Talk with an Expert
APR ’26Resources / AI2 min read

AI vendor questionnaire: the 12 questions your security team should be asking.

Michael ParkadzeMichael ParkadzeVP research & development

Before onboarding any AI vendor, these are the security and data governance questions that actually matter.

Why standard vendor questionnaires fall short

Your existing vendor security questionnaire was designed for SaaS providers that store and process structured data. AI vendors are different. They train models on your data. They may retain prompts and outputs. Their supply chain includes open-source model weights with unclear provenance.

Standard questions about encryption at rest and SOC2 certification are necessary but insufficient.

The 12 questions

Data handling

  1. Is our data used to train or fine-tune models? If yes, can we opt out? What is the data retention period for training data?
  2. Where is our data processed geographically? This matters for GDPR, NIS2, and sector-specific regulations.
  3. Can we delete our data from your systems, including any derived representations? Embeddings and model weights that encode our data count.

Model governance

  1. What is the provenance of your base model? Open-source, proprietary, or fine-tuned from another provider's model?
  2. How do you handle model updates? Will a model update change outputs for the same inputs? How are we notified?
  3. Do you perform red-teaming or adversarial testing on your models? How often, and can we see the results?

Security

  1. How is prompt injection mitigated? What guardrails prevent our data from being exfiltrated through crafted prompts?
  2. Is there tenant isolation for model inference? Shared infrastructure introduces side-channel risks.
  3. How are API keys and credentials managed? Do you support short-lived tokens and IP restrictions?

Compliance

  1. Can you provide a Data Protection Impact Assessment for your service? Not a generic one: specific to how we would use it.
  2. How do you handle regulatory requests for data disclosure? In which jurisdictions, and will we be notified?
  3. What is your incident notification timeline? NIS2 and DORA require 24-hour notification. Can you meet this?

How to use this

Add these to your existing vendor assessment process. Weight the answers based on what data you plan to share with the vendor. A marketing copy generator with anonymized inputs is different from a customer support AI that processes PII.

No vendor will score perfectly. The goal is informed risk acceptance, not perfection.

Talk with an Expert.

Tell us about your organization and the challenge you are facing. Our consultants will shape the right cybersecurity approach.