Vendor security questionnaires, SIG Lite, CAIQ, custom RFP spreadsheets: Most include a section on open-source, third-party software, or license compliance. Wording varies. The reviewer wants to know you control third-party license obligations in the product they are evaluating.
These questions arrive mid-deal, often answered by someone who did not write the code. Engineering may never have centralized inventory. Legal may not have seen the dependency list. This guide maps typical question types to honest answers when your codebase changes every sprint.
This page maps the questionnaire's question types. The reply workflow, step by step, is the guides page "Procurement license request".