Questionnaires
Regulators and customers send spreadsheets. Hundreds of rows, each one a requirement you have to say something about, and the answers are already written down across your specification, your architecture and your threat model.
A questionnaire in Taiga is that spreadsheet, brought in as a list of questions your project’s own documents can answer.
Bring your own form
Section titled “Bring your own form”Open a project, go to Assurance → Questionnaires, and choose Import a questionnaire. Pick the file you were sent. That is the whole thing — there is nothing else to press.
The questionnaire appears in the list the moment the upload finishes, and from there the work is Taiga’s, not your browser’s. You can refresh, close the tab or come back later; it is still there.
Taiga reads the sheets and works out which columns hold the requirement, the question, the answer and the space for your justification — in whatever language the form is written. If the form defines its answers — X, M, U, Yes / No — it reads that legend too, and will only ever answer with those values. Then it imports the requirements and starts answering them, and you land on the register while the run is going.
You are only stopped when it is genuinely unsure. A sheet it could not read confidently, or two roles pointing at one column, leaves the questionnaire waiting in the list with a Check the columns button. Anyone with import rights on the project can open it, correct the columns and import — because the answer column is the one your answers get written back into, and getting it wrong is the mistake nobody would notice. Whichever way the columns were settled, they stay with the questionnaire, so the file you get back at the end goes into the same columns it came from.
Nothing about the regulation is modelled, and there is no list of forms Taiga supports. Every workbook is read the same way, whichever authority or customer sent it — Finland’s ASTORI järjestelmälomake, a cloud-security questionnaire, a spreadsheet somebody assembled last week.
Answer from what you have published
Section titled “Answer from what you have published”Answering runs across every requirement, reading your project’s published documents — specification, architecture, data flow, privacy assessment, threat model, risk register.
Each answer carries the document and the version it rests on, and the exact sentence it was read from. An answer with no support is not invented: it comes back as no evidence found, not something documents can show, or needs your judgement, with a reason.
That is deliberate, and it is the point. An answer nobody can trace is worse than a blank one: a filled cell in a regulatory declaration is a statement you are making to an authority. Taiga would rather hand you thirty-six questions than one confident guess.
Answering a few hundred requirements is dozens of model calls and takes minutes, so the page counts what it has reviewed as it goes — including everything it decided it could not answer, which on most forms is the bulk of it — and tells you plainly if it fails. You can leave the page; the run carries on without you. You can also stop it, and the answers already written are kept.
Nothing can be downloaded while a run is still going, because a register still being written is not the one you read. Taiga refuses outright rather than only hiding the button, so a colleague starting a run cannot leave you with half a form.
Requirements are listed in the order your own workbook lists them, grouped under their sheet. What Taiga answered is on the page; the requirements your documents said nothing about fold away under their sheet, counted, one click from open.
Take your own file back
Section titled “Take your own file back”Press Download the filled form and Taiga writes the answers into your workbook — the file you uploaded, with its own sheets, its own formatting, and its own layout intact. Not a rendering of it.
Each answer carries its sources with it — the document and version it rests on, written into the same cell as the justification. That is the point of a draft you check rather than trust: you can see where an answer came from without opening Taiga.
Every other part of the file is byte-for-byte what you sent. That matters when the file is what you submit: a spreadsheet that merely looks similar is a different document.
The file is written fresh each time you ask for it, so it always matches the answers you can see on screen. You cannot download one while a run is still going — a half-filled form has blanks in it that nobody can tell apart from the requirements Taiga decided it could not answer.
It is a draft, and it is yours
Section titled “It is a draft, and it is yours”Taiga does not ask you to sign anything, and it does not sign anything on your behalf.
What comes back is a first draft: the answers your own documents support, each one naming the document and version it came from, and the requirements Taiga would not answer left for you. You check it, you change what you want, and you file it. The declaration you submit is yours.
That is also why every answer carries its source. The point is not that Taiga is confident — it is that you can check any answer in seconds instead of working it out again from scratch.
Delete it when you are done
Section titled “Delete it when you are done”A questionnaire is one-time work. You fill it, you take the file, and after that Taiga is holding a copy of a regulatory workbook for no reason.
Every questionnaire in the list can be deleted. It takes the requirements, the answers, the file you uploaded and any draft generated from it — permanently, with nothing left to restore. The file you already downloaded is on your own machine and is not touched.
The confirmation tells you what is going: how many requirements, and how many of them were answered. Several imports of the same form share a name, so the count is what tells you which one you are holding.
The list itself shows enough to tell them apart: how far each one has got, when it arrived, and whether anyone has downloaded it yet.
Correct an answer before you take the file
Section titled “Correct an answer before you take the file”Taiga answers what your documents support, you download your own workbook, and you finish the rest where you always have — in Excel, with the form in front of you. Hundreds of rows of retyping do not belong here.
A register is hundreds of rows, so each one shows only its answer and the first line of the reasoning. Open a row to see the rest: the full justification, the sources it rests on, and what the evidence does not settle.
The thing worth doing here is correcting an answer you disagree with, because that changes the file before you get it. Open the row, read the sources, and if Taiga got it wrong, fix the value or the wording. The file then says the answer is yours.
Inside the same row, under the sources, Taiga also states what the evidence does not settle: what the quoted evidence does not establish, such as a scope the document does not name or a condition it describes without confirming. Read that line before you rely on the answer. It stays in Taiga; the downloaded file carries the answer and its sources, not the argument.
The handful only you can settle
Section titled “The handful only you can settle”Some requirements come back marked Needs your judgement. Taiga found the evidence and stopped: the question is one of governance, not of fact, and nobody but you can answer it. Open the row, read what Taiga found, and answer it there. The file records the answer as yours.
A requirement the documents say nothing about can be answered here too, though its reason is usually the more useful thing: it tells you what to write when you reach that row in your own workbook.
A re-run never overwrites an answer you edited.
You will get an email when the answering finishes — it takes a while, and there is no reason to keep the page open.
Did you find what you needed?
