checklist
AI security questionnaire response checklist for small teams
A practical checklist for answering customer AI security questionnaires without over-sharing private evidence, raw logs, transcripts, source code, or sensitive customer data.
Use this checklist when a customer, procurement team, security reviewer, investor, insurer, or enterprise buyer asks how your small team uses AI tools.
AI security questionnaires often arrive before a small team has a formal trust center, SOC 2 report, or dedicated security team. That does not mean the answer should be improvised. A good response explains what is approved, what is prohibited, who owns the controls, what evidence exists, and what you will not disclose. If a new question reveals a tool or workflow that is outside your approved rules, run the AI Tool Risk Checker before sending the final response.
Bottom line
Answer AI security questionnaires from approved evidence, not memory.
- Do not claim certifications, audits, controls, or contractual commitments that are not true.
- Do not attach raw customer data, raw transcripts, full audit logs, source code, credentials, private admin screenshots, or internal incident notes by default.
- Use summaries, control descriptions, dates, owners, and redacted evidence.
- Route legal, regulatory, insurance, breach notification, data processing, and contract questions to the right owner.
- Keep a copy of the final response packet and review it during the next renewal or customer audit.
The Small Team AI Security Checklist is the baseline control set. This page turns that baseline into customer-facing answers.
When to use this checklist
| Situation | Use this checklist? | What it should produce |
|---|---|---|
| A customer asks whether employees use ChatGPT, Claude, Cursor, meeting bots, or browser extensions | Yes | A clear approved-tool and approved-use answer. |
| A procurement team asks for your AI governance process | Yes | A short policy summary and evidence packet. |
| A security team asks for AI vendor due diligence | Yes | Vendor review status, owner, data scope, and review cadence. |
| A customer asks for proof of deletion, retention, or access review | Yes | Redacted governance evidence, not raw operational data. |
| A questionnaire asks about model training or customer data reuse | Yes | Product-specific statements backed by vendor terms and your internal policy. |
| A buyer asks for a SOC 2, ISO, HIPAA, PCI, or legal assurance you do not have | Yes, with escalation | A truthful limitation and owner-reviewed answer. |
| A question requires contract interpretation, regulated data, breach notice, or insurance language | No | Route to legal, compliance, leadership, or counsel. |
Do not use this checklist to bypass a required contract review.
Response packet map
Prepare one response packet for each customer questionnaire. Keep it small enough to review, but complete enough to support your answers.
| Packet item | What to include | What to avoid |
|---|---|---|
| Response owner | Name or role of the person accountable for the answer. | A shared inbox with no owner. |
| Scope statement | Which product, team, customer data class, and time period the response covers. | Broad claims that cover unrelated products or future features. |
| Approved AI tool list | Tool name, owner, approved users, approved use cases, approved data classes, and review date. | Experimental tools that are not approved. |
| AI usage policy summary | One paragraph on allowed use, prohibited use, approval flow, and employee responsibility. | Full internal policy drafts with comments. |
| Customer data handling answer | Whether customer data can be entered, copied, uploaded, synced, transcribed, or summarized. | Raw examples of customer records. |
| Vendor review summary | Review date, decision, known data processors, admin controls, and next review date. | Vendor dashboard exports with private account details. |
| Access and connector evidence | Redacted screenshots or summaries showing admin controls, connector scope, and last review. | Full tokens, full user exports, unrelated app grants, or source-system data. |
| Retention summary | How long governance evidence, transcripts, logs, and exports are kept. | Raw transcripts unless the customer contract requires them. |
| Incident and escalation process | Who investigates AI tool incidents, how evidence is captured, and when customers are notified. | Internal incident notes before review. |
| Limitations | Controls you do not have, certifications not held, and assumptions behind the response. | Marketing language that sounds like an audit opinion. |
Store the response packet in the same evidence location used by your monthly access reviews and renewal reviews.
