Skip to main content
← Learning Center
Assessment Generator

AI Vendor Security Questionnaire

Select your compliance frameworks, AI tool type, and data sensitivity to generate a tailored 40+ question security assessment for evaluating any AI vendor. Export, share with your procurement team, or use as your due diligence baseline.

How It Works

In three quick steps, build a tailored security questionnaire for any AI vendor. The questions are mapped to major compliance frameworks and adapt based on your tool type and data sensitivity. Export as a text file or copy into your procurement system.

1
Select Frameworks
Choose which compliance standards apply, SOC 2, HIPAA, GDPR, and more.
2
Choose Tool Type
Pick the kind of AI tool you're evaluating, API, coding assistant, agent platform.
3
Set Data Sensitivity
Flag the data types your team might expose, PII, PHI, source code, financial.

The questionnaire finds the gaps. Shield closes them.

Once you've identified what your AI vendors should be doing, make sure your own team isn't the weak link. Shield redacts secrets, PII, and proprietary data from every prompt before it leaves your machine.

See Shield Pricing Book a Demo

Frequently Asked Questions

AI tools handle data differently than traditional SaaS. Prompts can contain PII, proprietary code, and business secrets. Standard vendor questionnaires don't cover model training data usage, prompt logging, token-level data exposure, or the unique supply chain risks of third-party model providers. This questionnaire fills those gaps with AI-specific questions that a standard SIG or VSA won't ask.
A standard vendor risk assessment covers infrastructure security, access controls, and compliance, but it doesn't ask the AI-specific questions: Are my prompts used for training? Does the model provider see raw data? Can I opt out of logging? Are completions stored? This questionnaire adds 40+ AI-specific questions across 8 security domains on top of the baseline assessment every vendor should answer.
Vendor transparency varies, especially with smaller AI startups. Treat refusal as a risk signal, not a dealbreaker. Prioritize the questions that map to your compliance requirements. If a vendor won't answer questions about data retention or sub-processors, that's a red flag. If they decline to share penetration test results, ask for a security white paper or SOC 2 report instead. Document every unanswered question in your risk register.
Annually at minimum, more frequently for vendors handling sensitive data or operating in regulated industries. AI tools evolve rapidly: new model versions, changed data policies, and added features can alter the risk profile within months. Set a calendar reminder. For critical vendors, request notification of material changes to data handling practices and re-assess within 30 days of any major update.
Partially. Open-source models you run yourself eliminate the third-party data sharing risk, but introduce supply chain risks (malicious model weights, tampered dependencies) and operational risks (do you have the expertise to secure the deployment?). Use the infrastructure-focused questions (encryption, access controls, incident response) for self-hosted models and skip the data-handling questions that apply to vendor-hosted services.
Yes. The generated questionnaire is a starting framework, add questions specific to your industry, remove questions irrelevant to your use case, and adjust the language for your procurement process. The questions here map to SOC 2, HIPAA, GDPR, ISO 27001, PCI DSS, CCPA, and FedRAMP. If you're covered by additional frameworks like FERPA or NIST 800-171, append those controls as supplementary questions.