SanctumShield · Agentic Governance for the Other 99%

AI Vendor Trust Questionnaire — 10 Questions

Audience: mid-market buyers (50–2,000 employees) evaluating any product that ships an AI agent.

Is your IT outsourced? Start with the MSP AI Trust Questionnaire — the ten questions to ask your managed provider. This one is what your provider should be asking their platform vendor; the two are a pair.

Why this exists. Mid-market organizations can't build SPIFFE, token exchange, or policy engines themselves — but they can refuse to buy from vendors who didn't. Procurement is the mid-market's real enforcement point: you can't build the controls into someone else's product, so make the vendor prove they already did. Ask these ten questions in your RFP, security review, or renewal. Paste them verbatim into an email; a straight, specific answer is a good sign, and evasion is data.

How to use the guidance. Under each question: ✅ Good answer (what a mature vendor says) and 🚩 Watch out for (the red flag). This is a decision aid, not a pass/fail certification — no score here "certifies" a vendor.


How to use this questionnaire — in plain English

What this is: ten questions to ask any company selling you an AI agent, so you can tell a serious, safe vendor from a risky one before you buy — even if you are not a security expert.

Why the wording is precise (and why that helps you): each question and its "good answer" note is worded exactly because it maps to recognized security frameworks (OWASP, CSA, NIST). That precision is what lets you compare vendors fairly and hold them to a real standard — not just a sales pitch.

How to use it (about 20 minutes):

  1. Copy the ten questions into your RFP or a plain email (there is a ready-to-send version at the bottom).
  2. Read each answer against the ✅ good answer and 🚩 watch out for notes below it.
  3. Pay special attention to the three non-negotiables — questions 2, 4, and 6.
  4. If you accept a weak answer, write down who accepted it and why. That is your record.

What this is NOT (the honest limits):


1. Does each AI agent have its own unique identity, or do agents share API keys?

2. If my agent's credential leaks, what can an attacker reach with it?

3. Can I set exactly what tools and data my agent may use — enforced outside the model?

4. What does your agent do when it's denied access to something?

5. Can I see a complete log of every action my agent took — and is it tamper-evident?

6. What's your kill-switch time — how fast can I fully stop a misbehaving agent?

7. Do you support autonomy levels and human-approval gates?

8. How do you vet the third-party tools/plugins your agent can call?

9. Will you notify me within 24 hours if your AI subprocessor chain is breached?

10. Which framework do you map to — OWASP Agentic Top 10, CSA ATF, NIST AI RMF?


How to read the answers

Count the ✅s, but don't turn it into a certificate. Use this rule of thumb:

RFP / email wrapper (copy-paste)

▼▼▼ COPY BELOW ▼▼▼ Subject: AI agent security — 10 questions before we proceed

Hi [vendor],

Before we move forward, we ask every AI-agent vendor the same ten security questions. Straight, specific answers help us move quickly. Where a control isn't available yet, just say so and note the roadmap.

  1. Does each AI agent have its own unique identity, or do agents share API keys?
  2. If our agent's credential leaks, what can an attacker reach with it?
  3. Can we set exactly what tools and data our agent may use, enforced outside the model?
  4. What does your agent do when it's denied access to something?
  5. Can we see a complete, tamper-evident log of every action our agent took?
  6. What's your kill-switch time to fully stop a misbehaving agent?
  7. Do you support autonomy levels and human-approval gates?
  8. How do you vet the third-party tools/plugins your agent can call?
  9. Will you notify us within 24 hours if your AI subprocessor chain is breached?
  10. Which framework do you map to — OWASP Agentic Top 10, CSA ATF, or NIST AI RMF?

Thank you, [name] ▲▲▲ COPY ENDS ▲▲▲

Guardrails honored

Sources

© PIGENAI LLC · SanctumShield · sanctumshield.com · This is an educational template, not legal advice or a compliance certification.