Enterprise AI Vendor Security Questionnaire

Forty questions that tell you whether an AI vendor has thought about security or just written about it. Built from the questions Ironbark Cyber asks when the vendor's answers are our problem to verify.

Last updated

What's in the questionnaire?

Forty questions across seven sections, each written to force a specific answer rather than a paragraph of reassurance. Every question comes with a note on what a good answer looks like and what a red flag looks like. Because a questionnaire you can't score is just homework for the vendor's marketing team.

  • Model provenance and supply chain. Whose models, trained on what, fine-tuned how, and what happens when the upstream model changes underneath you.
  • Data handling and training use. Whether your prompts and data are retained, logged, used for training, or visible to vendor staff. And for how long.
  • Tenant isolation. How one customer's data, context and embeddings are kept from another's, and how that has been tested.
  • Guardrails and abuse resistance. What stands between a hostile prompt and a harmful action, and whether anyone adversarial has ever tested it.
  • Security testing. When the product was last penetration tested, by whom, with AI attack coverage or without it.
  • Incident response and transparency. Notification timelines, breach history, and who picks up the phone.
  • Compliance mappings. ISO/IEC 42001, SOC 2, the AU AI Technical Standard and where the certificates actually apply.

Who is this for?

Security teams reviewing AI products before procurement, CISOs who keep receiving "it's SOC 2 compliant" as an answer to a question they didn't ask, and government buyers who need vendor answers they can put in front of a risk owner. If a vendor's answers worry you and the purchase matters, Ironbark Cyber can verify the claims directly. That's an AI security assessment.

About Ironbark Cyber

Ironbark Cyber is an Australian AI security and penetration testing consultancy, founded in 2025 by Luke Stephens (hakluke) and part of the Haksec group. We test AI systems for a living, which is why these questions are specific. You may also want the companion AI Security Assessment Checklist for systems you build yourself.

Download

Get the questionnaire

Tell us who you are and we'll send it over. No follow-up sequence, no surprise sales calls.

We'll email you the link as well. By submitting you agree to our privacy policy.