checklist

AI security questionnaire response checklist for small teams

A practical checklist for answering customer AI security questionnaires without over-sharing private evidence, raw logs, transcripts, source code, or sensitive customer data.

Audience: Founders, operators, IT owners, workspace admins, security leads, sales owners, and customer success teams answering AI security questionnaires Risk: Medium Evidence: NIST AI RMF, NIST Cybersecurity Framework 2.0, NIST Privacy Framework, NIST SP 800-53 Rev. 5, and Cybergiz AI tool operations templates

Use this checklist when a customer, procurement team, security reviewer, investor, insurer, or enterprise buyer asks how your small team uses AI tools.

AI security questionnaires often arrive before a small team has a formal trust center, SOC 2 report, or dedicated security team. That does not mean the answer should be improvised. A good response explains what is approved, what is prohibited, who owns the controls, what evidence exists, and what you will not disclose. If a new question reveals a tool or workflow that is outside your approved rules, run the AI Tool Risk Checker before sending the final response.

Bottom line

Answer AI security questionnaires from approved evidence, not memory.

  1. Do not claim certifications, audits, controls, or contractual commitments that are not true.
  2. Do not attach raw customer data, raw transcripts, full audit logs, source code, credentials, private admin screenshots, or internal incident notes by default.
  3. Use summaries, control descriptions, dates, owners, and redacted evidence.
  4. Route legal, regulatory, insurance, breach notification, data processing, and contract questions to the right owner.
  5. Keep a copy of the final response packet and review it during the next renewal or customer audit.

The Small Team AI Security Checklist is the baseline control set. This page turns that baseline into customer-facing answers.

When to use this checklist

SituationUse this checklist?What it should produce
A customer asks whether employees use ChatGPT, Claude, Cursor, meeting bots, or browser extensionsYesA clear approved-tool and approved-use answer.
A procurement team asks for your AI governance processYesA short policy summary and evidence packet.
A security team asks for AI vendor due diligenceYesVendor review status, owner, data scope, and review cadence.
A customer asks for proof of deletion, retention, or access reviewYesRedacted governance evidence, not raw operational data.
A questionnaire asks about model training or customer data reuseYesProduct-specific statements backed by vendor terms and your internal policy.
A buyer asks for a SOC 2, ISO, HIPAA, PCI, or legal assurance you do not haveYes, with escalationA truthful limitation and owner-reviewed answer.
A question requires contract interpretation, regulated data, breach notice, or insurance languageNoRoute to legal, compliance, leadership, or counsel.

Do not use this checklist to bypass a required contract review.

Response packet map

Prepare one response packet for each customer questionnaire. Keep it small enough to review, but complete enough to support your answers.

Packet itemWhat to includeWhat to avoid
Response ownerName or role of the person accountable for the answer.A shared inbox with no owner.
Scope statementWhich product, team, customer data class, and time period the response covers.Broad claims that cover unrelated products or future features.
Approved AI tool listTool name, owner, approved users, approved use cases, approved data classes, and review date.Experimental tools that are not approved.
AI usage policy summaryOne paragraph on allowed use, prohibited use, approval flow, and employee responsibility.Full internal policy drafts with comments.
Customer data handling answerWhether customer data can be entered, copied, uploaded, synced, transcribed, or summarized.Raw examples of customer records.
Vendor review summaryReview date, decision, known data processors, admin controls, and next review date.Vendor dashboard exports with private account details.
Access and connector evidenceRedacted screenshots or summaries showing admin controls, connector scope, and last review.Full tokens, full user exports, unrelated app grants, or source-system data.
Retention summaryHow long governance evidence, transcripts, logs, and exports are kept.Raw transcripts unless the customer contract requires them.
Incident and escalation processWho investigates AI tool incidents, how evidence is captured, and when customers are notified.Internal incident notes before review.
LimitationsControls you do not have, certifications not held, and assumptions behind the response.Marketing language that sounds like an audit opinion.

Store the response packet in the same evidence location used by your monthly access reviews and renewal reviews.

Question triage matrix

Use this matrix before answering. It prevents sales from sending optimistic answers and prevents security from over-sharing evidence.

Question typeDefault ownerRisk levelResponse rule
Approved AI tools and use casesAI tool ownerLowAnswer from the current inventory.
Employee AI usage policyOperations or security ownerLowShare the policy summary and review cadence.
Customer data input rulesData owner and security ownerMediumAnswer by data class and approved workflow.
Model training or model improvementTool owner and vendor review ownerMediumUse vendor terms plus your internal settings and policy.
Connectors, OAuth, browser extensions, or meeting botsWorkspace adminMediumShare connector scope, owner, and review date.
Retention and deletionData ownerMediumShare retention rules and evidence schedule.
Incident history or customer impactLeadership and security ownerHighEscalate before answering.
Contractual warranties or legal commitmentsBusiness owner and legal reviewerHighDo not improvise.
Regulated data such as health, payment, child, biometric, or government dataLegal, compliance, and data ownerHighEscalate and answer only after scope confirmation.
Requests for raw evidenceSecurity ownerHighProvide redacted summaries unless the contract requires more.

