Free: The AI Security Questionnaire Self-Check for MSPs

A client, insurer or enterprise procurement team sends you an AI security questionnaire. Could you answer it today?

Run the 12 questions below against your MSP. No email required, no gate — it's free because most MSPs fail it, and knowing that is worth more than a mailing list. Count your NOs as you go.

Section 1 — Policy (the first thing they ask for)

  1. Do you have a written AI acceptable-use policy that staff have actually seen — not a paragraph buried in your general IT policy?
  2. Does it name the tools staff may and may not use (ChatGPT, Copilot, Gemini, transcription bots) — and has it been updated in the last 6 months?
  3. Does it explicitly prohibit client data entering public AI tools? If a helpdesk engineer pastes a client's config into a chatbot tonight, has a rule been broken — or just taste?

Section 2 — Evidence (where questionnaires kill deals)

  1. Can you evidence AI security training — dated, named attendees, repeatable — for every technical member of staff?
  2. Could you produce that evidence within one working day if a renewal questionnaire demanded it?
  3. Do you keep a register of AI tools in use across your own business — including the ones staff adopted without asking?

Section 3 — Client-facing exposure

  1. Do you know which of your clients' environments have AI features switched on (Copilot for M365, AI note-takers in Teams meetings, CRM AI assistants)?
  2. If a client asked "is our data training someone's model?", could you answer in writing with confidence?
  3. Do your MSA/contract terms say anything about AI use in service delivery? Anything at all?

Section 4 — Incident readiness

  1. Would a data leak via an AI tool trigger your incident process? Does the process even recognise that category?
  2. Does anyone own AI risk in your business — a named person, not "all of us"?
  3. Has AI use ever appeared on your risk register or board agenda?

Scoring

0–2 NOs: better than 90% of the MSPs we talk to — formalise it before renewal season.
3–6 NOs: you'd survive a questionnaire with a week's warning, not with a day's. The gaps are documentation, not intent.
7+ NOs: you are one enterprise procurement email away from a very bad week. Start with the policy (question 1) — it's an afternoon's work.

What next

The scored 40-point version of this — mapped question-by-question to what insurers and procurement actually send, with an acceptable-use policy starter you can issue this week — is AISEC-CHECK (£19). Its price is credited against your first full purchase.

Prefer the full answer? AISEC-101 (£99) is the training framework + evidence pack that turns questions 4–6 into YESes, white-label deployment to your own clients included. Everything carries a 14-day no-quibble refund.

Secordit Intelligence Ltd — regulatory and AI-governance intelligence for UK MSPs. This self-check is informational, not legal advice.