Home / AI Questionnaire Readiness Checklist
ORIGINAL READINESS RESOURCE

AI Questionnaire Readiness Checklist

Before an enterprise buyer sends a 100-row spreadsheet, make sure the underlying evidence exists. Score one point for each item you can prove with a current document, system record or approved owner response.

Evidence readiness: 24-point check

1
AI ownership

Named owner for AI governance or product risk.

2
AI policy

Current internal policy covering approved AI use.

3
System inventory

List of AI features, models and third-party providers.

4
Risk classification

Documented process for assessing AI use-case risk.

5
Change review

Process for reviewing material model/provider changes.

6
Customer data map

Clear explanation of what customer data AI features process.

7
Training position

Documented statement on whether customer data trains shared models.

8
Prompt retention

Known retention period for prompts, outputs and AI logs.

9
Deletion

Documented deletion behavior for AI-related customer data.

10
Data residency

Known processing/storage regions for relevant AI data.

11
Subprocessors

Current list of AI and data subprocessors.

12
DPA/privacy

Contractual/privacy language aligned with actual AI processing.

13
Access control

Documented access model for prompts, logs and AI configuration.

14
Encryption

Current evidence for encryption in transit and at rest.

15
Secrets

Process for protecting model-provider credentials and API keys.

16
Logging

Audit/operational logging for material AI activity.

17
Incident response

AI/provider incidents covered by response procedures.

18
Secure development

AI-enabled features included in development/security review.

19
Model evaluation

Documented quality/safety evaluation before material release.

20
Monitoring

Defined monitoring for reliability or unsafe behavior where relevant.

21
Human oversight

Clear points where humans review, override or escalate.

22
Limitations

Known AI limitations and prohibited uses documented.

23
Answer owners

Named owners for security, privacy, legal and product questions.

24
Approved answer library

Current prior answers that can be verified and reused.

How to interpret your score

0–8

High questionnaire risk

Expect significant manual research and escalation. Focus first on data use, provider inventory, privacy and core security evidence.

9–17

Partially prepared

You can answer many questions, but gaps are likely to create back-and-forth. Convert the missing items into explicit documentation tasks.

18–24

Strong evidence base

Your team should be able to shift from writing answers to reviewing evidence-backed drafts—assuming the documents are current and accurate.

This scoring model is a ProcureDeal planning framework, not a certification or compliance assessment.