Question triage matrix
Use this matrix before answering. It prevents sales from sending optimistic answers and prevents security from over-sharing evidence.
| Question type | Default owner | Risk level | Response rule |
|---|---|---|---|
| Approved AI tools and use cases | AI tool owner | Low | Answer from the current inventory. |
| Employee AI usage policy | Operations or security owner | Low | Share the policy summary and review cadence. |
| Customer data input rules | Data owner and security owner | Medium | Answer by data class and approved workflow. |
| Model training or model improvement | Tool owner and vendor review owner | Medium | Use vendor terms plus your internal settings and policy. |
| Connectors, OAuth, browser extensions, or meeting bots | Workspace admin | Medium | Share connector scope, owner, and review date. |
| Retention and deletion | Data owner | Medium | Share retention rules and evidence schedule. |
| Incident history or customer impact | Leadership and security owner | High | Escalate before answering. |
| Contractual warranties or legal commitments | Business owner and legal reviewer | High | Do not improvise. |
| Regulated data such as health, payment, child, biometric, or government data | Legal, compliance, and data owner | High | Escalate and answer only after scope confirmation. |
| Requests for raw evidence | Security owner | High | Provide redacted summaries unless the contract requires more. |
If the questionnaire format forces a yes/no answer, add a short qualifier in the notes field whenever the answer depends on scope.
Evidence to prepare
Before answering, gather:
- Current approved AI tool inventory.
- Current AI usage policy or employee rule.
- Vendor review records for each customer-facing or customer-data-touching AI tool.
- Data classification rules for customer data, regulated data, source code, credentials, meeting recordings, and support tickets.
- Admin control screenshots or written summaries for each major AI workspace.
- Connector and OAuth review records.
- Browser extension allowlist or review record.
- Meeting bot consent, retention, and sharing rules.
- Developer AI tool rules for repositories, terminals, local files, and code context.
- Latest access review and offboarding evidence.
- Evidence retention schedule and deletion workflow.
- Incident, rollback, remediation, and exception process summaries.
Use record IDs and redacted screenshots when possible. The goal is to prove governance, not to create a second copy of sensitive operational data.
Safe response rules
| Rule | Practical wording |
|---|---|
| Answer only current controls | ”As of the review date below, our approved AI tool list is…” |
| Separate product behavior from employee behavior | ”Our product does not send customer data to AI tools for this workflow. Employees may use approved AI tools only under the policy below.” |
| Avoid unsupported certifications | ”We do not currently claim SOC 2 or ISO certification for this control. We maintain the internal controls described below.” |
| State limitations plainly | ”This response covers the Cybergiz site and internal content workflow. It does not cover unrelated client systems.” |
| Redact evidence | ”We can provide a redacted settings screenshot or control summary on request.” |
| Avoid raw data | ”We do not provide raw customer records, transcripts, source code, credentials, or full audit logs through questionnaire attachments.” |
| Use dates | ”Last reviewed on 2026-07-19.” |
| Escalate legal commitments | ”Contractual terms, data processing terms, and breach notice language require business owner review.” |
If an answer would require a private account screenshot, export the minimum view, redact identifiers, and save the redacted version in the response packet.
Common AI questionnaire answers
These examples are intentionally conservative. Replace bracketed placeholders with your real approved facts.
