Which AI questions show up in questionnaires?
The questions repeat across questionnaires because they all stem from the same fear: the customer's data reaching a third-party AI vendor without control. These are the common ones:
- Do your employees use generative AI tools? Which ones, and for what?
- Is customer data entered into AI tools? If so, under what contractual basis (DPA, processing terms)?
- Do your AI vendors appear on your subprocessor list?
- Is our data used to train models?
- What technical controls prevent sensitive data from entering unapproved tools?
- Is there a written AI policy, and are employees trained on it?
Why is "we don't use AI" a bad answer?
Because it is almost never true — and the customer knows it. Employees adopt AI tools with or without approval, and a blanket answer that turns out inaccurate undermines the credibility of the entire questionnaire. Denial also signals you have no AI governance at all: whoever won't admit to usage certainly isn't managing it.
The customer isn't looking for a vendor without AI — they're looking for a vendor in control of its AI. An honest answer with controls beats a polished denial.
What does a strong answer to the AI section look like?
A strong answer is built from three components: policy, technical control, and proof. In practice it reads like this:
- Written policy — "Generative AI use is governed by an approved policy: permitted tools, permitted data types, and a mandatory process for sensitive documents." If you're unsure what counts as sensitive, start with what should never be pasted into ChatGPT.
- Technical control — "Documents undergo consistent anonymization before any AI input: identifiers are replaced with tokens (PERSON_001), including metadata cleaning."
- Data flow — "Anonymization runs locally in the browser; the original file is never sent to any server, so no new subprocessor is added to the chain."
- Training and records — "Employees are trained on the policy, and use of approved tools is documented."
- A standards anchor — teams that fold AI controls into an existing ISMS answer from a position of strength; see ISO 27001 and AI usage.
How does anonymization turn a weak answer into a strong one?
Most of the hard questions in the AI section evaporate once the data entering the tools is no longer identifiable. "Does our data reach AI vendors?" — no: what reaches them is an anonymized version with no names, IDs or customer details. "Is our data used for training?" — even in the worst case, there is nothing identifying in it. An answer that used to sink deals becomes one that supports safe AI adoption across the account.