A security questionnaire rarely stalls because the answer is unknown. It stalls because the answer is a sentence, and the reviewer wanted a record.
SIG, CAIQ, a buyer’s own spreadsheet and the newer AI-governance addenda word things differently. Underneath, they ask the same families of question. For each one below I give the answer that stalls a deal and the evidence that closes it. The pattern repeats: the stalling answer describes an intention, and the closing answer points at something a reviewer can check.
A questionnaire answer is a claim. The evidence behind it is what the buyer is actually buying.
Access control and offboarding
- Is MFA enforced for all workforce access to production and customer data?
- Stalls on
- “MFA is available to all staff.” Available is not enforced, and the reviewer knows the difference.
- Closes with
- The identity provider policy showing enforcement, and the exceptions list, even if it is empty.
- How is access granted, reviewed and removed?
- Stalls on
- “Access is reviewed regularly.” No date, no reviewer, no result.
- Closes with
- The last access review with its date and sign-off, and the last leaver’s removal time set beside their leaving date.
- How is one customer’s data isolated from another’s?
- Stalls on
- “We use a multi-tenant architecture.” That describes the risk, not the control.
- Closes with
- A test in which one tenant’s credentials try to read another tenant’s record, and the refusal it gets.
- Who holds privileged or production access?
- Stalls on
- “A small number of senior engineers.”
- Closes with
- The named list, its count, and the approval path for emergency access.
Where I build this: TrustLedger. OAuth2 resource server. Every API is tenant-scoped, and a second tenant reading another’s issue gets 403.
Change management and secure development
- Are code changes reviewed before they reach production?
- Stalls on
- “We follow best practice for code review.”
- Closes with
- Branch protection settings, and a sample of merged changes showing who approved each.
- Can one person ship a change to production alone?
- Stalls on
- Silence, when the honest answer at a small company is yes.
- Closes with
- The rule that prevents it, or the plain exception with the compensating control that watches it.
- How are vulnerable dependencies found and fixed?
- Stalls on
- “We keep our dependencies up to date.”
- Closes with
- The scanner running in CI, and the count and age of open critical findings.
- Are production deployments recorded?
- Stalls on
- “Our CI/CD pipeline handles deployments.”
- Closes with
- A deploy log naming who shipped which commit, and when.
Where I build this: Agent Clearing Network. Maker-checker approval before a clearing decision stands.
Logging, monitoring and incident response
This is the family where I found my own answer wrong. The Agent Clearing Network’s feature matrix said OpenTelemetry hooks were present until a search found the string in three documents and zero source files. The row now says No, and the homepage matrix shows the gap.
- What do you log, and for how long?
- Stalls on
- “We log all relevant events.”
- Closes with
- The retention setting as configured, and the list of event types actually written.
- Are logs protected from alteration?
- Stalls on
- “Our logs are tamper-proof” said of a store that is only append-only. Append-only is not tamper-evident.
- Closes with
- Write-once storage or a hash chain, and a verification you can run on demand.
- Do you have an incident response plan, and when was it last tested?
- Stalls on
- A plan with no exercise date.
- Closes with
- The plan, and the record of the last real incident or exercise, dated.
- How quickly will you notify us of a breach?
- Stalls on
- “Promptly.”
- Closes with
- A number of hours, matching the one in your data processing agreement.
Where I build this: CyberGuardPlus. A hash-chained log of privileged actions that can be verified on demand.
Data handling, retention and sub-processors
- Where is our data stored and processed?
- Stalls on
- “In secure cloud data centres.”
- Closes with
- The region for each system and sub-processor that touches customer data.
- Is data encrypted at rest and in transit?
- Stalls on
- “Yes, we use industry-standard encryption.”
- Closes with
- The storage encryption setting, the minimum TLS version, and who controls the keys.
- What happens to our data when the contract ends?
- Stalls on
- “Data is deleted in line with our policy.”
- Closes with
- The deletion procedure, its timescale, and the record of a deletion you have actually completed.
- Which sub-processors do you use, and how will we hear about changes?
- Stalls on
- A list that omits the model provider.
- Closes with
- A current list including every AI provider, and the notice period for adding one.
AI model use and human oversight
- Is our data used to train or fine-tune any model, yours or a provider’s?
- Stalls on
- “We take data privacy seriously.”
- Closes with
- A direct no or yes, the provider terms or retention setting that backs it, and your own statement.
- Which models and providers do you use, and for what?
- Stalls on
- “We use leading AI models.”
- Closes with
- A model inventory: provider, model, purpose, and which data reaches it.
- What can the AI do without a person approving it?
- Stalls on
- “A human is always in the loop.” Usually not true of every action, and reviewers test it.
- Closes with
- The list of actions it may take alone, the ones it may not, and the record of an approval gate firing.
- How do you evaluate outputs and handle errors?
- Stalls on
- “The model is highly accurate.”
- Closes with
- The evaluation set, the known failure modes, and how a user overrides or reports a wrong output.
- How does this map to the NIST AI RMF, ISO/IEC 42001 or the EU AI Act?
- Stalls on
- “We are fully compliant.” Nobody reviewing an AI addendum believes an unqualified claim.
- Closes with
- Your risk classification under each, with the reasoning, and the obligations you have not yet met.
Where I build this: Agent Clearing Network. Signed mandates carrying purpose, limits, counterparty allowlists and expiry, plus a runtime policy endpoint.
Third-party assurance
- Please provide your SOC 2 Type II report.
- Stalls on
- Answering the questionnaire around its absence and hoping it is not noticed.
- Closes with
- The report and a bridge letter for the uncovered period, or a named gap with a date: readiness started, auditor engaged, window planned.
- When was your last penetration test?
- Stalls on
- A date with no findings attached.
- Closes with
- The executive summary, and the remediation status of each finding.
- Is the service we are buying inside your ISO/IEC 27001 scope?
- Stalls on
- A certificate whose scope covers a different entity or product.
- Closes with
- The certificate and the scope statement naming this service.
- What are your recovery point and recovery time objectives, and when did you last test a restore?
- Stalls on
- Targets with no test behind them. Documentation is not evidence.
- Closes with
- The objectives, and the dated record of a restore that was checked for data integrity, not just for starting.
What this guide does not do
- It is not legal advice, and it does not certify anything. Only an accredited auditor can issue a SOC 2 report or an ISO certificate.
- The questions are paraphrased from what the public formats commonly ask. Your buyer’s wording will differ, and so will the weighting.
- A strong answer here closes a question. It does not make an absent control exist.
Turn your answers into records.
The Rescue Sprint maps each question on your live questionnaire to the evidence that closes it, and names the gaps before your buyer does.
See the Rescue Sprint