Use this questionnaire to collect written answers, evidence, and red-flag signals from every AI vendor before sharing data, connecting systems, or approving a pilot.
Section 01
Company and compliance baseline
- Do you have SOC 2 Type II?
- Can you provide the latest report under NDA?
- What systems, products, and environments are covered by the report?
- Do you have ISO 27001, HIPAA, PCI, GDPR, CCPA, or other relevant certifications?
- Do you conduct annual penetration tests?
- Can you share recent penetration test findings and remediation status?
- Do you maintain a written information security program?
- Do you have cyber insurance?
Section 02
Data usage and model training
- Will our data ever be used to train your models?
- Will prompts, outputs, documents, logs, or feedback train third-party models?
- Is customer-data training opt-in or opt-out?
- Can we disable training permanently?
- Can you contractually commit that our data will not be used for model training?
- Are prompts and outputs retained? If yes, for how long?
- Can we configure retention windows?
- Can we delete our data on request, and can you prove deletion?
Section 03
Model provider and hosting architecture
- Which model providers do you use?
- Which specific models do you use in production?
- Where does inference happen?
- Is inference hosted by OpenAI, Azure, AWS, Google Cloud, Anthropic, your own infrastructure, or another provider?
- Does customer data ever leave approved regions?
- Are any foreign-hosted services in the processing path?
- Do you use open-weight models, and where are they hosted?
- Do you fine-tune models on customer data?
- Can we choose or restrict model providers?
Open-weight models are not automatically unsafe. The question is where the model runs, who controls infrastructure, whether customer data is logged, and whether the vendor has real operational controls.
Section 04
Deployment model
- Is your product SaaS, single-tenant, private cloud, customer VPC, on-prem, or hybrid?
- What deployment models are supported?
- Does the product require VPN, database access, API access, file exports, or user credentials?
- Can the product run with read-only access first?
- Can write actions be gated by human approval?
- How do you separate customer environments?
- How do you manage secrets and credentials?
- Do you support data residency requirements?
Section 05
Access control and identity
- Do you support SSO through SAML or OIDC?
- Do you support SCIM user provisioning?
- Do you support role-based access control?
- Can permissions mirror our existing business roles?
- Can access be restricted by department, region, business unit, or data type?
- Can admins see who accessed what?
- Can we revoke users immediately?
- Do you support MFA?
Section 06
Data integration and system access
- Which systems do you need to connect to?
- Do you use APIs, database connections, files, RPA, browser automation, or screen scraping?
- Do you require write access?
- Can access be scoped to specific objects or tables?
- How do you handle rate limits, failures, and retries?
- How do you prevent the AI from taking unauthorized actions?
- Can customers approve system actions before execution?
- How are credentials stored and rotated?
Section 07
AI agent controls
- What actions can the AI agent take?
- Which actions are read-only?
- Which actions can change business records?
- Can high-risk actions require human approval?
- Can we restrict actions by role, department, or workflow?
- Can the agent explain why it made a recommendation?
- Can the agent cite the source data it used?
- Can the agent be stopped, paused, or rolled back?
Section 08
Prompt injection and AI-specific security
- How do you defend against prompt injection?
- How do you prevent users or documents from overriding system instructions?
- How do you isolate user content from system prompts?
- How do you prevent the model from leaking confidential data?
- How do you prevent insecure output handling?
- How do you test for jailbreaks and adversarial prompts?
- How do you evaluate model behavior before releases?
- Do you red-team your AI workflows?
Section 09
Auditability and observability
- Do you log prompts, outputs, tool calls, and system actions?
- Can customers access audit logs?
- Can logs be exported to a SIEM?
- Do logs show which data sources were used?
- Can we trace an output back to source records?
- Do you monitor hallucinations, failures, escalations, and overrides?
- Do you provide workflow-level analytics?
- Can we review agent actions before and after deployment?
Section 10
Industry-specific data protection
- Can you support PHI, PCI, PII, financial data, legal documents, source code, or other regulated data?
- Do you sign BAAs for healthcare data?
- Do you support PCI-sensitive workflows without storing card data?
- Can sensitive fields be masked or tokenized?
- Can access be restricted by data classification?
- Can data be excluded from prompts?
- Can customer-specific retention policies be applied?
- Can production data be separated from test data?
Section 11
Subprocessors and third parties
- Who are your subprocessors?
- Which subprocessors see customer data?
- Which subprocessors see prompts, outputs, files, logs, or metadata?
- Can we review and approve subprocessors?
- Do you notify customers before adding subprocessors?
- Are subprocessors bound to equivalent security obligations?
- Where are subprocessors located?
- Can any subprocessor use our data for training?
Section 12
Data retention and deletion
- What data do you retain?
- How long do you retain prompts, outputs, files, embeddings, logs, and metadata?
- Can retention be configured?
- Can data be deleted on request?
- Can embeddings be deleted?
- Can backups be deleted or aged out?
- What happens at contract termination?
- Can you provide deletion certification?
Section 13
Model changes and release management
- How often do you change models?
- Do customers receive notice when models change?
- Can customers pin a model version?
- Do you test workflows before changing models?
- Do you run regression tests?
- Do you measure accuracy, latency, cost, and failure rates?
- Can customers review release notes?
- Can customers opt out of major behavior changes?
Section 14
Incident response
- Do you have a written incident response plan?
- What is your breach notification timeline?
- Who is responsible for incident communication?
- Do you test incident response?
- Do you have a process for AI-specific incidents?
- How do you handle data leakage, unauthorized action, or model misbehavior?
- Can customers suspend access immediately?
- Do you provide post-incident reports?