Template
LLM Vendor Risk Questionnaire
46 questions across 12 domains for LLM and AI vendors, split into 20 Core and 26 Enhanced.
Conventional vendor security questions alongside AI-specific ones. Every question names the evidence to ask for and has a response field and a notes area.
What’s inside
- Twelve domains, including model and data provenance, prompt and interaction security, agent and tool access, retrieval and embeddings, evaluation and safety testing, and contracts and compliance
- Prompt security: direct and indirect injection, jailbreaks, system prompt protection, and treating retrieved content and plugin output as untrusted
- Agent and retrieval controls: capability inventories, approval steps, sandboxing and rollback, tool calls logged against the user and tenant, access inheritance, and source citation
- What the vendor has to disclose: whether prompts, files and outputs train or tune models, whether there is an opt-out, the model provider, an AI bill of materials, and notice before a material model change
- Evaluation for hallucination, bias, privacy leakage and refusal behavior, with adversarial tests mapped to MITRE ATLAS and the OWASP LLM list, plus a worked example on an AI support agent
The last pages show the same review running on SAFE’s TPRM platform. See how SAFE handles TPRM.