Most companies that fail a supplier questionnaire are not badly secured. They are unable to demonstrate what they do. Backups exist but no procedure is written. Access is reviewed, but from memory, with no record. Encryption is in place, but nobody can say on exactly which data.
The questionnaire does not measure your security: it measures your ability to document it. A cautious client treats absent evidence as an absent control, and is right to do so.
The second difficulty is repetition. Every client has its own form, with the same questions worded differently. Without a library, everything is rewritten each time, and the answers drift from one client to the next. That drift is exactly what an auditor picks up.