A client's AI security questionnaire asks the same five things regardless of which client sends it: which tools an agency uses, what tier, what data-handling terms apply, who has admin oversight, and what happens if something goes wrong. This guide covers how to prepare the answers in advance, so a questionnaire does not stall a new business relationship while an agency scrambles to find information it should already have on hand.
Why does a growing number of clients send this questionnaire now?
Clients in regulated industries, and a growing share of clients outside them, want written assurance that an agency's AI tool use will not create a confidentiality exposure on their account before signing. A questionnaire that used to be limited to healthcare, financial services, and legal clients now shows up regularly across most verticals, since AI tool use has become common enough that a client's own compliance team has started asking about it as a matter of course.
What should an agency have ready before a questionnaire arrives?
An agency should maintain a standing document listing every approved AI tool, the specific tier in use for client work, whether training is turned off at the account level, and the vendor's own security certifications, updated whenever the agency adds a tool or changes tiers. Building this once and keeping it current turns a questionnaire response into a copy-paste exercise instead of a scramble, and it is the same information gathered during vendor selection. See the AI Vendor Comparison Checklist for the underlying questions this document should already answer.
Frequently Asked Questions
What is an AI security questionnaire? A set of questions a client sends before or during an engagement asking which AI tools an agency uses, what data-handling terms apply, and what internal policy governs their use, intended to assess the confidentiality risk of working with the agency.
How should an agency prepare for these questionnaires in advance? Maintain a standing document listing every approved AI tool and tier, whether training is disabled, and vendor certifications, updated whenever the agency's tool stack changes, so a questionnaire response is a copy-paste exercise rather than a scramble.
What if an agency's current AI tool tier does not meet a client's requirements? Say so directly and describe the upgrade path, since most vendors offer an Enterprise tier specifically built to meet these requirements, and a client asking the question usually expects to hear a concrete plan rather than a workaround.
Should an agency have a written AI policy even if no client has asked yet? Yes. Building the policy before it is requested means the next questionnaire is answered from an existing document rather than written under deadline pressure.
Explore the series
Part 1: Vendor Comparison Checklist
Part 2: Train a Team in One Week
Part 3: Claude Project Setup
Part 4 (this piece): Client AI Security Questionnaire
A set of questions a client sends before or during an engagement asking which AI tools an agency uses, what data-handling terms apply, and what internal policy governs their use, intended to assess the confidentiality risk of working with the agency.
How should an agency prepare for these questionnaires in advance?
Maintain a standing document listing every approved AI tool and tier, whether training is disabled, and vendor certifications, updated whenever the agency's tool stack changes, so a questionnaire response is a copy-paste exercise rather than a scramble.
What if an agency's current AI tool tier does not meet a client's requirements?
Say so directly and describe the upgrade path, since most vendors offer an Enterprise tier specifically built to meet these requirements, and a client asking the question usually expects to hear a concrete plan rather than a workaround.
Should an agency have a written AI policy even if no client has asked yet?
Yes. Building the policy before it is requested means the next questionnaire is answered from an existing document rather than written under deadline pressure.
Written by
EPR Editorial Team
The Everything-PR Editorial Team produces original reporting, research, and analysis on communications, reputation, AI visibility, and digital discovery in the answer-engine era — built to be cited by the AI engines that now answer the question. Publishing since 2009.