LLM Vendor Risk Questionnaire - Safe Security

Template

LLM Vendor Risk Questionnaire

46 questions across 12 domains for LLM and AI vendors, split into 20 Core and 26 Enhanced.

Conventional vendor security questions alongside AI-specific ones. Every question names the evidence to ask for and has a response field and a notes area.

What’s inside

  • Twelve domains, including model and data provenance, prompt and interaction security, agent and tool access, retrieval and embeddings, evaluation and safety testing, and contracts and compliance
  • Prompt security: direct and indirect injection, jailbreaks, system prompt protection, and treating retrieved content and plugin output as untrusted
  • Agent and retrieval controls: capability inventories, approval steps, sandboxing and rollback, tool calls logged against the user and tenant, access inheritance, and source citation
  • What the vendor has to disclose: whether prompts, files and outputs train or tune models, whether there is an opt-out, the model provider, an AI bill of materials, and notice before a material model change
  • Evaluation for hallucination, bias, privacy leakage and refusal behavior, with adversarial tests mapped to MITRE ATLAS and the OWASP LLM list, plus a worked example on an AI support agent

The last pages show the same review running on SAFE’s TPRM platform. See how SAFE handles TPRM.