"Complete our vendor security assessment (VSA)" — the AI section, question by question
Not every questionnaire is a SIG or a CAIQ. Some buyers send their own spreadsheet — a "vendor security assessment" built in Excel by their security team, with their tabs, their phrasing, and no published guidance. With nothing published to lean on, the AI section of a custom VSA invites improvisation, and improvised legal claims are exactly what due diligence dismantles. Here is the method. (If it just arrived, run the first-24-hours triage first.)
Why custom VSAs are harder than standards
A SIG or an AI-CAIQ comes with question codes, definitions and structure; a custom VSA comes with whatever the buyer's team wrote, sometimes ambiguous, sometimes not even phrased as questions. The fix is not to answer the spreadsheet — it is to answer the underlying control, then phrase it for the spreadsheet. A custom AI question is, in practice, a homegrown version of something a known framework already asks.
Step 1 — map every AI question to a framework you can cite
The reference points: the AI-CAIQ (Cloud Security Alliance, October 2025 — guide), the SIG 2026 AI domain mapped to ISO 42001 (guide), the EU's model contractual clauses for AI (MCC-AI, updated March 2025), and Article 50 of Regulation (EU) 2024/1689. Typical mappings:
| The VSA asks | It is really asking about | Answer with |
|---|---|---|
| "Do you use AI in your product?" | AI system inventory | Per feature: model, provider, version, purpose, fine-tuning yes/no, processing region — full structure |
| "Is our data used to train your models?" | Training-data policy | The model provider's policy verified against its current DPA before you write, plus your own policy — details |
| "Are you compliant with the EU AI Act?" | Classification and obligations | Never a bare yes: classification, applicable obligations (typically Art. 50 and Art. 4), status per obligation, gaps with dates — the four-part answer |
| "Do users know they are interacting with AI?" | Art. 50(1) transparency | If you ship a third-party model under your own brand, you are the provider and the duty is yours, unless the AI is obvious to a person "reasonably well-informed, observant and circumspect" |
| "Which AI certifications do you hold?" | ISO/IEC 42001, SOC 2 | If none: "not currently certified; our AI governance program covers [inventory, transparency, oversight]; we evaluate certification based on customer demand" — no invented dates |
| "List AI subprocessors and data flows" | Third parties and regions | Model providers as subprocessors, processing regions, and the transfer mechanism named in each provider's DPA |
The quoted wordings are illustrative templates — placeholders in brackets, verify every clause against your own facts and each provider's current DPA before submitting.
Keep the dates straight while you map: Article 50 applies from 2 August 2026 and was not postponed by the Digital Omnibus; content-marking under Article 50(2) has a transition until 2 December 2026 for systems already on the market; Article 4 AI-literacy measures have applied since 2 February 2025; the Annex III high-risk regime starts 2 December 2027. If you are unsure which Article 50 duties hit your product, the free Article 50 checker maps it in six questions, and the Article 50 guide covers who owes what.
Step 2 — the consistency rule across tabs
Custom VSAs often repeat the same question in different tabs with different words: the security tab asks about "data protection in AI features", the privacy tab about "personal data in machine-learning systems", the AI tab about "training data". If those three answers diverge — "yes" here, "partially" there — you have handed the reviewer a due-diligence flag no individual answer would have raised. The rule: one person owns the canonical answer set; every cell is an adaptation of a canonical answer, never a fresh improvisation. And assume the reviewer reads the VSA next to your website and your DPA — consistency is cross-document, not just cross-tab.
Step 3 — gaps in the format that survives review
Where a control is missing or partial: current state, compensating control, "in progress", and a target date someone in your company actually approved. If a dropdown forces yes/no, choose the closest value and put the real answer in the notes column. Never invent a control to make a cell green — your answers may end up warranted contractually, and under Article 99(4)(g) a breach of Article 50 can draw fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher (for SMEs and startups, the lower of the two, Article 99(6)). That is why our standard is every legal claim cited to its article, and why the full method in how to answer the AI section treats accuracy as the deliverable.
Mini-FAQ
The dropdown only allows yes/no but the honest answer is "partially" — what do we do?
Closest value in the dropdown, real answer in the notes column: state, compensating control, in progress, approved date. Never a hopeful yes.
Should we answer a custom VSA differently from a SIG or CAIQ?
Same substance, different packaging. Build one canonical answer per underlying question, mapped to its framework, and adapt the phrasing per spreadsheet. The library makes the next questionnaire faster.
What if a question does not apply to our product?
"Not applicable" plus one line of why. A naked N/A reads as evasion and invites another round; a reasoned one closes the question.
Related: all answer guides for the individual questions inside the VSA, and the honest comparison of your delivery options if you are deciding who fills it in.