The situation
A mid-sized SaaS company is two weeks from signing its largest enterprise customer. Procurement sends over the security review: a few hundred questions, most of which the team has answered before. This time there is a new tab labelled Artificial Intelligence. It asks which models power the product's AI features, whether customer data is used for training, who the model providers are, and whether the company follows an AI management standard. Near the bottom sit three questions that no one on the product team owns: Do employees use generative AI tools? What prevents them from entering customer data into those tools? How is that use monitored?
The sales engineer fills in the product questions in an afternoon. The last three sit blank for a week.
What the rules actually say
Two things are true at once. There is no single mandatory AI questionnaire, and the standard ones buyers borrow from have all added AI content.
What the standard questionnaires include
- Shared Assessments SIG. The 2024 SIG maps to the NIST AI Risk Management Framework (NIST AI 100-1), according to Shared Assessments' list of mapped references. Its September 2025 release added AI governance content and references to ISO/IEC 42001, so buyers can assess how a vendor manages AI across data collection, model training, deployment, and monitoring. The SIG itself is licensed, so the exact wording depends on which version and scope your buyer uses.
- Cloud Security Alliance AI Controls Matrix. CSA released the AICM in July 2025 as 243 control objectives across 18 domains, with an accompanying questionnaire, the AI-CAIQ, meant for self-assessment or for evaluating third-party vendors. The AICM download is free and assigns responsibilities across roles such as model provider, application provider, and AI customer, which helps a SaaS company describe which controls it owns and which sit with its model provider.
- ISO/IEC 42001. Published in December 2023, ISO/IEC 42001 sets requirements for an AI management system in organizations that develop, provide, or use AI-based products or services. Questionnaires often ask whether you are certified or aligned. See our ISO 42001 overview for the basics.
Two different questions under one heading
Most AI sections mix two subjects, and it helps to separate them before answering.
AI in your product. Which models and providers are involved, whether they act as subprocessors of customer data, retention and training terms, how outputs are tested, and who approves new AI features. This is familiar territory for product and engineering teams.
Your employees' use of AI with customer data. Support agents pasting tickets into a chatbot to draft replies, engineers pasting production logs or customer schemas into a coding assistant, account managers summarizing contract terms. None of this touches your product, and all of it can move customer data to a third party the customer never approved.
For Canadian vendors, the second question has a legal anchor. Under PIPEDA Schedule 1, clause 4.1.3, an organization stays responsible for personal information it transfers to a third party for processing and must use contractual or other means to provide comparable protection. A customer's data pasted into an unsanctioned AI account comes with no such contract. Confirm with counsel how this applies to your data flows.
Why policies and bans fall short
The easy answer to the employee questions is "we have an acceptable use policy". Buyers increasingly follow up by asking how the policy is enforced and what records exist. A policy with no enforcement is a statement of intent, and a security reviewer will read it that way.
Blocking AI tools outright is a hard sell at a software company, where engineers expect AI assistance and will find it on a personal account if the company account is locked. The result is the worst possible questionnaire answer: use continues, and there is no record of it. Our post on keeping engineering AI velocity without leaking source code covers that tension. If you are a law firm facing a client questionnaire instead, answering the client AI security questionnaire addresses that version of the problem.
What a practical control looks like
- Split ownership. Product and engineering answer the product questions; security or operations answers the employee questions.
- Keep a model and provider register listing each AI provider, the customer data it receives, its retention and training terms, and whether it appears in your subprocessor list.
- Publish an employee AI policy that names sanctioned tools and forbids entering customer data, credentials, and source code into unsanctioned ones.
- Pick a reference framework. Map your answers to the AICM or ISO/IEC 42001 so they stay consistent across buyers.
- Control the point of entry so customer data is caught before it reaches an AI tool, whichever tool an employee opens.
- Train and record. Keep completion data and incident reports you can cite.
- Maintain a reusable answer set with evidence attached, reviewed each quarter.
Sanitized Ai is a browser extension that gives vendors a concrete answer to the employee questions. When a staff member pastes or uploads customer personal information, identifiers, financial data, or source code into an AI assistant, it redacts or blocks the sensitive content before submission and explains in plain language what was flagged and why. Content already submitted to a public AI tool cannot be recalled and becomes subject to the provider's terms, so the control acts before that point.
Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) that never includes prompt content, so your evidence of enforcement does not become a new store of customer data. Those records can support a questionnaire answer as evidence of reasonable safeguards, without guaranteeing how any buyer will score it. Learn more on our engineering page.