Security template

AI vendor security questionnaire

Ask questions that can be answered with bounded explanations and supporting evidence, then review those answers in the context of the proposed use.

What this security questionnaire is for

This AI vendor security questionnaire helps reviewers request bounded explanations and supporting evidence about architecture, access, data protection, secure development, incidents, resilience, dependencies, and AI-specific controls. Answers must be interpreted in the context of the proposed use.

Intended roles:
Security reviewers and the business, privacy, legal, procurement, compliance, risk, or AI-governance roles that depend on security findings.
Use it when:
Scoping a security review, requesting vendor responses, mapping responses to evidence, or following up on unclear or incomplete controls.
Inputs:
Defined use case, relevant architecture and data flows, integrations, vendor responses, evidence scope and date where available, internal requirements, and known gaps.
Outputs:
Evidence-linked responses, reviewer findings, unanswered questions, control dependencies, follow-up owners, and decision-relevant limitations.
Boundary:
A questionnaire response, policy, report, test result, or certification has a defined scope and date. None should be treated as blanket assurance or automatic approval.

About this resource

AI Vendor Decision publishes static informational resources for structuring an internal vendor review. The site does not receive documents, assess vendors, provide professional advice, or make approval decisions. Check each resource against your current use case, evidence, policies, contracts, and applicable requirements.

Architecture and boundaries

  1. Describe the service architecture and trust boundaries relevant to customer data.
  2. Identify material hosting, model, integration, and subprocessor dependencies.
  3. Explain how customer environments and data are logically separated.

Identity and access

  1. Describe administrative access controls, authentication, authorization, and review.
  2. Explain how privileged actions are logged and monitored.
  3. Describe employee access approval and removal practices.

Data protection

  1. Describe encryption for data in transit and at rest.
  2. Explain retention, deletion, backup, and restoration behavior.
  3. State whether customer data is used to train or improve models and what controls apply.

Secure development

  1. Describe code review, testing, dependency management, and vulnerability handling.
  2. Explain how production changes are approved and monitored.
  3. Describe relevant security testing and the scope and date of available evidence.

Incidents and resilience

  1. Describe detection, response, customer notification, and lessons-learned practices.
  2. Explain service continuity assumptions and recovery objectives relevant to the use case.
  3. Identify customer controls or integrations needed for safe operation.

AI-specific controls

  1. Describe controls for prompt injection, unsafe tool use, data leakage, and harmful output.
  2. Explain evaluation methods and known limits for the intended use.
  3. Describe model or system changes that are communicated to customers.

Evidence note

Request evidence proportionate to the use case. A policy, report, test result, or certification has a defined scope and date; it should not be interpreted as a blanket security assurance.

Frequently asked questions

What is an AI vendor security questionnaire?

It is a set of use-case-aware questions for documenting a vendor’s architecture, access controls, data protection, development practices, incident handling, resilience, dependencies, and AI-specific controls.

Should every security question be answered with yes or no?

No. Ask for bounded explanations and relevant evidence. Record the response, source, scope, date when available, reviewer finding, limitations, and any open follow-up.

Does a certification answer every AI vendor security question?

No. A certification or report has a defined scope and date. Reviewers still need to determine what it covers, what it does not cover, and how it relates to the proposed use.