# Enterprise AI Security Questionnaire Answer Bank
Executive Summary
This answer bank gives sales, trust, legal, product, and security one controlled source for enterprise AI security questionnaire answers. It separates approved answers from drafts, partial answers, blocked answers, and escalation-only topics.
The goal is not to make questionnaires painless. The goal is to stop answer drift, prevent unsupported claims, and route every customer-facing AI security answer back to evidence.
Public sample notice
Recommended sales enablement decision
Use the answer bank for enterprise review, but mark retrieval authorization, agent execution, prompt retention, and AI incident response as partial or blocked until evidence is complete.
Answer Bank Snapshot
The risk is not only the answer. It is who made it up.
Controlled answer bank
Enterprise AI Security Questionnaire Answer Bank
The answer bank tracks buyer questions, approved answers, answer status, owners, evidence, freshness rules, do-not-say notes, and escalation paths.
High-friction buyer questions
High-friction AI security questions
| Question | Status | Owner | Evidence |
|---|---|---|---|
| Is customer data used to train foundation models? | Draft | Vendor Management and Legal | provider-data-use-statement-draft |
| Can a user receive information through AI that they cannot access directly? | Partial | Search Platform | rag-authz-test-plan |
| Can the AI system take actions on behalf of users? | Partial | AI Platform Engineering | agent-tool-permission-matrix |
| Are prompts and outputs retained? | Draft | Security Engineering | ai-trace-retention-policy-draft |
| How do you respond to AI-related incidents? | Blocked | Security Operations | ai-incident-playbook-draft |
Answer quality findings
Answer Bank Findings
Provider training-use answer needs legal approval
The organization should not reuse a customer-facing no-training answer until it is mapped to provider terms, subprocessors, model route, and approved legal language.
Retrieval access answer must remain partial
The retrieval answer should say designed, not fully validated, until negative authorization tests pass across the full retrieval pipeline.
Agent action answer needs action classes
The buyer question is not whether the AI uses tools. The buyer question is what the AI can read, draft, queue, approve, execute, and log.
AI incident response answer is blocked
The organization should not claim mature AI incident response until the AI incident playbook and tabletop exercise are complete.
Do-not-say rules
Do-not-say rules
| Topic | Do not say | Say instead |
|---|---|---|
| Model training | “No data is used for training” without route-specific proof | “Provider terms exclude training for approved routes; legal-approved wording applies” |
| Retrieval | “AI respects permissions” without tests | “Retrieval is designed to preserve authorization; tests are being completed” |
| Agents | “Human in the loop” without context | “Sensitive actions require approval with evidence, target, diff, blast radius, and trace reference” |
| Logging | “We do not retain prompts” unless true | “AI traces are governed by retention and access policy” |
| Incidents | “Existing IR covers AI” without tabletop | “AI incident playbook is being finalized and exercised” |
Escalation rules
Escalation rules
| Trigger | Owner | SLA |
|---|---|---|
| Model training, provider retention, subprocessors, customer data use | Legal and Vendor Management | 2 business days |
| Claims that retrieval authorization is complete | Search Platform and Product Security | 2 business days |
| Claims about AI execution authority | AI Platform Engineering | 1 business day |
| Prompt/output retention periods | Security Engineering and Privacy | 2 business days |
Sales process decision
Route every AI security questionnaire through the answer bank. If the answer is draft, partial, blocked, or stale, escalate before sending it to the customer.
Operating checklist
How to operate the answer bank
Related artifact: Enterprise AI Security Evidence Pack
The evidence pack is the source of proof. The answer bank is the controlled customer-facing answer layer.
Related artifact: RAG Security Test Plan
The RAG test plan supplies the evidence needed to move retrieval answers from partial to approved.