Due-diligence workbook and vendor response document

Knowledge Base Software Security & AI Questionnaire

Ask one control per row, require product- and region-scoped evidence, separate current controls from roadmap, and track exceptions, residual risk, remediation, and the buyer’s decision.

Independent and vendor-neutral: no vendor names, affiliate ranking, prefilled scores, or email gate are built into the file.

Excel .xlsx + Word .docxVersion 1.0Updated August 10, 2026No macros
Security & AI due-diligence workbook
QuestionnaireEvidence RegisterAI ComponentsExceptions
IDDomainQuestion / evidenceStatus
SEC-001GovernanceName the accountable owner and current control scopeUndisclosed
SEC-027IdentityProve SSO, MFA, and lifecycle behavior for this planReview
SEC-090AIShow ACL enforcement, retention, and model data useEvidence
EX-001ExceptionRecord owner, remediation date, acceptance, and expiryOpen

Illustrative preview of the file structure. The download contains the full editable template.

Excel .xlsx + Word .docxeditable download
Version 1.0clear change control
August 10, 2026last updated
No signupdirect download

Inside the download

What the security questionnaire asks vendors to prove

The value is in the method, evidence fields, visible limits, and decision controls—not in decorative blank cells.

100+ focused questions

Governance, architecture, tenancy, identity, encryption, secure development, logging, incidents, recovery, privacy, AI, KB-specific controls, and exit.

Evidence register

Type, issuer, product and region scope, period, issue, expiry, NDA, assurance, evaluator, validation, and status.

Data-flow and subprocessor map

Purpose, categories, source, destination, regions, retention, encryption, deletion, contract, and owner.

AI component register

Feature, model, provider, release status, default behavior, data use, retention, region, ACL, human review, and change notice.

Exceptions and remediation

Gap, risk, compensating control, commitment, date, owners, acceptance, expiry, and evidence.

Decision summary

Coverage, evidence, blockers, mandatory follow-ups, roadmap gaps, remediation, and human risk decision.

How to use it

Four steps from blank template to evidence

Define applicability

Set buyer targets, criticality, plan, region, and AI scope before sending.

Request controlled evidence

Let vendors reference sensitive evidence under NDA instead of exposing it in the file.

Verify scope and currency

Check exact product, component, region, report period, expiry, and current availability.

Decide risk explicitly

Keep vendor answer, evidence confidence, inherent risk, residual risk, and acceptance separate.

What this template does not prove

The questionnaire is informed by security and AI risk frameworks, but it is not an audit, legal advice, or proof that a vendor is secure or compliant. The prefilled criticality is only a suggested starting point; tailor applicability and criticality before issue.

File-specific questions

Frequently asked questions

Is a certification enough evidence?

No. Check the issuing entity, exact product and region scope, report period, expiry, exclusions, and whether the control applies to the proposed service.

Does Undisclosed mean No?

It remains a distinct status, but it receives no evidence confidence and may still create a blocker or follow-up for critical controls.

How should roadmap controls be treated?

Record them as roadmap, not current. They do not reduce present risk unless the buyer accepts a contractual remediation plan.

Why provide both Excel and Word?

The Word edition is easier to send as a formal vendor response document. The Excel workbook keeps buyer verification, formulas, risk, exceptions, and decision summary.

Download, adapt, and preserve the evidence

We keep each download URL stable across version updates so your bookmarks and citations continue to work. No email address or account is required.

Published by Knowledge-Base.software · Template v1.0 · Updated August 10, 2026 · Free to adapt for internal evaluation; no resale · Editorial standards · Corrections