnaire is not a form to get through. It is the filter that decides whether your bid gets read.
If your platform vendor cannot give you the answers to sections 1 through 3 in a day, that is an answer about the vendor. Resolvah's security overview at resolvah.com/security has ours.
This is how we think — and how Resolvah works. See it for yourself.
Thirty minutes, a real operator, and the actual product. No script.