Back to Blog

    The AI Vendor Security Questions Worth Asking

    Most security questionnaires are long and answer nothing. Twelve questions get you further, if you read the replies properly.

    Erin Moore

    Erin Moore

    Fractional Chief AI Officer

    |October 8, 20263 min read
    The AI Vendor Security Questions Worth Asking
    Share:
    Share:

    A useful AI vendor security questionnaire is about twelve questions long and asks what happens to your data rather than which certifications the vendor holds. Long questionnaires get delegated to a sales engineer who pattern-matches to previous answers; short specific ones get escalated to someone who actually knows.

    The twelve

    Data handling

    1. Where is our data processed and stored, by country?
    2. Is our data used to train or fine-tune any model, by default or optionally?
    3. How long is it retained after we delete it, and after we terminate?
    4. Which subprocessors touch it, and how are we notified of changes?

    Access 5. Who at your company can access our data, and under what circumstances? 6. Is access logged, and can we see those logs?

    The model 7. Which underlying models do you use, and will you notify us before changing them? 8. Is anything about our usage shared with the model provider?

    Failure and incident 9. What is your incident notification commitment, in hours? 10. What happens to our workloads if you lose access to your model provider?

    Exit 11. In what format do we get our data back, and how quickly? 12. What happens to anything derived from our data — embeddings, indexes, fine-tunes?

    Reading the answers

    Specific beats certified. SOC 2 tells you a process exists, not what happens to your data. A vendor who answers question 2 precisely is more useful than one who attaches a compliance PDF.

    Watch for the passive voice. "Data may be retained for operational purposes" is an answer designed not to answer. Ask again.

    Question 12 is the discriminator. Most vendors have a clean answer for returning your raw data and no answer at all for derived artefacts. That gap is where lock-in lives — the theme in AI contract negotiation.

    Sales answering security questions is itself a signal. These should come from someone technical, in writing.

    Anchoring the questionnaire

    You do not need to invent the standard. NIST's AI Risk Management Framework and CISA's AI resources give you public references to point at, which makes the request routine rather than adversarial — useful when a vendor implies you are being unusually demanding.

    Whatever comes back, the answers belong in your AI risk register rather than in an inbox, because the person who asked will not be the person who needs them.

    Frequently asked questions

    What should an AI vendor security questionnaire cover? Data location and residency, training use, retention, subprocessors, internal access and logging, model choice and change notice, incident notification, and what you get back on exit including derived artefacts.

    Is SOC 2 enough? No. It tells you a process exists; it does not tell you whether your data trains their models or what happens to embeddings when you leave.

    What is the most revealing question? What happens to artefacts derived from your data. Most vendors can return raw data and have no clear answer for indexes, embeddings or fine-tunes.

    How long should the questionnaire be? Short enough to be answered by someone technical rather than pattern-matched by sales. Around a dozen specific questions works better than a hundred generic ones.

    Further reading

    Erin Moore

    Written by

    Erin Moore

    Fractional Chief AI Officer

    Army Veteran turned Fractional Chief AI Officer. Founder of AutomateNexus. I help growing businesses implement enterprise-grade AI solutions that deliver ROI in 90 days or less. Author of "The AI Automation Field Manual."

    Ready to Automate Your Business?

    Let's discuss how AI automation can deliver measurable ROI for your organization in 90 days or sooner.