AI vendor questionnaire
AI vendor questionnaire
Questions to ask AI vendors about prompts, files, outputs, training use, retention, deletion, subprocessors, and enterprise controls.
For teams ready to implement rather than only compare options, the related template is AI Vendor Review Questionnaire and the public sample is available in the sample library.
Buyer
IT, security, procurement, privacy, operations, and AI governance teams
Problem
Generic vendor questionnaires often miss AI-specific data use, model training, output handling, and embedded third-party model dependencies.
What to look for
- Questions for prompts, files, outputs, embeddings, metadata, logs, and feedback.
- Evidence requests covering retention, deletion, training opt-out, subprocessors, audit logs, SSO, and role controls.
- Approval bands that define when a tool can be approved, piloted, deferred, or blocked.
Red flags
- The vendor cannot explain whether customer data is used for training.
- No retention or deletion commitment exists for uploaded content.
- The review ignores third-party model providers and subprocessors.
Compare related options
Generic security questionnaire
Use when: The review needs baseline security, access, hosting, encryption, and business-continuity evidence.
Next step: Use it as a baseline, then add AI-specific data and model questions.
AI vendor questionnaire
Use when: The vendor processes prompts, files, outputs, embeddings, metadata, or feedback.
Next step: Collect AI-specific evidence before approval, pilot, restriction, or block decision.
AI tool approval form
Use when: The internal team needs to request and record business use of the vendor tool.
Next step: Connect vendor evidence to owner, data category, restrictions, decision, and review date.
Implementation steps
- Define the proposed AI use case, users, data categories, and output use before sending questions.
- Ask how prompts, uploaded files, outputs, metadata, embeddings, logs, and feedback are processed.
- Request evidence for model-training use, opt-out settings, retention, deletion, subprocessors, audit logs, SSO, role controls, and enterprise terms.
- Compare the vendor evidence against the proposed workflow and decide approved, approved with restrictions, pilot only, defer, or block.
- Record the decision, restrictions, evidence link, owner, and review date in the AI tools register.
Template preview
What the paid product adds
Generic security review versus AI-specific review
A normal security questionnaire may cover encryption, access controls, and hosting, but AI tools add questions about prompts, uploaded files, generated outputs, embeddings, metadata, logs, feedback, model-training use, retrieval systems, and downstream model providers. The AI-specific review should not replace security review; it should add the missing evidence.
Enterprise AI procurement checklist
For enterprise AI procurement, the questionnaire should connect vendor evidence to the proposed business workflow. A vendor can have strong general security material and still be unsuitable for a specific use case if prompts, files, outputs, embeddings, or feedback are retained, reviewed, used for training, or passed to subprocessors in ways the company cannot accept.
- Confirm whether prompts, uploaded files, outputs, feedback, logs, metadata, and embeddings are used for model training or product improvement.
- Check retention, deletion, export, tenant isolation, audit logs, SSO, role controls, and admin visibility.
- Map subprocessors and downstream model providers to the data categories used in the workflow.
- Record whether the approval is broad, restricted to non-sensitive data, pilot only, deferred, or blocked.
Data handling questions to ask
The questionnaire should ask what data the vendor receives, whether that data is retained, how long it is retained, whether it can be deleted, whether it is used for training or product improvement, whether humans can review it, and whether enterprise settings change those defaults.
- Prompts and chat history
- Uploaded files and extracted text
- Generated outputs and feedback
- Metadata, logs, embeddings, and retrieval indexes
- Connected app or integration data
Subprocessors and model providers
Many AI vendors rely on third-party model providers, infrastructure providers, annotation vendors, or analytics services. The review should identify subprocessors, what data each receives, where contract terms apply, and whether the vendor can notify customers when those dependencies change.
Approval decisions
The answer is not always yes or no. Use approved for low-risk use with sufficient evidence, approved with restrictions for limited data categories or user groups, pilot only for time-boxed testing, defer when evidence is missing, and block when the workflow or vendor evidence is incompatible with the company risk profile.
FAQ
Why not use a normal security questionnaire?
AI tools introduce specific risks around prompts, uploaded files, outputs, feedback, model training, and downstream model providers.
Should every AI vendor be blocked until review is complete?
Low-risk pilots can sometimes proceed with limits, but sensitive data or high-impact workflows need stronger evidence first.
Related next steps
AI tool approval form
A guide to collecting owner, use-case, data, vendor, and review information before approving a new AI tool at work.
Read the related guideAI risk register template
How to create an AI risk register that shows use cases, owners, data categories, decision impact, controls, and residual risk.
Read the related guideISO 42001 checklist for small teams
How small teams can evaluate AI management-system gaps before deeper ISO 42001 certification or assurance work.
Read the related guideAI Governance Readiness Pack
Risk, readiness, vendor review, and management-system checklists for teams moving beyond first policy rollout.
Review the packAgency AI Ops Pack
Client-service AI policy, disclosure, review, and approval material for agencies using AI in client work.
Review the pack