If the questionnaire format forces a yes/no answer, add a short qualifier in the notes field whenever the answer depends on scope.

Evidence to prepare

Before answering, gather:

  1. Current approved AI tool inventory.
  2. Current AI usage policy or employee rule.
  3. Vendor review records for each customer-facing or customer-data-touching AI tool.
  4. Data classification rules for customer data, regulated data, source code, credentials, meeting recordings, and support tickets.
  5. Admin control screenshots or written summaries for each major AI workspace.
  6. Connector and OAuth review records.
  7. Browser extension allowlist or review record.
  8. Meeting bot consent, retention, and sharing rules.
  9. Developer AI tool rules for repositories, terminals, local files, and code context.
  10. Latest access review and offboarding evidence.
  11. Evidence retention schedule and deletion workflow.
  12. Incident, rollback, remediation, and exception process summaries.

Use record IDs and redacted screenshots when possible. The goal is to prove governance, not to create a second copy of sensitive operational data.

Safe response rules

RulePractical wording
Answer only current controls”As of the review date below, our approved AI tool list is…”
Separate product behavior from employee behavior”Our product does not send customer data to AI tools for this workflow. Employees may use approved AI tools only under the policy below.”
Avoid unsupported certifications”We do not currently claim SOC 2 or ISO certification for this control. We maintain the internal controls described below.”
State limitations plainly”This response covers the Cybergiz site and internal content workflow. It does not cover unrelated client systems.”
Redact evidence”We can provide a redacted settings screenshot or control summary on request.”
Avoid raw data”We do not provide raw customer records, transcripts, source code, credentials, or full audit logs through questionnaire attachments.”
Use dates”Last reviewed on 2026-07-19.”
Escalate legal commitments”Contractual terms, data processing terms, and breach notice language require business owner review.”

If an answer would require a private account screenshot, export the minimum view, redact identifiers, and save the redacted version in the response packet.

Common AI questionnaire answers

These examples are intentionally conservative. Replace bracketed placeholders with your real approved facts.

QuestionSafer answer pattern
Do employees use generative AI tools?”Yes. Employees may use only approved AI tools for approved use cases. The approved list is reviewed by [owner] on [cadence].”
Can employees paste customer data into AI tools?”Customer data may be used only when the tool, data class, customer workflow, and vendor terms have been approved. Sensitive or regulated data requires explicit owner approval.”
Is customer data used to train public models?”Our policy prohibits sending customer data to tools or settings that permit public model training unless explicitly approved for that data class and customer workflow. Tool-specific answers are based on current vendor terms and settings.”
Do you use AI meeting bots?”Meeting bots require approval, participant notice, transcript storage rules, sharing limits, retention rules, and owner review before use.”
Do browser extensions have access to customer systems?”AI browser extensions are reviewed for permissions, host access, OAuth grants, data access, vendor terms, and deployment scope before approval.”
Do developers use AI coding tools?”Developer AI tools require approval for repository scope, file access, terminal use, code context sharing, retention, and owner review.”
How do you review AI vendors?”We review vendors for data use, retention, admin controls, access controls, connectors, subprocessor disclosures where available, security documentation, and change signals.”
How do you handle AI incidents?”AI incidents are routed to [owner]. The team records scope, affected data class, tool, user, containment action, customer impact assessment, and closure decision.”
How long do you keep AI governance evidence?”Governance evidence is kept according to the evidence retention schedule. Raw customer content is not retained in governance records by default.”
Can you provide proof?”We can provide redacted control summaries, dated decision records, and settings screenshots appropriate to the request scope.”

Never copy these rows as final answers without replacing placeholders and confirming current settings.

Red flags that need escalation

Escalate before answering when a question asks about:

  1. Legal warranties, indemnities, data processing terms, breach notification terms, or security addendum language.
  2. Regulated data, protected health information, payment card data, children’s data, biometrics, government data, or export-controlled data.
  3. A customer-specific incident, suspected exposure, data deletion proof, or data subject request.
  4. Raw logs, raw transcripts, source code, credentials, private admin exports, or full user directories.
  5. Claims about SOC 2, ISO 27001, HIPAA, PCI, GDPR, CCPA, FedRAMP, or other compliance programs.
  6. Vendor terms that changed since the last review.
  7. Tools used by contractors, agencies, or outsourced teams outside your normal workspace controls.
  8. AI features embedded inside products that process customer content automatically.

Write the escalation decision into the response packet so future questionnaires do not repeat the same debate.

Internal owner map

Response areaPrimary ownerBackup ownerEvidence source
Approved AI tool inventoryOperations ownerSecurity ownerTool inventory and intake approvals.
AI usage policyOperations ownerFounder or executive sponsorCurrent policy and acknowledgement record.
Customer data rulesData ownerSecurity ownerData classification table and approval records.
Vendor reviewTool ownerWorkspace adminVendor review packet and renewal record.
Connectors and OAuthWorkspace adminSource-system ownerConnector register and access review.
Browser extensionsBrowser adminSecurity ownerExtension allowlist and policy evidence.
Meeting botsMeeting ownerOperations ownerConsent, retention, and sharing rules.
Developer AI toolsEngineering leadSecurity ownerRepository and IDE approval records.
Incident and remediation answersSecurity ownerFounder or business ownerIncident process and closure records.
Contract and legal languageBusiness ownerLegal reviewerCustomer contract and approved language.

