Security Answer Kit

All guides

AI tool questions in a vendor security questionnaire

Questionnaires now ask whether you use AI tools with client data, whether you have a generative AI policy and whether AI providers count as subprocessors. Three short questions with one policy behind them.

What the client wants to know

The client wants to know that nobody pastes their code or documents into a public chat assistant, that the tools you do use do not train on their data, and that a person reviews the output. They also treat the AI provider as one more party that touches their data.

The 3 questions as clients phrase them

The kit covers 3 questions in this area. The wording varies between questionnaires, the control behind it does not.

  1. Do you use AI tools (such as chat assistants or code assistants) with our data?
  2. Do you have a policy on the use of generative AI?
  3. Are AI providers included in your subprocessor list?

What a good answer contains

Watch out for

If you have no written rules yet, say that, and say staff are told not to put client data into AI tools until the rules exist. That is true to write down today.

Controls behind these answers

These are the controls the free Security Overview builder asks about for this area. Each line is the statement you can make once the control is in place, followed by the fix step if it is not.

Example: how a prepared answer opens

Question: Do you use AI tools (such as chat assistants or code assistants) with our data?

Only AI tools approved under our written AI rules are used with client data, on business plans whose terms exclude training on our data.

This is the first sentence only. In the kit the full answer is built from your profile, with an honest variant for each control you do not have yet.

Back to all guides

Related: Data protection Vendors and subprocessors

Guidance and templates, not legal advice. The kit does not certify you. Your answers must match what you actually do.