The AI Vendor Security Questionnaire Every UK Buyer Should Send
Third parties featured in 30% of breaches last year, yet only 15% of UK businesses review supplier risk. Send these 21 questions to any AI vendor before you sign.

By Ivan Pylypchuk, CEO of SoftBlues. Has led Claude and Gemini implementations for finance, legal and healthcare teams across the UK and Ireland.
Before signing with any AI vendor, send a security questionnaire covering UK GDPR roles, training-data use, retention and deletion, model and API access controls, audit logging, sub-processors, hosting locations, and incident response. The 21 questions below are the ones a UK compliance team will ask eventually; sending them first saves weeks and filters weak vendors early.
The case for asking is now statistical. Third parties were involved in 30% of data breaches in the latest Verizon analysis, double the share of the year before (Verizon Data Breach Investigations Report, 2025). Yet only 15% of UK businesses reviewed the risks posed by their immediate suppliers, and even among large businesses fewer than half did (Cyber Security Breaches Survey 2025/26, GOV.UK). At SoftBlues, an AI consulting firm working with regulated mid-market companies across the UK and Ireland, we sit on both sides of these questionnaires: we send them to the AI platforms we build on, and we answer them as a vendor. This is the question set we would want to receive.

Key facts
Who this is for, and who it isn't
This is for the person responsible for approving an AI supplier at a UK mid-market firm: a COO, CTO, head of IT, DPO or compliance lead, especially in regulated sectors answering to the FCA, SRA, CQC or ICO. Use it whether you are buying an AI platform subscription, a built solution, or consulting that touches your data.
It is less useful if you are experimenting with AI on public data only, with nothing confidential in scope. In that case a standard supplier check covers most of it.
Why do AI vendors need a different questionnaire from normal SaaS?
Because three risks exist with AI suppliers that a standard SaaS review never probes. First, training: could your data end up improving a model that serves other customers? Second, prompt and output logging: AI systems often retain the very content you send them, which for a law firm or adviser can mean client confidential material sitting in a vendor's logs. Third, model access: your data may pass through a model provider (Anthropic, OpenAI, Google) that is a sub-processor of your actual vendor, and the terms that matter are theirs.
A generic questionnaire misses all of that. The one below does not.
The questionnaire: 21 questions across seven areas
Copy these into a document, send them to the vendor, and ask for written answers. Notes on what a good answer looks like follow in the next section.
Data protection and UK GDPR
1. Are you a processor or a controller for our data under UK GDPR, and will you sign our data processing agreement (or provide yours for review)?
2. Where is our data processed and stored, at rest and in transit? Name the countries and the legal transfer mechanism for anything outside the UK/EEA.
3. What categories of our data do you process, and can we exclude special category or client confidential data from specific features?
Training data and model use
4. Is any of our data, including prompts and outputs, used to train or fine-tune models, yours or a third party's? If yes, can we opt out in writing?
5. Which foundation model providers does your product rely on, and under what terms (consumer, API, enterprise)?
6. Can you guarantee our data is never used to serve other customers, and describe the tenant isolation that enforces this?
Retention and deletion
7. How long are prompts, outputs, files and logs retained, per data type?
8. When we delete data, or leave, what is actually deleted, from where, and within what timescale? Backups included?
9. Can retention periods be configured to match our own policies?
Access controls
10. Which of your staff can access our data, under what approval process, and is that access logged?
11. Do you support SSO, multi-factor authentication and role-based permissions for our users?
12. How are API keys and credentials issued, scoped, rotated and revoked?
Audit logging
13. What user and admin actions are logged, and can we export those logs?
14. Can we see who in our organisation sent what to the AI system, for internal investigations and regulator requests?
15. How long are audit logs kept, and are they tamper-evident?
Sub-processors and hosting
16. Provide your current sub-processor list. How are we notified of changes, and can we object?
17. Who hosts your infrastructure, and which certifications does that hosting carry?
18. If your model provider changes its terms or has an incident, what is your obligation to us?
Incident response and assurance
19. Describe your breach notification process and timescales. UK GDPR expects the controller to report to the ICO within 72 hours; your notice to us must arrive well within that.
20. Have you had a security incident in the past 24 months? What happened and what changed afterwards?
21. What independent assurance can you share: ISO 27001 certification, SOC 2 report, recent penetration test summary?
How do you read the answers?
| Signal | Good answer | Red flag |
|---|---|---|
| Speed and form | Written answers in days, from existing documents | Weeks of delay, or a call offered instead of answers |
| Training data | "No training on your data, by default, in the contract" | "We may use data to improve our services" |
| Retention | Specific periods per data type, configurable | "Data is retained as long as necessary" |
| Sub-processors | A published, dated list with a change notification process | A list produced on request, or none |
| Audit logs | Exportable, covering user prompts and admin actions | "Logs are available on request to support" |
| Incidents | A dated, specific account and what changed | "We have never had any security issues" |
| Assurance | A current SOC 2 or ISO 27001 certificate, pen test summary | "We follow industry best practices" |
Two notes from the vendor side of the table. A supplier who has genuinely done the work can answer almost everything from documents they already maintain; slow, defensive answers usually mean the documents do not exist. And be precise about certification claims in both directions: "aligned with ISO 27001 principles" and "ISO 27001 certified" are different statements, and a vendor who blurs them on security will blur other things too. SoftBlues, for the record, builds around ISO 27001 principles and is not certified; we say so.

