This questionnaire helps us understand how information security is managed across your organisation. There are no right or wrong answers, if you're unsure about anything, write "Not sure".
- This is not a formal audit or legal compliance review.
- Do not include names or personal details in your answers, describe situations and roles in general terms only.
- Your responses are stored securely for up to 12 months, used solely for this assessment, and shared only with our AI provider (Anthropic) to help analyse your data, after which they are discarded. All reports are professionally reviewed by a qualified consultant before delivery.
Tick one, this helps us understand your regulatory context.
Briefly describe your main services or activities.
Tick all that apply.
Includes paper records, digital files, emails, databases, and verbal information. Tick all that apply.
For example on personal phones, home computers, in paper files, or via personal email.
Tick all that apply, include formal and informal practices.
Tick all that apply.
Most organisations that process personal data need to register. It costs £35/year for small organisations.
Usually published on your website and given to clients when you first collect their information.
This is called a Subject Access Request (SAR). Organisations usually have 30 days to respond.
This applies when a breach is likely to result in a risk to people's rights and freedoms, for example a leak of sensitive client or customer records.
An information asset register is the foundation of good information security governance. It helps identify what needs protecting and by whom.
A risk assessment is required under ISO 27001 and recommended under UK GDPR. It helps prioritise where controls are most needed.
Risk ownership means specific people are accountable for ensuring agreed actions are taken to reduce identified risks.
This is sometimes called a risk appetite or risk tolerance. It helps decision-makers understand what risks to accept, treat, or escalate.
This might include management reviews, internal audits, post-incident reviews, or regular checks that controls are still appropriate. It maps to ISO 27001 Clause 9 (Performance Evaluation) and Clause 10 (Improvement).
Tick all that apply.
Tick all that apply.
For example CEO, operations manager, trustee, data protection lead, IT provider.
For example a volunteer who manages all passwords, or a staff member who is the only admin on all systems.
For example: are OS and software updates applied when available? Are any devices running unsupported software?
For example checking who still has access to email, shared drives, CRM, finance systems.
For example one login used by several people.
Consider both access to the building (who can enter, visitor sign-in, locked areas, server or comms rooms) and access to information within it (paper records secured, screens visible to visitors, filing cabinets locked).
For example client records, HR files, trustee papers, or finance documents.
For example: strong/unique passwords, two-step verification (MFA), password manager in use.
Tick all that apply.
For example IT provider, CRM provider, payroll provider, accountant, website developer, local authority, funder.
For example free AI tools, file-sharing services, or online forms not approved by the organisation.
Consider: confidential data entered into AI tools, outputs used without verification, data retained by the tool provider.
For example sharing client or customer records with contractors, referral agencies, health or care services, local authorities, or commercial partners.
Select Yes / No / Not sure for each, and add names or details where known.
Tick all that apply.
Tick up to three.
Thank you for completing this questionnaire. Your responses are being reviewed by Social Catalyst UK and a personalised report will be emailed to you shortly.
If you have any questions in the meantime, please contact antony@socialcatalystuk.com.