Home / AI Vendor Questionnaire Template
ORIGINAL PREPARATION RESOURCE

AI Vendor Security Questionnaire Template: 36 Questions to Prepare Before Enterprise Procurement

This vendor-side preparation template is designed to expose the evidence gaps that typically create back-and-forth during an AI procurement review. It is not a replacement for a buyer’s own questionnaire or any official framework.

Original ProcureDeal resource · Updated 15 September 2026

Data use and customer content

  1. What customer data is processed by AI features?
  2. Are prompts or outputs used to train shared models?
  3. Can customers opt out of any model-improvement use?
  4. How long are prompts, outputs and related logs retained?
  5. Where is AI-related customer data stored and processed?
  6. How is customer data deleted when the service relationship ends?

Models and third-party providers

  1. Which foundation-model or AI service providers are used?
  2. Can model providers change without customer notice?
  3. Are customer inputs shared with any downstream model provider?
  4. Do you fine-tune models using customer-specific data?
  5. How are model versions evaluated before production use?
  6. What fallback behavior exists when a model/provider is unavailable?

Security controls

  1. How is access to AI configuration and customer prompts controlled?
  2. Is AI-related data encrypted in transit and at rest?
  3. What logging exists for AI requests and administrative changes?
  4. How are secrets/API keys for model providers protected?
  5. How are vulnerabilities in AI-enabled features identified and remediated?
  6. Does the incident-response process explicitly cover AI services and providers?

Privacy and subprocessors

  1. Which subprocessors handle AI-related customer data?
  2. How are privacy obligations flowed down to AI providers?
  3. How are data-subject requests handled when AI systems process personal data?
  4. What cross-border transfers can occur through AI providers?
  5. What data-minimization controls apply to prompts and context?
  6. Can customers configure retention or disable selected AI features?

AI governance and risk

  1. Who is accountable for AI risk and product approval?
  2. Do you maintain an inventory of AI systems or model dependencies?
  3. How do you classify AI use cases by risk?
  4. How are material model/provider changes reviewed?
  5. What testing is performed for reliability, bias or unsafe outputs?
  6. How are known AI limitations documented for customers and internal teams?

Human oversight and operations

  1. Where can a human review or override AI-generated decisions or outputs?
  2. What customer-facing features rely on fully automated AI decisions?
  3. How are harmful or unexpected outputs reported and investigated?
  4. How are employees trained on approved AI use?
  5. How are exceptions to AI policy approved and documented?
  6. What evidence can you provide to support the answers above?

Use this as an evidence test, not a checkbox list

For each question, record the answer owner, exact evidence source, last-reviewed date and whether the evidence fully supports the claim. That turns a static template into a reusable procurement readiness system.

Next steps