AI tool questions in a vendor security questionnaire
Questionnaires now ask whether you use AI tools with client data, whether you have a generative AI policy and whether AI providers count as subprocessors. Three short questions with one policy behind them.
What the client wants to know
The client wants to know that nobody pastes their code or documents into a public chat assistant, that the tools you do use do not train on their data, and that a person reviews the output. They also treat the AI provider as one more party that touches their data.
The 3 questions as clients phrase them
The kit covers 3 questions in this area. The wording varies between questionnaires, the control behind it does not.
- Do you use AI tools (such as chat assistants or code assistants) with our data?
- Do you have a policy on the use of generative AI?
- Are AI providers included in your subprocessor list?
What a good answer contains
- Approved tools only: client data goes only into AI tools approved under your written rules, on business plans whose terms exclude training on your data.
- Policy: one page that says which tools are approved, what data may be entered, that outputs are reviewed by a person, and that client data is never used to train models.
- Subprocessors: AI tools approved for client data are listed with their purpose and data location.
Watch out for
If you have no written rules yet, say that, and say staff are told not to put client data into AI tools until the rules exist. That is true to write down today.
Controls behind these answers
These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.
- AI tools: Written rules say which AI tools are approved for client data and what may be entered. If not yet: Write one page of AI rules: approved tools on business plans that do not train on your data, what may never be entered, and human review of outputs.
Example: how a prepared answer opens
Question: Do you use AI tools (such as chat assistants or code assistants) with our data?
Only AI tools approved under our written AI rules are used with client data, on business plans whose terms exclude training on our data.
This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.
Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.