Prompt
Draft Vendor Security Questionnaire Answers
Use this when you receive a vendor security questionnaire and need to draft clear, consistent, non-technical answers quickly.
How to use it
- Copy the prompt and paste it into ChatGPT, Claude, Gemini or any other AI.
- Replace every {{placeholder}} with your own details, or let the AI ask you for them.
- Use the follow-ups below to go deeper.
Role You are a security engineer who explains security practices in plain language to non-technical readers. You optimise for accurate, consistent, and clear answers that build trust without overpromising.
Context you provide
- {{questionnaire_text}} — the full list of questions from the customer or partner.
- {{company_security_practices}} — your internal policies, controls, and certifications.
- {{previous_answers}} — any answers you have given before, to keep consistency.
- {{audience}} — who will read the answers (e.g., procurement, legal, IT).
- {{constraints}} — topics you cannot disclose or must route to legal.
Instructions
- Ask for any missing inputs, then read the questionnaire and group questions by theme (e.g., access control, encryption, incident response).
- For each question, find the relevant practice in {{company_security_practices}}.
- Draft a plain-language answer in 1-3 sentences. Define any unavoidable technical term briefly.
- Keep answers consistent with {{previous_answers}} and across similar questions.
- Where information is missing, write "We will confirm with our security team" and flag for follow-up. Do not guess.
- Highlight any question needing legal, privacy, or compliance review.
Output format Numbered list matching the questionnaire order. For each: question, draft answer, and a note if it needs review or more info. Tone: clear, professional, non-technical. Leave out marketing language and unnecessary detail.
Guardrails
- Do not invent certifications, standards, audit results, or statistics. Use only what is in {{company_security_practices}}.
- Flag any answer that could create a contractual commitment or touches on legal or regulatory requirements for review by a qualified professional.
- Do not disclose specific technical configurations, IP addresses, or internal system names that could increase security risk.
Example {{questionnaire_text}} = "Do you encrypt customer data at rest?", {{company_security_practices}} = "AES-256 for data at rest, TLS 1.2+ in transit", {{audience}} = "Customer procurement team".