extrasphere.

AI Questionnaire
First Draft Kit

Use your policies. Reference the evidence. Know what needs checking.

Extrasphere AI Questionnaire First Draft Kit

Turn the AI questions in a client questionnaire into a source-referenced draft, with clear gaps for review.

Free starter edition · 27 September 2026

Start with one real task

Use this kit when a client asks how your business uses AI, handles client information, reviews AI outputs, or manages AI suppliers. It is designed for operations, IT and client-assurance leads at agencies and professional-service businesses.

Start with a small section of the questionnaire. You need the exact questions, relevant current policies or procedures, and access to a business AI tool your organization has approved for that information. Existing approved answers can help, but may be stale or apply to a different service.

The prompts are plain text and designed for most capable AI assistants your organization approves. File handling and available features depend on the provider, account and configuration. We checked the workflow in Gemini Pro and Microsoft 365 Copilot Auto using fictional, pasted source excerpts; other assistants have not been verified here. Always validate the workflow with a non-confidential example and check the model's output before relying on it for client work.

Your first session

1. Read the fictional example in 03-WORKED-EXAMPLE.md to see what a useful answer looks like.

2. Gather only relevant, permitted documents. Keep client secrets, personal information and unnecessary confidential details out of the exercise.

3. Open your approved AI tool. Attach or reference the documents using the features available in your account. Give each source a short ID, title, version/date and scope.

4. Open the Prompts section in START-HERE.html or 01-PROMPTS.md. Run prompts 1–5 in order, in the same conversation. Review each result before moving on.

5. Use 02-RESPONSE-RECORD.md to record the answers and unresolved questions. Small batches are easier to check; start with five questions.

6. Check citations in the original documents. Ask the relevant owner to confirm operational claims. Transfer only approved answers into the client's form.

If the tool cannot read a source, ask it to say so. Where your organization's rules permit, paste the relevant passage with its source ID and location. Do not let the tool guess the missing contents.

What you should leave with

A draft answer for each question you supplied.

A source reference for supported statements.

Explicit missing information and conflicting evidence.

A short list of questions for the people who can confirm the facts.

A documented requirement is not proof that the activity takes place. A policy requiring review does not establish that every output has actually been reviewed. Unsupported answers stay unresolved until a person supplies and checks the evidence.

Check the review pack for invented sources, too. In testing, a model treated a scope statement in the chat as a separate “Scope Document” even after being told not to. Delete any citation that you cannot match to an actual source you supplied.

When you need a repeatable process

If questionnaires keep coming, the Extrasphere AI Security Questionnaire Response Kit provides a guided local dashboard for reusable draft answers, supporting-evidence references and review gaps. It includes a concise report and a full record. It does not automatically connect to your AI assistant; bring reviewed text into the dashboard yourself.

Explore the response kit

If the exercise reveals missing AI rules, ownership or a tool inventory, the AI Governance Toolkit is a more suitable next step.

Explore the governance toolkit

See each product page for its current availability and purchase terms.

Use and scope

You may use and adapt this free starter for your organization's internal work. Consultants may use the method in client engagements, keeping each client's information separate. It does not grant resale rights to Extrasphere materials or access to paid products. Paid kits have separate license terms.

This kit supports drafting and review. It does not verify operating controls, certify compliance, or replace accountable human approval. Extrasphere is independent and is not affiliated with or endorsed by Google or Microsoft.

Five prompts for a source-referenced first draft

Copy one complete prompt at a time. Replace the bracketed inputs. Keep the outputs and your corrections in the same conversation. These instructions guide the model; they cannot guarantee that it follows them. Check the original evidence yourself.

1. Establish the sources and scope

2. Map the questions to evidence

3. Draft the answers

4. Challenge the draft

5. Prepare the human review pack

Final human check

Check each original citation and scope, resolve material gaps, confirm claims about practice with the owner, and ensure the wording matches what the client asked. Retain a dated copy of what was approved and submitted. Model self-review does not replace this step.

Response record

Duplicate this block for each original client question. It can be copied into a document or your team's existing records.

Questionnaire context

Company:

Client/reference:

Service/product and scope:

Questionnaire version/date:

Response owner:

Due date:

Sources used, with versions/dates:

Question entry

Question ID:

Exact question:

Required answer format/limit:

Draft client-facing answer:

Supporting source IDs and sections/pages:

Evidence status: Supported / Partial / Missing / Conflicting / Scope unclear

Facts still requiring confirmation:

Suggested owner role:

Approval status: Draft / Hold for review / Approved / Rejected

Actual reviewer:

Actual approval date:

Approved wording:

Submission date and version, if submitted:

Before submission

[ ] Every original question is accounted for, including subquestions.

[ ] Each citation was checked against its original document.

[ ] No cited document was inferred from chat context or invented by the model.

[ ] Evidence applies to the service, period and scope being assessed.

[ ] Operating claims were confirmed; policy requirements were not treated as proof.

[ ] Material conflicts and missing facts were resolved or accurately disclosed.

[ ] Required yes/no fields were decided by an accountable reviewer.

[ ] Unnecessary confidential details were removed without hiding relevant facts.

[ ] Only approved wording was transferred to the client's form.

[ ] Reviewer, date and the final submitted version were retained.

Worked example: a client asks about AI

All organizations, documents and facts below are fictional. This example illustrates the desired behavior; it is not a recorded Gemini or Copilot test.

Context and sources

Meridian Studio is answering questions about its design service. It provides two source passages:

S1 · AI Acceptable Use Policy · v1.2 · 1 September 2026 · section 3: “Staff must not enter client-confidential information into an AI tool unless the tool and the particular use have been approved by the operations lead.”

S2 · Creative Review Procedure · v2.0 · 10 September 2026 · section 4: “The project lead must review AI-assisted client deliverables before release.”

No tool configuration records, release logs or completed reviews have been supplied.

Question Q1

Client question: Do you have a documented policy restricting the use of client-confidential information with AI tools?

Draft: Yes. Our AI Acceptable Use Policy prohibits staff from entering client-confidential information into an AI tool unless the operations lead has approved both the tool and the particular use.

Source: S1, section 3.

Evidence status: Supported for the existence and content of a documented policy in the provided source. Human review must still confirm that this is the current approved policy and applies to the service.

Approval status: Draft. No reviewer decision supplied.

Question Q2

Client question: Are all AI-assisted client deliverables reviewed by a human before release?

Draft: HOLD FOR REVIEW.

Internal note: S2 requires project-lead review, but no operating evidence establishes that all relevant deliverables were reviewed. Do not select Yes solely from this policy.

Evidence status: Partial.

Owner question: Can the delivery lead confirm how this review operates, supply review records for the relevant scope and period, and identify any exceptions?

Possible wording after confirmation: Draft only after receiving that information. Describe any verified exceptions accurately.

Question Q3

Client question: Is client data excluded from model training by every AI supplier you use?

Draft: HOLD FOR REVIEW.

Internal note: Neither source establishes the full supplier list, contract terms, applicable products or account settings. A restriction on staff input does not prove how suppliers handle data.

Evidence status: Missing.

Owner question: Can IT provide the in-scope AI suppliers and products, applicable contractual commitments and relevant account-setting evidence, including exceptions?

Result

Three questions accounted for. One source-supported draft and two evidence gaps. Zero answers approved for submission. The useful result is knowing what can be supported and exactly what needs checking.

Reuse the work

When the team confirms facts, record the source, reviewer, scope and date. Check whether those facts remain current before using the answer again.

For a guided dashboard to organize reusable answers and evidence references, explore the Extrasphere AI Security Questionnaire Response Kit.