Free: The AI Security Questionnaire Self-Check for MSPs
A client, insurer or enterprise procurement team sends you an AI security questionnaire. Could you answer it today?
Run the 12 questions below against your MSP. No email required, no gate — it's free because most MSPs fail it, and knowing that is worth more than a mailing list. Count your NOs as you go.
Section 1 — Policy (the first thing they ask for)
- Do you have a written AI acceptable-use policy that staff have actually seen — not a paragraph buried in your general IT policy?
- Does it name the tools staff may and may not use (ChatGPT, Copilot, Gemini, transcription bots) — and has it been updated in the last 6 months?
- Does it explicitly prohibit client data entering public AI tools? If a helpdesk engineer pastes a client's config into a chatbot tonight, has a rule been broken — or just taste?
Section 2 — Evidence (where questionnaires kill deals)
- Can you evidence AI security training — dated, named attendees, repeatable — for every technical member of staff?
- Could you produce that evidence within one working day if a renewal questionnaire demanded it?
- Do you keep a register of AI tools in use across your own business — including the ones staff adopted without asking?
Section 3 — Client-facing exposure
- Do you know which of your clients' environments have AI features switched on (Copilot for M365, AI note-takers in Teams meetings, CRM AI assistants)?
- If a client asked "is our data training someone's model?", could you answer in writing with confidence?
- Do your MSA/contract terms say anything about AI use in service delivery? Anything at all?
Section 4 — Incident readiness
- Would a data leak via an AI tool trigger your incident process? Does the process even recognise that category?
- Does anyone own AI risk in your business — a named person, not "all of us"?
- Has AI use ever appeared on your risk register or board agenda?
Scoring
0–2 NOs: better than 90% of the MSPs we talk to — formalise it before renewal season.
3–6 NOs: you'd survive a questionnaire with a week's warning, not with a day's. The gaps are documentation, not intent.
7+ NOs: you are one enterprise procurement email away from a very bad week. Start with the policy (question 1) — it's an afternoon's work.
What next
The scored 40-point version of this — mapped question-by-question to what insurers and procurement actually send, with an acceptable-use policy starter you can issue this week — is AISEC-CHECK (£19). Its price is credited against your first full purchase.
Prefer the full answer? AISEC-101 (£99) is the training framework + evidence pack that turns questions 4–6 into YESes, white-label deployment to your own clients included. Everything carries a 14-day no-quibble refund.
Secordit Intelligence Ltd — regulatory and AI-governance intelligence for UK MSPs. This self-check is informational, not legal advice.