Small teams can use roles instead of named people, but every response area needs one accountable owner.

Response review workflow

  1. Intake the questionnaire and assign a response owner.
  2. Mark questions as low, medium, or high risk using the triage matrix.
  3. Pull the current AI tool inventory and policy summary.
  4. Confirm the customer, product, data class, and time period in scope.
  5. Draft answers from evidence, not memory.
  6. Replace all placeholders.
  7. Redact screenshots and remove raw sensitive content.
  8. Send high-risk answers to the correct owner before submission.
  9. Save the final response, date, reviewer, and evidence packet.
  10. Convert repeated questions into reusable approved answer text.

If the questionnaire exposes a gap, create a remediation or exception record instead of hiding the gap in vague wording.

Customer evidence package

For most small-team questionnaires, prepare these customer-safe artifacts:

ArtifactCustomer-safe version
AI tool inventoryTool names, approved uses, owners, review dates, and risk level.
Policy summaryOne-page summary of allowed use, prohibited use, approval flow, and escalation.
Data handling summaryData classes allowed and prohibited by AI workflow.
Connector register summaryConnected systems, purpose, owner, and last review date.
Browser extension summaryApproved extensions, host scope, permissions reviewed, and owner.
Meeting bot summaryConsent notice, retention rule, transcript location category, and sharing rule.
Developer AI summaryApproved tools, repository scope, code context rule, and owner.
Access review proofReview date, reviewer, removals or exceptions, and next review.
Retention schedule summaryGovernance evidence categories and deletion cadence.
Incident process summaryIntake route, containment owner, customer impact assessment, and closure rule.

Keep private versions internally. Customer-safe versions should be redacted, concise, and dated.

Follow-up tracker

Use this tracker after submitting a questionnaire.

FieldExample
Customer or reviewerCustomer name or procurement team.
Questionnaire dateDate received.
Submitted dateDate sent.
Response ownerRole or person.
Product or service scopeProduct, workflow, or team covered.
High-risk questionsCount and owner.
Evidence sharedRedacted screenshots, summaries, or policy excerpts.
Open gapsMissing control, stale review, unknown vendor setting, or contract issue.
Follow-up due dateDate.
Reusable answer updatesApproved wording added to the answer library.
Next review dateDate.

Review this tracker monthly if customer security reviews are part of your sales cycle.

Metrics to track

Track a few signals so the response process improves over time:

MetricWhy it matters
Questionnaires receivedShows whether customer trust work is becoming a sales bottleneck.
Average response timeMeasures operational drag.
High-risk questions per packetShows where controls or evidence are weak.
Reused approved answersReduces one-off drafting.
Evidence gaps foundFeeds the remediation backlog.
Customer follow-up questionsShows which answers are unclear or unsupported.
Deals delayed by AI security reviewHelps prioritize trust work.
Controls updated after questionnairesTurns customer pressure into better operations.

If response time is rising, build a small approved-answer library before adding more policies.

Evidence checked

This checklist is aligned with:

  1. NIST AI Risk Management Framework guidance for governing, mapping, measuring, and managing AI risks.
  2. NIST Cybersecurity Framework functions for governance, identification, protection, detection, response, and recovery.
  3. NIST Privacy Framework concepts for identifying, governing, controlling, communicating, and protecting privacy risk.
  4. NIST SP 800-53 Rev. 5 control families that commonly support access control, audit, configuration, incident response, risk assessment, and system protection evidence.
  5. Cybergiz templates for tool inventory, access review, retention, incident response, vendor review, connector review, browser extension review, meeting bot review, and developer AI review.

This page is an operational checklist, not legal, procurement, compliance, or audit advice.

FAQ

Should a small team answer “yes” to having an AI governance program?

Only if you can explain what that means. A lightweight program can be real if it has approved tools, owners, data rules, access reviews, vendor review, incident routing, and evidence. Do not use enterprise language if the controls are informal.

Can we send screenshots as proof?

Yes, but use redacted screenshots. Remove private account details, unrelated users, sensitive customer names, credentials, full logs, and unrelated connected apps. Save the redacted copy with the response packet.

What if a customer asks whether any AI vendor trains on our data?

Answer by tool and workflow. Review the current vendor terms, workspace settings, product tier, data class, and internal policy. Do not give a blanket answer if different tools have different settings.

What if we do not have a SOC 2 report?

Say that plainly. Then describe the specific internal controls you do maintain. Do not imply an audit, certification, or assurance report that does not exist.

Should sales answer these questionnaires alone?

No. Sales can coordinate the response, but AI tool inventory, data rules, vendor review, incident handling, and contract language need the responsible owners.

How often should approved answers be reviewed?

Review approved answers after vendor changes, customer incidents, major product changes, new data workflows, new AI tools, renewal reviews, and at least quarterly if questionnaires are common.