Glossary
Security questionnaire
The standard set of questions a buyer sends a vendor before approving a purchase, and frequently the slowest step in adopting anything new.
In plain terms
A list of questions sent to a vendor before they are approved, asking how they run their security, what happens to material you send, and who else is involved. Some are a page and some are hundreds of rows. The vendor answers, somebody reads the answers, and frequently a second round follows because the first answers were not specific enough to record.
Why it matters
Because it is where adoption timelines are actually spent, and because most of the delay is structural rather than anybody being slow. Each round costs days of waiting on both sides, and the number of rounds is largely decided by how specific the first answers were. Understanding that changes what a buying team can do about it, which is more than most buying teams believe.
How it works
Its purpose is to produce a record somebody can rely on, not to be convinced. A reviewer has to write down what was established, so an answer that reads well and says nothing checkable creates work rather than closing it. That is why a vague reply generates another round: the reviewer literally cannot complete their own task with it.
Much of it is the same questions everywhere, which is why vendors keep prepared answers and why standard formats exist. A vendor asked to complete a bespoke spreadsheet when it holds a completed standard one is being asked for translation work, and accepting the format it already has is frequently the single largest saving available in the whole exercise.
Existing artefacts answer a lot of it. An audit report or a certification with its scope statement covers many rows outright, and asking for those first often reduces the questionnaire to the parts genuinely specific to your situation. Sending the full list without asking is how a two-week step becomes a two-month one.
For AI tools a few questions carry most of the weight, and they are not usually on the standard form. What is retained and for how long, whether material is used to train, which model provider sits behind the product, and where processing happens. Adding those four to a general questionnaire is worth more than the other several hundred rows combined.
Two ways to run the same review
Seen in the wild
Asking what an assistant retains and whether material is used for training, which a general questionnaire rarely covers.
ChatGPTEstablishing how a search tool handles permissions from the systems it reaches, which is the question specific to that product.
GleanAsking how an automation platform stores the credentials it holds for every other service you connect.
Make
Common misconceptions
People assume
It is slow because vendors drag their feet.
In fact
Most delay is rounds, and rounds come from answers too general for a reviewer to record. Vendors usually reply promptly with what they have. Sending a bespoke format when they hold a completed standard one, and not asking for existing reports first, cause more delay than anybody's responsiveness.
People assume
A longer questionnaire is more thorough.
In fact
Past a point it mostly adds rounds. Hundreds of general rows produce general answers, while a handful of specific questions about what happens to your material produce answers a reviewer can act on. For AI tools the questions that matter are usually absent from the long form entirely.
Questions
- How do we make it faster?
- Ask for existing reports and certifications first, accept the standard format the vendor already holds, and add the few questions specific to your situation. Most of the delay is extra rounds, and each of those three removes a cause of one rather than pressing anybody to hurry.
- What should we add for an AI tool?
- What is retained and for how long, whether material may be used to train, which model provider sits behind the product, and where processing happens. Those four are frequently missing from general forms and are usually the ones that would actually change a decision.
- Why do vague answers cause another round?
- Because the reviewer's output is a record of what was established, and a reassuring sentence gives them nothing to write. That is a structural feature of the task rather than pedantry, and it is why specific answers close a review while confident general ones extend it.
Key takeaways
- The point is a record somebody can rely on, not persuasion.
- Most delay is extra rounds, caused by answers too general to record.
- Existing reports and certifications answer many rows before you ask.
- For AI tools, four specific questions beat several hundred general rows.
Last checked July 2026