SanctumShield · Agentic Governance for the Other 99%

MSP AI Trust Questionnaire — 10 Questions to Ask Your Managed Service Provider

Audience: mid-market organizations (50–2,000 employees) whose IT is run by a managed service provider — and providers who want to answer before they're asked.

Why this exists. When your IT is outsourced, your provider's remote-management platform runs with the highest privileges on every machine you own — and those platforms are now shipping AI into alert triage and scripting. You didn't pick that AI, you can't see it, and you can't turn it off. But the compliance obligation is still yours — outsourcing IT does not transfer it. These ten questions are how you see past your provider, and how a good provider proves you don't need to.

How to use the guidance. Under each question: ✅ Good answer (what a mature provider can show) and 🚩 Watch out for (the red flag). This is a decision aid, not a pass/fail certification — no score here "certifies" a provider.

Scope — who this is for, and who's who

Use it for: a security review, a renewal, onboarding a new provider, or answering a cyber-insurance renewal questionnaire. About 20 minutes.

Keep the three parties distinct — most of the confusion in these conversations comes from asking one party a question only another can answer:

This is one half of a pair. These ten are what you ask your provider. The other ten — the AI Vendor Trust Questionnaire — are what your provider should be asking their platform vendor (and what any buyer asks any AI vendor). Ask your MSP these ten; then ask whether they've asked their vendor the other ten.

Are you the provider? Answer these before you're asked — the MSP AI Disclosure is the fill-in answer sheet that resolves all ten in advance and turns them into a trust asset.


How to use this questionnaire — in plain English

What this is: ten questions to ask the company that runs your IT, so you can tell whether AI is operating in your environment under control — or under nobody's — even if you are not a security expert.

Why the wording is precise (and why that helps you): each question and its "good answer" note is worded to demand something you can actually inspect — a policy, a record, an owner, a date — not a reassuring sentence. A provider that wants to look compliant can say "we monitor AI" and "we have human oversight" without producing a thing. The wording below is built to get past that.

How to use it (about 20 minutes):

  1. Copy the ten questions into a plain email or your security-review doc (there is a ready-to-send version at the bottom).
  2. Read each answer against the ✅ good answer and 🚩 watch out for notes below it. A useful answer resolves to something you can inspect: the control, the artifact, the owner, and when it was last exercised.
  3. Pay special attention to the three non-negotiables — questions 2, 7, and 8 (control what arrives · stop it fast · know where our data goes).
  4. If you accept a weak answer, write down who accepted it and why. That is your record.

What this is NOT (the honest limits):


1. What AI-driven features are currently active in our environment — and how do you learn when your platform vendor adds one?

2. When your platform vendor ships a new AI feature, how much notice do you get — and what happens between that notice and it running on our endpoints? (non-negotiable)

3. Before an AI feature that can execute scripts or take action reaches our systems, what is your approval process — and where do we enter it?

4. Can AI-driven actions be scoped or disabled for our organization specifically — or is it one setting across your whole client base?

5. Can you produce a record of AI-initiated actions in our environment — what acted, on which asset, when, and under whose authority?

6. Is a technician reviewing AI-generated scripts before they execute in our environment — or does generated code run unreviewed?

7. If the AI misfires, can you disable it for our organization or a single endpoint — without degrading the rest of the service? (non-negotiable)

8. When an AI feature processes our data, where does it go? (non-negotiable)

9. If your platform vendor or its AI subprocessor is breached, how many hours until we hear from you?

10. Who at your company is the named owner accountable for AI behavior in client environments?


Also worth asking

If your provider is a security provider (MSSP) — two more

When the provider is a security provider, two things change: the AI doesn't just draft scripts — it can isolate hosts, disable accounts, and suppress alerts (autonomous action against production) — and the MSSP often produces your compliance evidence, so the AI can end up grading its own homework.


How to read the answers

Count the ✅s, but don't turn it into a certificate. Use this rule of thumb:

Email wrapper (copy-paste)

▼▼▼ COPY BELOW ▼▼▼ Subject: AI in our environment — 10 questions for our provider

Hi [provider],

As part of our security review, we're asking the same ten questions about AI running in our environment. Straight, specific answers — a policy, a record, an owner, a date — help us move quickly. Where a control isn't available yet, just say so and note the plan.

  1. What AI-driven features are currently active in our environment — and how do you learn when your platform vendor adds one?
  2. When your platform vendor ships a new AI feature, how much notice do you get, and what happens between that notice and it running on our endpoints?
  3. Before an AI feature that can execute scripts reaches our systems, what is your approval process, and where do we enter it?
  4. Can AI-driven actions be scoped or disabled for our organization specifically, or is it one setting across your whole client base?
  5. Can you produce a record of AI-initiated actions in our environment — what acted, on which asset, when, and under whose authority?
  6. Is a technician reviewing AI-generated scripts before they execute in our environment, or does generated code run unreviewed?
  7. If the AI misfires, can you disable it for our organization or a single endpoint without degrading the rest of the service? What's the time-to-effect, who's authorized, and when was it last tested?
  8. When an AI feature processes our data, who receives it, under what terms, retained how long, and is any of it used for training?
  9. If your platform vendor or its AI subprocessor is breached, how many hours until we hear from you?
  10. Who at your company is the named owner accountable for AI behavior in client environments?

Thank you, [name] ▲▲▲ COPY ENDS ▲▲▲

Guardrails honored

Sources

© PIGENAI LLC · SanctumShield · sanctumshield.com · This is an educational template, not legal advice or a compliance certification.