Security sends the same 200-question SIG to every SaaS vendor. The AI startup answers "yes" to encryption while their consumer tier trains on uploads. Generic questionnaires miss prompt retention, tool execution sandboxes, and model supply chain risk. An AI vendor security questionnaire tailored to inference workloads closes gaps before procurement approves spend.
Use this buyer guide when assessing AI writing platforms and AI marketing suites that process customer content at scale.
AI-Specific Domains: Model, Data, Prompts, and Outputs
Organize questions into domains standard SIGs under-specify:
Model
- Which model families and versions power the SKU we buy?
- Who hosts weights (vendor, hyperscaler, customer VPC)?
- How are model updates rolled out? Can we pin versions?
- Is customer data used for training by default? Opt-out mechanism?
Data
- What is logged: prompts, outputs, tool traces, embeddings?
- Retention periods per log type and deletion API availability
- Tenant isolation model for multi-tenant SaaS
- Geographic residency options and failover regions
Prompts and outputs
- DLP or PII detection on ingress and egress?
- Human reviewer access to prompts: who, when, audit trail?
- Output filtering for malware, secrets, policy violations
- Customer-managed encryption keys (CMEK) support?
Marketing tools in AI marketing categories often integrate with ESPs; extend questions to OAuth scopes and token storage for those connectors.
Evidence: Pen Tests, SOC Reports, and Architecture Diagrams
Request evidence mapped to answers, not checkbox trust alone:
- SOC 2 Type II (or ISO 27001) with scope covering AI inference services
- Penetration test executive summary less than 12 months old
- Architecture diagram: data flow from client to model to logs
- Subprocessor list with security certifications
- Incident response summary and breach history (redacted)
- Bug bounty or vulnerability disclosure program link
| Evidence type | What to verify |
|---|---|
| SOC 2 | Trust Services Criteria in scope; exceptions noted |
| Architecture | Matches answers on logging and training |
| Pen test | Critical findings remediated or accepted with plan |
Scoring and Risk Acceptance
Score vendors by domain weight aligned to your data classification. Critical gaps (training on customer data without opt-out, no tenant isolation, no deletion API) may be disqualifying. Medium gaps (no CMEK, 90-day log retention) may proceed with compensating controls and time-bound remediation in contract.
Document risk acceptance sign-off from CISO or delegate for exceptions. Link acceptance to writing tool use cases restricted to public marketing copy only, for example.
Re-Assessment Triggers
- Annual renewal or major contract expansion
- New enterprise SKU or self-hosted option
- Public security incident affecting the vendor or key subprocessor
- Material architecture change (new model provider, new region)
- Your data classification upgrade (internal to regulated personal data)
Running Effective Vendor Review Meetings
Schedule a sixty-minute technical session after written questionnaire responses arrive. Security asks follow-ups on logging defaults, agent tool scopes, and data residency maps. Engineering validates architecture diagrams against actual integration plans. Legal confirms DPA terms match questionnaire claims about training opt-out and deletion SLAs.
Red flags in responses include vague answers on prompt retention ("we may log for quality"), unwillingness to share SOC scope pages, and no named owner for security inquiries. Yellow flags include SOC 2 in progress without interim pen test, or training opt-out only on unpublished enterprise tier.
Document scoring in a shared register: vendor, product, data class, score, compensating controls, approver, review date, next review date. Auditors prefer registers over scattered email threads. Link each row to stored evidence files with retention matching contract life.
For AI writing and marketing tools, ask specifically whether uploaded brand assets or customer lists enter shared training pools on default plans. Marketing teams paste campaign briefs with unreleased product names; logging and training defaults matter as much as encryption.
Re-assessment triggers should be explicit in the register: new agent feature, acquisition, breach notification from vendor, material SOC exception, or your own data classification upgrade. Light delta questionnaires save time when only one domain changed since last year.
Scoring Rubric Template
Weight domains 0–5: identity (SSO, SCIM), data isolation, logging and retention, training policy, appsec (SDLC, pen test), incident response, compliance certs. Require minimum 4 on data isolation for regulated workloads. Document compensating controls for scores of 2–3.
Two vendors with identical scores may differ on writing workflow fit; security score is gate one, not the only gate.
Follow-up questions when answers are vague
"We encrypt data" → At rest, in transit, who holds keys? "We do not train on your data" → Including abuse monitoring, RLHF, evaluation? "SOC 2" → Type I or II, date, exceptions? Push until answers are operational, not marketing.
