8 questions from the RFI stage, free
These come from the module as sold. The workbook adds follow-ups, a response format, a weight and a score column to each.
1. Provide your current sub-processor list. For each sub-processor, include its legal name, processing purpose, country/region of data processing, and the specific categories of customer data it may process (e.g., content, metadata, telemetry). This can be provided as a public URL or a direct attachment.
Why it matters. Buyers need a current, detailed sub-processor inventory to complete data-protection impact assessments and vendor risk reviews. Understanding the location, purpose, and data access for each sub-processor is essential for this.
- Direct public URL or attachment provided without NDA
- List includes legal name, processing purpose, location, and data categories for each entry
- States its own update cadence, and the last-updated date is consistent with it
- List only available under NDA or via sales request
- Missing processing purpose, location, or data categories
- No stated update cadence, or a last-updated date inconsistent with it
2. Describe your due-diligence process for onboarding a new sub-processor, including required certifications, security review steps, and approval authority.
Why it matters. Buyers inherit their vendor's sub-processor risk posture. A documented onboarding gate (e.g. SOC 2 review, DPIA, security questionnaire, executive sign-off) shows whether the vendor checks a sub-processor before it receives customer data.
- Documented process with named owners
- Minimum certification floor (e.g. SOC 2 Type II, ISO 27001)
- Privacy and security reviews both required
- Process is informal or undocumented
- Single function approves with no second line
- No certification or assessment floor
3. Confirm whether you can provide a Software Bill of Materials (SBOM) for the deployed product, and identify the format(s) supported (e.g. CycloneDX, SPDX).
Why it matters. Under US Executive Order 14028, OMB memorandum M-22-18 let US agencies require an SBOM; OMB M-26-05 (January 23, 2026) rescinded it and leaves an SBOM to agency contract terms. The EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to draw up an SBOM from 11 December 2027. Format support (CycloneDX, SPDX) determines whether the SBOM integrates with the buyer's tooling.
- SBOM available in CycloneDX or SPDX
- Provided per release
- Available without additional NDA beyond the master agreement
- SBOM unavailable
- Available only on request under separate NDA
- Provided as a static document not refreshed per release
4. Identify all third-party AI models (e.g., foundation, embedding) and related AI services (e.g., for annotation, evaluation, fine-tuning) used to deliver your product. For each, specify the provider, its function, and confirm if customer data is sent to it.
Why it matters. Material product behavior can depend on third-party model providers whose terms, residency, and data practices vary. Buyers need explicit disclosure of all AI dependencies — including for training and evaluation — to evaluate model-tier risk separately from infrastructure risk.
- Each model and service named with provider and function
- Distinguishes vendor-hosted vs API-called models
- Clarifies whether customer data is sent to each dependency
- Vague references to 'our AI partners'
- Refuses to disclose model providers
- Disclosure inconsistent with marketing claims
5. Describe how customers receive advance notice of new or replacement sub-processors, including the notification channel and minimum notice period before the sub-processor goes live.
Why it matters. Under a general written authorization, GDPR Article 28(2) requires the processor to inform the controller of intended changes to sub-processors, giving it the opportunity to object. The notification channel (email, RSS, portal) and notice window materially affect a buyer's ability to act before processing begins.
- States a specific, contractually committed notice period, in the vendor's own number of days
- Multiple notification channels including subscribable feed or email
- Standard DPA references the mechanism
- Notice is only via website check (pull, not push)
- No minimum notice period committed contractually
- Notice happens after the sub-processor is already live
6. Describe how you monitor sub-processors on an ongoing basis, including reassessment frequency and triggers for ad-hoc review.
Why it matters. One-time onboarding is insufficient. Buyers need evidence of continuous monitoring — scheduled reassessments, breach-triggered reviews, certification expiry tracking — proportional to the criticality of each sub-processor.
- Reassessment cadence documented and tied to a named reference point, such as the sub-processor's SOC 2 Type II period or ISO 27001 surveillance cycle
- Tracking of certification expirations
- Ad-hoc review triggered by breach or material change
- No reassessment after initial onboarding
- No tracking of certification status
- Monitoring described in vague aspirational terms
7. Describe your process for identifying, prioritizing, and remediating vulnerabilities in open-source and third-party components.
Why it matters. How a vendor finds and fixes vulnerabilities in third-party components decides how long customers stay exposed to them. The answer reveals whether the vendor practices continuous scanning or only reactive triage.
- Continuous scanning of dependencies
- Documented remediation SLAs by severity, with the vendor's own numbers stated
- Use of SCA tooling named
- Reactive only (responds to CVE announcements)
- No remediation SLA
- No SCA tooling in pipeline
8. For each third-party model used, confirm whether customer prompts, completions, or fine-tuning data may be used by the model provider to train or improve their models.
Why it matters. Buyers with regulated workloads often need to rule out training on customer data. The answer must be explicit per provider, since defaults differ across foundation-model vendors and across API tiers.
- Explicit per-provider answer
- References enterprise/zero-retention tier in use
- Contractual commitment that no customer data is used for provider training
- Aggregated 'no, we don't' answer not tied to specific providers
- Relies on default consumer-tier terms
- Cannot say with certainty
What the audit changed
A language model drafted these questions and a second model critiqued them. Three audit passes followed and made 145 changes. Three examples:
Wrong or outdated citation
Draft: GDPR Article 28(2) requires controllers to be informed of changes to sub-processors with an opportunity to object.
Now: Under a general written authorization, GDPR Article 28(2) requires the processor to inform the controller of intended changes to sub-processors, giving it the opportunity to object.
Carried from the Xither audit (supply-chain-questions.ts). Art. 28(2) binds the processor, and the duty to inform applies under a general written authorization. GDPR Art. 28 text: https://gdpr-info.eu/art-28-gdpr/
Wrong or outdated citation
Draft: the same obligations imposed on the processor be imposed on sub-processors
Now: the same data protection obligations set out in the controller-processor contract be imposed on sub-processors
Art. 28(4) says 'the same data protection obligations as set out in the contract or other legal act between the controller and the processor'. Same correction pass 1 made in rfp.007. GDPR Art. 28 (EUR-Lex): https://eur-lex.europa.eu/eli/reg/2016/679/oj
Wrong or outdated citation
Draft: No TIA process
Now: No TIA process for transfers under SCCs or BCRs
A transfer under an adequacy decision needs no TIA; pass 1 made this correction in rfp.008 only. EDPB Recommendations 01/2020, step 2: with an adequacy decision 'you will not need to take any further steps, other than monitoring that the adequacy decision remains valid'. https://www.edpb.europa.eu/system/files/2021-06/edpb_recommendations_202001vo.2.0_supplementarymeasurestransferstools_en.pdf