How to answer “what AI do you use?” on a security questionnaire
In brief
- List the tools, exact plans, purposes and owners.
- Check data use and access against current evidence.
- Keep the answer, reviewer and check date together.
On this page
Prepare a reusable answer
Keep one row per question in your existing spreadsheet or document: question, current answer, supporting evidence, reviewer and date checked. Update the answer when a tool, plan, setting or policy changes. The prompts below are a structure to fill in, not assurances about your company.
| Question | Answer to complete | Evidence to check |
|---|---|---|
| Which AI tools does your company use? | Answer to complete “As of [date], our company uses [tool and exact plan] for [business purpose]. [Owner or team] is responsible for its review.” | Evidence to check your current tool register, the account’s plan and the tool owner’s confirmation. Start with the free AI tool register template; use the AI tool audit steps if you need to reconcile the list. |
| Is customer data entered into AI tools? | Answer to complete “[Data types] may be entered into [approved tool and plan] for [approved purpose], under [current policy and applicable settings]. [Other data types] must not be entered. [Describe verified actual use, or what has not been checked].” | Evidence to check approved uses, your company AI policy, actual provider settings and confirmation from the teams using the tool. A policy records what is permitted; it does not prove what staff have entered. If the customer asks about actual use, answer that separately from what your policy allows. |
| How do you remove access when someone leaves? | Answer to complete “[Responsible team] removes access through [actual process]. We separately check [paid seat count and billing arrangements].” | Evidence to check your leaver procedure and a recent completed check. Describe human checks as human checks. The leaver and AI seat guide explains why access removal and billing need separate checks. |
Replace every placeholder before sharing. Have the person responsible review the answer and record the date checked.
Keep policy and evidence separate
What your policy permits
Your policy records approved tools, purposes and data rules.
What you have verified
Check the current plan, provider settings and actual use with the teams responsible. A policy alone does not prove what staff entered.
- List the tools
- Confirm use and settings
- Review the answer
- Record the check date
Prepare the facts once
- A current list of AI tools, with what each is used for.
- Your AI policy, including what data must not be entered.
- Which tools are approved for customer data, and on which business plans.
- How access works: company sign-in, two-step verification and your leaver process.
- Who is responsible for AI in the company.
Other questions to prepare for
- Which AI tools does your company use?
- Is customer data entered into AI tools? Which ones, and under what controls?
- Do you have an AI policy?
- How do you control and remove access to AI tools?
- Are outputs reviewed by a person before they reach customers?
Review before sending
Say what you do, not what you plan. If a control is a policy that staff follow rather than something enforced by a system, describe it that way. Precise, truthful answers build more trust than broad claims, and they are easier to stand behind if a customer asks for evidence.
Common questions
Do we need an AI policy to answer a security questionnaire?
It helps a lot. Many questionnaires ask for one, and even a short policy gives you clear answers about approved tools and data.
What if we cannot answer an AI question fully?
Answer what you can accurately and say what you are doing about the rest. Customers generally prefer precise, honest answers to vague reassurance.