| Question | Safer answer pattern |
|---|---|
| Do employees use generative AI tools? | ”Yes. Employees may use only approved AI tools for approved use cases. The approved list is reviewed by [owner] on [cadence].” |
| Can employees paste customer data into AI tools? | ”Customer data may be used only when the tool, data class, customer workflow, and vendor terms have been approved. Sensitive or regulated data requires explicit owner approval.” |
| Is customer data used to train public models? | ”Our policy prohibits sending customer data to tools or settings that permit public model training unless explicitly approved for that data class and customer workflow. Tool-specific answers are based on current vendor terms and settings.” |
| Do you use AI meeting bots? | ”Meeting bots require approval, participant notice, transcript storage rules, sharing limits, retention rules, and owner review before use.” |
| Do browser extensions have access to customer systems? | ”AI browser extensions are reviewed for permissions, host access, OAuth grants, data access, vendor terms, and deployment scope before approval.” |
| Do developers use AI coding tools? | ”Developer AI tools require approval for repository scope, file access, terminal use, code context sharing, retention, and owner review.” |
| How do you review AI vendors? | ”We review vendors for data use, retention, admin controls, access controls, connectors, subprocessor disclosures where available, security documentation, and change signals.” |
| How do you handle AI incidents? | ”AI incidents are routed to [owner]. The team records scope, affected data class, tool, user, containment action, customer impact assessment, and closure decision.” |
| How long do you keep AI governance evidence? | ”Governance evidence is kept according to the evidence retention schedule. Raw customer content is not retained in governance records by default.” |
| Can you provide proof? | ”We can provide redacted control summaries, dated decision records, and settings screenshots appropriate to the request scope.” |
Never copy these rows as final answers without replacing placeholders and confirming current settings.
Red flags that need escalation
Escalate before answering when a question asks about:
- Legal warranties, indemnities, data processing terms, breach notification terms, or security addendum language.
- Regulated data, protected health information, payment card data, children’s data, biometrics, government data, or export-controlled data.
- A customer-specific incident, suspected exposure, data deletion proof, or data subject request.
- Raw logs, raw transcripts, source code, credentials, private admin exports, or full user directories.
- Claims about SOC 2, ISO 27001, HIPAA, PCI, GDPR, CCPA, FedRAMP, or other compliance programs.
- Vendor terms that changed since the last review.
- Tools used by contractors, agencies, or outsourced teams outside your normal workspace controls.
- AI features embedded inside products that process customer content automatically.
Write the escalation decision into the response packet so future questionnaires do not repeat the same debate.
Internal owner map
| Response area | Primary owner | Backup owner | Evidence source |
|---|---|---|---|
| Approved AI tool inventory | Operations owner | Security owner | Tool inventory and intake approvals. |
| AI usage policy | Operations owner | Founder or executive sponsor | Current policy and acknowledgement record. |
| Customer data rules | Data owner | Security owner | Data classification table and approval records. |
| Vendor review | Tool owner | Workspace admin | Vendor review packet and renewal record. |
| Connectors and OAuth | Workspace admin | Source-system owner | Connector register and access review. |
| Browser extensions | Browser admin | Security owner | Extension allowlist and policy evidence. |
| Meeting bots | Meeting owner | Operations owner | Consent, retention, and sharing rules. |
| Developer AI tools | Engineering lead | Security owner | Repository and IDE approval records. |
| Incident and remediation answers | Security owner | Founder or business owner | Incident process and closure records. |
| Contract and legal language | Business owner | Legal reviewer | Customer contract and approved language. |
Small teams can use roles instead of named people, but every response area needs one accountable owner.
Response review workflow
- Intake the questionnaire and assign a response owner.
- Mark questions as low, medium, or high risk using the triage matrix.
- Pull the current AI tool inventory and policy summary.
- Confirm the customer, product, data class, and time period in scope.
- Draft answers from evidence, not memory.
- Replace all placeholders.
- Redact screenshots and remove raw sensitive content.
- Send high-risk answers to the correct owner before submission.
- Save the final response, date, reviewer, and evidence packet.
- Convert repeated questions into reusable approved answer text.
If the questionnaire exposes a gap, create a remediation or exception record instead of hiding the gap in vague wording.
