8 questions from the RFI stage, free
These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.
1. Do you hold a current SOC 2 Type II attestation covering the product offered? Provide the report date, observation period end date, and the name of the auditing firm.
Why it matters. SOC 2 Type II is a foundational attestation for enterprise SaaS vendors, demonstrating that security controls have been independently audited over a period of time. A missing, stale, or in-flight-only attestation can indicate immature controls or an unwillingness to undergo scrutiny.
- States the observation period end date and when the next report is due, so the buyer can check the report's age against its own policy.
- Names a recognized, independent CPA firm as the auditor.
- Confirms the offered product is within the scope of the report.
- Offers only a SOC 2 Type I report.
- Attestation is 'in progress' with no firm completion date.
- The report's observation period ended earlier than the buyer's policy accepts, and no bridge letter covers the gap.
2. Provide a table mapping each of your certifications and attestations to the specific products, service editions, and geographic regions they cover. Explicitly confirm that the solution offered in this proposal is included in this scope.
Why it matters. Certifications can be scoped to a specific product line or region, not the entire company portfolio. A buyer can purchase a product that is outside the scope of the vendor's advertised certifications. Buyers with data residency needs must verify their specific region is covered.
- Provides a clear, per-certification matrix mapping certs to products and regions.
- Explicitly confirms the offered SKU and deployment region are in scope.
- Distinguishes corporate certifications from product certifications.
- Evades the question with a link to a generic compliance webpage.
- Cannot map certifications to specific products and regions.
- The offered product or region is in a separate, uncertified environment.
3. Will you provide your most recent, unredacted attestation reports (e.g., SOC 2 Type II) and certifications (e.g., ISO 27001) to us under a standard non-disclosure agreement (NDA) before we sign a contract?
Why it matters. Meaningful due diligence requires reviewing the actual audit reports, not just marketing summaries. Vendors that withhold these artifacts until after contract signature are preventing buyers from making an informed risk decision.
- Confirms that full reports can be shared pre-contract under a standard, mutual NDA.
- Provides access to a self-service trust portal where documents can be reviewed.
- Proactively offers to schedule a call with their security/compliance team to review the reports.
- Will only provide reports after a contract is signed.
- Requires use of a vendor-sided, non-negotiable NDA with onerous terms.
- Will only provide heavily redacted reports or high-level summaries, not the full document.
4. Describe the process your organization uses to monitor and adapt to emerging AI-specific regulations and standards (e.g., EU AI Act, US state-level AI laws). Provide a recent example of a product or control change driven by this process.
Why it matters. The global regulatory landscape for AI is evolving rapidly. A vendor without a structured process for monitoring these changes and integrating them into their product development and compliance programs exposes their customers to significant compliance risks.
- Describes a formal process for regulatory horizon scanning, involving legal, GRC, and product teams.
- Provides a concrete example of a recent regulatory change (like the EU AI Act) and the specific product features or controls implemented in response.
- Can articulate their interpretation of how major regulations apply to their service.
- Provides a generic statement like 'our legal team monitors regulations'.
- Cannot provide any recent examples of a regulatory change impacting their product.
- Is unaware of or has no position on major AI regulations relevant to the buyer's jurisdiction (e.g., the EU AI Act for an EU buyer).
5. Which Trust Services Criteria (Security, Availability, Confidentiality, Processing Integrity, Privacy) were included in the scope of your most recent SOC 2 Type II report?
Why it matters. A SOC 2 report is not monolithic. The Security criterion is mandatory, but others are optional. A criterion left out of scope means the auditor did not examine those controls.
- Explicitly lists all TSCs that were in scope.
- Confidentiality and Availability are included, especially if the product handles sensitive data or is governed by an SLA.
- The Privacy criterion is included if the service processes personal information (PI/PII).
- Only the Security criterion is in scope, despite the service handling sensitive customer data.
- Vendor cannot articulate which TSCs are covered without checking the report.
- Confidentiality is omitted from the scope for a service intended to process confidential business data.
6. List all sub-processors and third-party services whose activities are part of the service you are offering (including cloud infrastructure providers, model providers, etc.). Indicate whether each is covered inclusively within your certifications or is a 'carve-out' for which you rely on their attestations.
Why it matters. Modern AI services are complex supply chains. A vendor's certification provides little assurance if critical components, like the underlying cloud provider or foundation model API, are 'carved out' of the audit scope. Understanding this distinction is vital to assessing the true extent of third-party assurance.
- Provides a complete list of sub-processors.
- Clearly distinguishes between the 'inclusive' and 'carve-out' methods for each sub-processor.
- For carve-out sub-processors, can provide their own attestations (e.g., the cloud provider's SOC 2 report).
- Refuses to provide a sub-processor list prior to contract.
- Material sub-processors (like the primary cloud hosting provider or LLM endpoint) are carved out, and the vendor cannot provide their compliance reports.
- Vendor is unable to explain the difference between the inclusive and carve-out methods.
7. Do you provide bridge letters (or gap letters) to cover the period between the end of one audit's observation period and the issuance of the next report?
Why it matters. There can be a multi-month gap between when an audit period ends and when the final report is issued. Bridge letters provide assurance from the vendor that their control posture has not materially changed during that gap.
- States how often bridge letters are issued and how a customer requests one.
- The bridge letter attests to no material changes in the same control environment covered by the underlying report.
- Does not issue bridge letters.
- Bridge letters are available only to customers on the highest enterprise tier.
- The scope of the bridge letter is narrower than the underlying report.
8. List any major certifications or attestations you are actively pursuing but have not yet achieved. For each, provide the target audit date, expected issuance date, and the name of the engaged assessor or audit firm.
Why it matters. A vendor's compliance roadmap signals their future investment and market focus. Asking for the engaged assessor and specific dates helps distinguish a real, funded project from a marketing talking point.
- Provides a list of in-flight certifications with specific target dates (e.g., 'Q3 202X').
- Names the engaged audit firm or assessor for each item on the roadmap.
- Clearly distinguishes between certifications that are 'in audit' vs. 'planned'.
- Lists roadmap items as 'in progress' with no dates or named assessor.
- The same certifications have been listed as 'in-flight' for multiple years without progress.
- Refuses to name the engaged audit firm, citing confidentiality.
What the audit changed
A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 196 changes. Three examples:
Wrong or outdated citation
Draft: Names an IAF-accredited certification body (e.g., BSI, Schellman, A-LIGN).
Now: Names its certification body (e.g., BSI, Schellman, A-LIGN) and that body's accreditation body, which signs the IAF Multilateral Recognition Arrangement (e.g., ANAB, UKAS).
The IAF does not accredit certification bodies; national accreditation bodies that sign the IAF Multilateral Recognition Arrangement (e.g., ANAB, UKAS) do (https://iaf.nu).
Wrong or outdated citation
Draft: The certification body is not IAF-accredited or is unnamed.
Now: The certification body is unnamed, or is not accredited by an accreditation body that signs the IAF Multilateral Recognition Arrangement.
The IAF does not accredit certification bodies; national accreditation bodies that sign the IAF Multilateral Recognition Arrangement (e.g., ANAB, UKAS) do (https://iaf.nu).
Wrong or outdated citation
Draft: What is the scope defined in the Statement of Applicability for your ISO 27001 certification?
Now: What is the scope of your ISO 27001 certification as stated on the certificate, and which Annex A controls does your Statement of Applicability exclude?
ISO/IEC 27001:2022 clause 4.3 defines the ISMS scope, which the certificate states; the Statement of Applicability (clause 6.1.3 d) lists the Annex A controls included and excluded, not the scope.