What if the vendor won't answer?
Treat a refusal as data. For a low-stakes tool touching no confidential information, you might accept a subset of answers and restrict what the tool can access. For anything processing client, financial or health data, an unanswered questionnaire should end the conversation, because the numbers say the risk is real: with third parties now involved in 30% of breaches, your supplier's security posture is effectively part of yours.
There is also a regulatory floor here. If the vendor is your processor, UK GDPR Article 28 requires you to use only processors providing "sufficient guarantees", and the ICO can fine controllers who cannot show they checked. The questionnaire is your evidence that you did.
Where does this fit in the buying process?
Send it at shortlist stage, after you know a vendor is a plausible fit but before commercial negotiation. It pairs with the evaluation framework in our guide to comparing AI consulting proposals, teams and delivery risk, and if you are rolling out Claude specifically, the governance side is covered in our Claude Enterprise implementation checklist.
For what these controls look like from the inside, we have documented how we run our own company on Claude, including permissions and data boundaries, in the SoftBlues Claude Operating System case study.
Frequently asked questions
Should we send this to consultancies as well as software vendors?
Yes, if they will touch your data. A consultancy building automation for you processes your data just as a SaaS product does, sometimes with broader access. The same 21 questions apply; expect the answers to reference their own suppliers.
What is a reasonable deadline for answers?
Ten working days is fair for a mid-market questionnaire of this size. A vendor with mature security practices will usually respond faster, because the material already exists.
Do we need a DPIA as well?
Often, yes. If the AI system processes personal data in a way likely to result in high risk (large-scale processing, special category data, systematic monitoring), UK GDPR requires a data protection impact assessment. The vendor's questionnaire answers feed directly into it.
Is ISO 27001 or SOC 2 mandatory before we can buy?
No. Neither is a legal requirement, and plenty of capable smaller vendors hold neither. What matters is honest evidence: a pen test summary and precise answers can outweigh a certificate held by a vendor who cannot explain their own retention policy.
How is this different for free or consumer AI tools?
Consumer tiers of AI tools typically log prompts and may use them for training, with no DPA, no SSO and no audit trail. That is why "shadow AI", staff using personal accounts for work data, fails almost every question above. If a team needs the tool, buy the enterprise tier or block it.
How often should we re-run the questionnaire?
Annually, and on trigger events: a change of sub-processor, a vendor acquisition, an incident, or a new feature that touches more of your data. Questions 16 to 21 are the ones to re-check most often.
SoftBlues is a registered Anthropic Partner Network member and a registered Google Cloud and Microsoft partner. We build AI systems for regulated UK and Ireland firms, and we answer questionnaires like this one for a living. If you are evaluating AI vendors and want a second pair of eyes on the answers, book a discovery call.
See it in production
Systems we have built and run for clients, with the numbers that came out of them.
Related Articles

EU AI Act for UK Companies: What Applies in 2026 and What to Do Next

AI Total Cost of Ownership: What UK Mid-Market Companies Actually Spend on AI in 2026
