Client Questionnaires
The Client Questionnaires module is used to manage incoming client questionnaires. It allows AI to automate responses by drawing on your golden questionnaire, your controls, and your policies, reducing the manual work involved in completing each questionnaire.
When the AI runs against an incoming questionnaire, it looks at three sources, in priority order:
- Your golden questionnaire: This is the primary source the AI uses and should be in place before you upload incoming questionnaires. (See the next section for guidance.)
- Controls: The AI uses your implemented controls as a source when answering questions. It assumes that if the control is in place, you are operating in line with it.
- Policies: The AI will only use the text of your most recent approved policies. Draft or unapproved policies will not be referenced.
If the AI cannot find supporting evidence across these sources, it will not fabricate an answer. The module is designed to confirm positive security outcomes; where the supporting content is not there, the question will be left for you to answer manually.
Building Your Golden Questionnaire
The golden questionnaire is a static document of your 'golden' answers to common security questions. It is the first source the AI checks when answering an incoming questionnaire, so the quality of this document directly drives the quality of AI-generated responses.
Format and structure:
- File type: Excel or CSV, in a simple tabular format - your CE team member will provide you with guidance on formatting
- Columns: one column for the Question and one column for the Golden Answer.
- Keep it clean: one question per answer. Avoid adding multiple versions of the same question with slightly different answers, as this dilutes quality.
To upload the golden questionnaire:
Navigate to Settings → Trust → Documents.
Upload your file under the Golden Questionnaire File section.
Important: The AI does not learn from edits you make to individual questionnaires. To improve future answers, update the golden questionnaire itself.
Uploading an Incoming Client Questionnaire
To upload a questionnaire, navigate to your client questionnaires tab on the left-hand navigation bar.
Click the ‘Add questionnaire’ button in the top right-hand corner
- Fill in all the relevant information and upload the Excel or CSV file of the questionnaire and click Submit.
Note: Incoming questionnaires work best in editable, structured formats with the question in one column and an empty answer column alongside it. Locked CSV files or files with complex formatting may not process correctly. Questionnaires delivered through client portals or as non-editable PDFs cannot currently be automated through the module.
The status of the questionnaire will reflect the progress the AI has made on the questionnaire, and then once you have completed a full review and accepted all the answers, the status will update again.
Available statuses:
- Processing: The AI is extracting the questions from the uploaded document, and gathering the answers from your golden questionnaire, the controls you have in your environment, and your policies.
- Pending: The AI has suggested answers for all applicable questions and it is ready for your review. No edits have been made yet.
- In progress: You have started to review the AI answers and are making any necessary edits
- Expiring: The due date is coming up in 1 week.
- Overdue: If you haven't completed the questionnaire within the due date you set
- Failed: The questions could not be extracted from the uploaded document, or there was an error.
- Complete: You have completed a full review of the questionnaire, accepted all of the answers provided by the AI and made any changes or additions needed
When the AI has successfully filled in the questionnaire, you will receive a notification informing you that the questionnaire is ready for review: 'The questionnaire [Name of Questionnaire] has been successfully processed and is ready to be reviewed.'
Reviewing and Approving AI Answers
Once the AI has finished, open the questionnaire to review the extracted questions, the AI-generated answers, and the status of each.
Key points when reviewing:
- Answer format: the AI returns answers in a Yes + description format as standard.
- AI indicator: AI-generated answers display an AI sparkles icon. If you edit an answer manually, the icon is removed to show the answer has been updated by a person.
Available statuses:
Pending: The AI was unable to draw an answer from your Golden questionnaire, your controls, or your policies
Ready for review: The AI has completed the first pass to answer the question, and now it is ready to be reviewed, updated if necessary, and approved.
Approved: Once a team member has reviewed the answer and is happy with the response, the answer can be marked as approved.
When all answers have been reviewed and marked as approved, the status of the questionnaire updates to Complete and is ready to be exported and returned to your vendor.
Exporting the Completed Questionnaire
When all answers are finalized, you can export the questionnaire back into the original format it was received in.
Open the questionnaire and select Export — the AI places the answers back into the correct cells of the original file, so you can return the completed questionnaire to the client without copying and pasting answers manually.
Still have questions? Reach out to our support team via the Support Center for assistance.