Home / AI Vendor Questionnaire Template
ORIGINAL PREPARATION RESOURCEAI Vendor Security Questionnaire Template: 36 Questions to Prepare Before Enterprise Procurement
This vendor-side preparation template is designed to expose the evidence gaps that typically create back-and-forth during an AI procurement review. It is not a replacement for a buyer’s own questionnaire or any official framework.
Data use and customer content
- What customer data is processed by AI features?
- Are prompts or outputs used to train shared models?
- Can customers opt out of any model-improvement use?
- How long are prompts, outputs and related logs retained?
- Where is AI-related customer data stored and processed?
- How is customer data deleted when the service relationship ends?
Models and third-party providers
- Which foundation-model or AI service providers are used?
- Can model providers change without customer notice?
- Are customer inputs shared with any downstream model provider?
- Do you fine-tune models using customer-specific data?
- How are model versions evaluated before production use?
- What fallback behavior exists when a model/provider is unavailable?
Security controls
- How is access to AI configuration and customer prompts controlled?
- Is AI-related data encrypted in transit and at rest?
- What logging exists for AI requests and administrative changes?
- How are secrets/API keys for model providers protected?
- How are vulnerabilities in AI-enabled features identified and remediated?
- Does the incident-response process explicitly cover AI services and providers?
Privacy and subprocessors
- Which subprocessors handle AI-related customer data?
- How are privacy obligations flowed down to AI providers?
- How are data-subject requests handled when AI systems process personal data?
- What cross-border transfers can occur through AI providers?
- What data-minimization controls apply to prompts and context?
- Can customers configure retention or disable selected AI features?
AI governance and risk
- Who is accountable for AI risk and product approval?
- Do you maintain an inventory of AI systems or model dependencies?
- How do you classify AI use cases by risk?
- How are material model/provider changes reviewed?
- What testing is performed for reliability, bias or unsafe outputs?
- How are known AI limitations documented for customers and internal teams?
Human oversight and operations
- Where can a human review or override AI-generated decisions or outputs?
- What customer-facing features rely on fully automated AI decisions?
- How are harmful or unexpected outputs reported and investigated?
- How are employees trained on approved AI use?
- How are exceptions to AI policy approved and documented?
- What evidence can you provide to support the answers above?
Use this as an evidence test, not a checkbox list
For each question, record the answer owner, exact evidence source, last-reviewed date and whether the evidence fully supports the claim. That turns a static template into a reusable procurement readiness system.