Customer evidence package
For most small-team questionnaires, prepare these customer-safe artifacts:
| Artifact | Customer-safe version |
|---|---|
| AI tool inventory | Tool names, approved uses, owners, review dates, and risk level. |
| Policy summary | One-page summary of allowed use, prohibited use, approval flow, and escalation. |
| Data handling summary | Data classes allowed and prohibited by AI workflow. |
| Connector register summary | Connected systems, purpose, owner, and last review date. |
| Browser extension summary | Approved extensions, host scope, permissions reviewed, and owner. |
| Meeting bot summary | Consent notice, retention rule, transcript location category, and sharing rule. |
| Developer AI summary | Approved tools, repository scope, code context rule, and owner. |
| Access review proof | Review date, reviewer, removals or exceptions, and next review. |
| Retention schedule summary | Governance evidence categories and deletion cadence. |
| Incident process summary | Intake route, containment owner, customer impact assessment, and closure rule. |
Keep private versions internally. Customer-safe versions should be redacted, concise, and dated.
Follow-up tracker
Use this tracker after submitting a questionnaire.
| Field | Example |
|---|---|
| Customer or reviewer | Customer name or procurement team. |
| Questionnaire date | Date received. |
| Submitted date | Date sent. |
| Response owner | Role or person. |
| Product or service scope | Product, workflow, or team covered. |
| High-risk questions | Count and owner. |
| Evidence shared | Redacted screenshots, summaries, or policy excerpts. |
| Open gaps | Missing control, stale review, unknown vendor setting, or contract issue. |
| Follow-up due date | Date. |
| Reusable answer updates | Approved wording added to the answer library. |
| Next review date | Date. |
Review this tracker monthly if customer security reviews are part of your sales cycle.
Metrics to track
Track a few signals so the response process improves over time:
| Metric | Why it matters |
|---|---|
| Questionnaires received | Shows whether customer trust work is becoming a sales bottleneck. |
| Average response time | Measures operational drag. |
| High-risk questions per packet | Shows where controls or evidence are weak. |
| Reused approved answers | Reduces one-off drafting. |
| Evidence gaps found | Feeds the remediation backlog. |
| Customer follow-up questions | Shows which answers are unclear or unsupported. |
| Deals delayed by AI security review | Helps prioritize trust work. |
| Controls updated after questionnaires | Turns customer pressure into better operations. |
If response time is rising, build a small approved-answer library before adding more policies.
Evidence checked
This checklist is aligned with:
- NIST AI Risk Management Framework guidance for governing, mapping, measuring, and managing AI risks.
- NIST Cybersecurity Framework functions for governance, identification, protection, detection, response, and recovery.
- NIST Privacy Framework concepts for identifying, governing, controlling, communicating, and protecting privacy risk.
- NIST SP 800-53 Rev. 5 control families that commonly support access control, audit, configuration, incident response, risk assessment, and system protection evidence.
- Cybergiz templates for tool inventory, access review, retention, incident response, vendor review, connector review, browser extension review, meeting bot review, and developer AI review.
This page is an operational checklist, not legal, procurement, compliance, or audit advice.
FAQ
Should a small team answer “yes” to having an AI governance program?
Only if you can explain what that means. A lightweight program can be real if it has approved tools, owners, data rules, access reviews, vendor review, incident routing, and evidence. Do not use enterprise language if the controls are informal.
Can we send screenshots as proof?
Yes, but use redacted screenshots. Remove private account details, unrelated users, sensitive customer names, credentials, full logs, and unrelated connected apps. Save the redacted copy with the response packet.
What if a customer asks whether any AI vendor trains on our data?
Answer by tool and workflow. Review the current vendor terms, workspace settings, product tier, data class, and internal policy. Do not give a blanket answer if different tools have different settings.
What if we do not have a SOC 2 report?
Say that plainly. Then describe the specific internal controls you do maintain. Do not imply an audit, certification, or assurance report that does not exist.
Should sales answer these questionnaires alone?
No. Sales can coordinate the response, but AI tool inventory, data rules, vendor review, incident handling, and contract language need the responsible owners.
How often should approved answers be reviewed?
Review approved answers after vendor changes, customer incidents, major product changes, new data workflows, new AI tools, renewal reviews, and at least quarterly if questionnaires are common.