Marketing tool connector review
Marketing AI with ESP and ad platform OAuth needs questions on token storage, refresh, scope minimization, and revoke on offboarding.
Evidence Repository and Audit Trail
Store questionnaire responses, SOC reports, pen test letters, and architecture PDFs in a GRC tool with access controls. Name files consistently: Vendor_Product_SOC2_2026.pdf. Set expiry reminders ninety days before SOC report ages out. Stale evidence is worse than missing evidence because it creates false confidence.
When vendors refuse to share full SOC under NDA, record who approved continued use, which data classes are allowed, and compensating controls such as IP allowlisting or prompt minimization. Risk acceptance should expire annually unless renewed with fresh evidence.
AI-specific pen test scope should include prompt injection attempts against your configured integration, not only vendor generic SaaS test. Your implementation may expose tools and retrieval paths the vendor default test never touched. Budget internal red team time for high-impact deployments.
Startups without SOC 2 should provide CAIQ or SIG Lite responses, vulnerability scan summaries, and incident history questions honestly. Ask for funded roadmap milestone dates for Type II audit. Short contract term plus exit clause may be appropriate until evidence matures.
Scoring Rubrics and Tiering
Tier vendors by data sensitivity: Tier 1 public marketing copy, Tier 2 internal business data, Tier 3 customer PII, Tier 4 regulated special categories. Tier 3 and 4 require full AI domain questionnaire and executive risk sign-off. Tier 1 may use abbreviated review but still needs training and logging answers documented.
Numeric rubrics reduce argument in committee: 0 missing, 1 partial, 2 adequate, 3 exemplary per control. Weight prompt logging and training opt-out higher for Tier 4. Publish rubric to vendors so they know what "adequate" looks like and do not over-promise controls they cannot configure on your plan tier.
AI Due Diligence Closing Checklist
Before production sign-off, confirm: DPA executed with AI addendum, training opt-out configured and screenshot archived, SSO and SCIM tested, admin audit logging enabled, subprocessor list matches questionnaire, pen test summary less than twelve months old or risk accepted, incident contact verified, and data flow diagram stored in evidence repository. Missing any item should block Tier 3 and 4 data classes.
Re-assessment calendar entry created with owner and triggers documented. Link questionnaire score to procurement renewal so security review is not skipped on auto-renew. AI capabilities change mid-contract; treat renewal as mini re-assessment even when price unchanged.
Security questionnaires for AI vendors are living documents. When the vendor ships agent marketplaces, computer use, or new regional endpoints, append delta questions rather than waiting for annual renewal. Procurement should attach the latest completed questionnaire to every order form amendment so sales cannot bypass review with "same tool, new module" assumptions.
Frequently Asked Questions
Startups without SOC 2 yet?
Request detailed security whitepaper, pen test, reference customers, and roadmap for certification. Limit data classes and contract term until SOC report is available. Consider escrow or termination rights.
Vendors complain about questionnaire length?
Send a 40-question AI addendum instead of full SIG for pilots. Expand at enterprise deal stage.
Shared responsibility for API use?
Clarify customer obligations: secure API keys, prompt injection defenses, output review. Vendor secures platform; you secure integration.
Should we require red-team results?
Valuable for critical vendors; expensive for small tools. Ask if vendor has third-party LLM red-team or prompt injection assessments.
How to compare two passing vendors?
Weight domains by your threat model: residency, no-train, audit logs, SSO, SCIM, data residency, support SLAs.
The Bottom Line
Completing AI vendor security questionnaires well means covering model, data, prompts, and outputs, demanding mapped evidence, scoring honestly, and re-assessing on change. Procurement teams buying writing and marketing AI should attach the AI addendum to every security review so generic SaaS answers cannot hide training and logging risks.
Questionnaire Workflow and SLAs
Define SLAs: vendor receives questionnaire within 48 hours of shortlist, answers due in 10 business days, follow-up call for gaps in 5 days. Parallel legal review of DPA while security reviews technical answers. Do not let procurement sign before both complete.
Maintain a library of your standard AI addendum questions in Excel or GRC tool. Version it when your threat model changes (e.g., you adopt agents with tool execution). Send same version to all vendors in a category for apples-to-apples comparison.
Alternatives when evidence is thin
For early-stage vendors, accept detailed security whitepaper plus customer references plus commitment to SOC 2 within 12 months. Cap data classification and contract value until report arrives. Never process special category data on startup honor system alone.