SOC 2 Questionnaires Are Asking About Generative AI — Here’s What That Means for Mid-Market IT
If you’ve filled out a SOC 2 vendor security questionnaire in the last 12 months, you’ve probably noticed a new section near the bottom: something about generative AI, large language models, or AI sub-processors. A year ago that section didn’t exist. Now it’s showing up on questionnaires from enterprise procurement teams, cyber insurers, and prospective customers running their own vendor due diligence.

The question isn’t theoretical anymore. If your organization uses ChatGPT, Microsoft Copilot, GitHub Copilot, or any SaaS product with an embedded AI feature, you’re using generative AI in a business context — and your customers and partners increasingly want to know how you’re managing that risk. Most mid-market IT teams aren’t ready to answer those questions in writing, which is the actual problem.
This post walks through what these questionnaires are actually asking, where most organizations get caught flat-footed, and what you can do this week to be in a position to answer with something more credible than “we’re working on it.”
What SOC 2 Generative AI Questions Are Actually Asking
SOC 2 itself doesn’t define a generative AI control set — the Trust Services Criteria predate the current wave of LLM adoption. What’s happening instead is that procurement and security teams are appending their own AI-specific sections to standard questionnaires, or using AI governance addendums built on frameworks like the NIST AI Risk Management Framework or emerging ISO 42001 language.
These questions tend to cluster around four areas. First, inventory: do you know which AI tools your organization uses, including tools embedded in third-party SaaS products? Second, data handling: what customer or sensitive data is processed by those tools, and where? Third, vendor risk: have you assessed the AI vendors themselves — their data retention practices, model training opt-outs, and sub-processor disclosures? Fourth, policy and controls: do you have a written AI use policy, and can you show evidence that employees have been trained on it?
The inventory question is the one that catches most teams off guard, because the honest answer is often “we don’t have a complete list.” That’s a shadow AI problem masquerading as a questionnaire problem. If you haven’t already done a structured discovery of the AI tools running in your environment, the questionnaire response is the wrong place to start — the inventory is. See how to build an AI tool inventory without enterprise software if you need a starting point.
Why AI Sub-Processor Disclosure Is the Hardest Part
The sub-processor question is the one that trips up even well-prepared teams. When your organization uses a SaaS product — your CRM, your HR platform, your project management tool — and that product has added an AI feature powered by OpenAI, Anthropic, or a similar model provider, that model provider is now an AI sub-processor. Depending on your customer contracts and the data flowing through that SaaS tool, you may have an obligation to disclose it.
This is where the SOC 2 generative AI questionnaire intersects directly with data protection requirements. If you have EU customers or process data subject to GDPR, the sub-processor chain matters beyond the questionnaire itself. The EU AI Act adds another layer for certain use cases. But even setting aside the regulatory angle, enterprise procurement teams are asking because their own legal and security teams told them to — and “we haven’t looked at our SaaS vendors’ AI features” is not a defensible answer in writing.
The practical implication: your AI tool register needs to include not just the tools your employees are directly using (ChatGPT, Copilot, the AI writing assistant someone expensed last quarter), but also the AI features embedded in the SaaS stack you already manage. That’s a longer list than most teams expect. For context on how quickly that list grows in a real mid-market environment, the 43 Shadow AI Tools Found in 48 Hours case study is worth a read.
How to Answer the SOC 2 AI Risk Assessment Section
The AI risk assessment section of a vendor questionnaire is asking, in effect: have you done vendor-side due diligence on the AI tools and features you use? That means reviewing the AI vendor’s own documentation — their data processing agreements, model training opt-out controls, sub-processor lists, and security practices — and making a judgment about acceptable risk.
For a mid-market IT team without a dedicated GRC platform, this doesn’t have to be a formal risk model. What it does have to be is documented. A spreadsheet with columns for tool name, vendor, data classification of what’s flowing through it, data retention policy, sub-processor disclosures reviewed, and a risk acceptance sign-off is enough to show a questionnaire reviewer that you have a process. What you can’t do is answer “yes” to “have you assessed AI vendor risk” and have nothing to back it up if a follow-up conversation happens.
If you’re operating under or adjacent to EU AI Act obligations, vendor risk documentation becomes more specific — you need to know whether the tools you’re using fall under the Act’s high-risk or general-purpose AI provisions, and whether your vendors have published conformity documentation. The AIAAIC incident database and the EU’s own AI Act text are useful references, though for practical AI governance alignment guidance specific to mid-market IT, see InfoDefenders’ SOC2 framework page.
Building the Evidence Package a SOC 2 Questionnaire Requires
Answering a questionnaire is one thing. Backing it up with exportable evidence is what separates a credible response from a checkbox exercise. The four artifacts that matter most are: a current AI tool register (dated, with data classification), a written AI use policy (with a version date), vendor risk assessment records for each material AI tool or sub-processor, and some form of training or acknowledgment record showing employees have been briefed on the policy.
The export format matters. When a customer’s procurement or security team asks for evidence, they’re looking for something they can attach to a vendor file — a PDF, a spreadsheet, a signed policy. Verbal assurances don’t close enterprise deals. If your governance documentation lives in a shared drive folder that hasn’t been touched since someone created it, that’s not an evidence package; it’s a liability.
This is also where mid-market AI compliance runs into a structural gap. Enterprise organizations have GRC platforms that generate audit-ready exports. Most SMB and mid-market teams are managing this in a combination of spreadsheets, shared docs, and email threads — which means evidence is scattered and hard to assemble under deadline. The organizations that answer SOC 2 AI questionnaires confidently are typically the ones that built the register and policy infrastructure before the questionnaire arrived, not in response to it.
What to Do This Week
If a SOC 2 questionnaire landed in your inbox tomorrow, here’s the minimum you need to be able to answer it without writing “in progress” next to every AI row.
Start with the tool register. Spend two hours this week pulling together every AI tool your team uses directly — and then spend another hour going through your top ten SaaS vendors’ privacy policies or DPAs to find out which ones have added AI features or LLM sub-processors. Document what data categories touch each tool. Even a rough first draft of this list puts you ahead of most mid-market organizations.
Next, verify your AI use policy exists and is current. If you don’t have one, or the one you have predates your current AI tool usage, that’s a gap a questionnaire will expose immediately. A policy doesn’t need to be long — it needs to cover acceptable use, prohibited data inputs, and who owns AI governance decisions.
Finally, make sure you can export something. Whether that’s a PDF of your register, a dated policy document, or a vendor risk summary, you need artifacts you can hand to a procurement team. Download the free AI tool register template to get the register structure right without building it from scratch.
If you want a platform that keeps the register, policy, and evidence export in one place — and generates the kind of audit-ready output that actually closes vendor questionnaires — see how the InfoDefenders AI Governance Manager works. It’s built specifically for IT teams managing this without a dedicated compliance function.
The Questionnaire Is the Signal, Not the Problem
The SOC 2 generative AI questionnaire isn’t the thing you need to solve. It’s a signal that your customers and partners are now treating AI governance the same way they treat access controls and incident response — as a baseline expectation, not a differentiator. The organizations that will answer these questions cleanly 12 months from now are the ones building the register, the policy, and the evidence trail today.
The good news is that mid-market AI compliance doesn’t require an enterprise GRC budget. It requires a current tool inventory, a defensible vendor risk process, and documentation you can export when someone asks. None of that is out of reach for a two-person IT team — it just has to actually exist.
Sources