Most vendor security questionnaires measure the vendor's patience. A few produce useful information. The difference is what you ask and what you do with the answers.
Ask about this engagement
Generic questionnaires produce generic answers. The questions that matter depend on what the vendor will hold: where our data goes, who can access it, how access is logged, how it is deleted, who they subcontract to, and what happens when they are breached.
Prefer artefacts to assertions
A current audit report with its scope and exceptions, a penetration test summary, an architecture diagram, a subprocessor list, an incident response policy with real contact routes. One artefact beats fifty yes-or-no answers, and the exceptions section of an audit report is the most informative page you will receive.
Tier the effort
Not every supplier deserves the same scrutiny. Tier by data sensitivity, availability dependence and integration depth. A design tool with no customer data does not need the treatment given to a payroll processor.
Put it in the contract
A questionnaire answer is not binding; a contract clause is. The ones that earn their place: breach notification within a defined window, the right to audit or receive audit reports, subprocessor notification, data location, deletion on termination, and security requirements that survive renewal.
Reassess on change
Annual reassessment catches little. Reassess when the integration deepens, when the vendor is acquired, when they report an incident, or when the data they hold changes.