HECVAT Category
General AI Questions
General AI Questions covers controls and questions related to that domain. It outlines expectations institutions typically require from vendors. The category helps assess risk posture and operational maturity. It provides structure for consistent evaluation during security reviews.
Assessment Questions
Does your solution have an AI risk model when developing or implementing your solution's AI model?
This question is asking whether your AI solution incorporates a formal risk management framework or methodology specifically designed for AI systems during development or implementation.
Can your solution's AI features be disabled by tenant and/or user?
This question is asking whether your software solution allows administrators to turn off artificial intelligence (AI) features at different levels of granularity - specifically at the tenant level (affecting an entire organization) and/or at the individual user level.
Have your staff completed responsible AI training?
This question is asking whether your organization has implemented formal training for staff on responsible AI practices. Responsible AI training covers ethical considerations, bias mitigation, transparency, privacy protection, and other principles that ensure AI systems are developed and deployed in ways that are fair, accountable, and beneficial to society.
Please describe the capabilities of your solution's AI features.
This question is asking you to describe the AI capabilities in your product or service. The assessor wants to understand what AI features exist, what they're designed to do, how they work, and what benefits they provide to users.
Does your solution support business rules to protect sensitive data from being ingested by the AI model?
This question is asking whether your AI solution has mechanisms to prevent sensitive data (like personally identifiable information, financial data, health information, etc.) from being fed into the AI model during training or inference.
ResponseHub is the product I wish I had when I was a CTO
Previously I was co-founder and CTO of Progression, a VC backed HR-tech startup used by some of the biggest names in tech.
As our sales grew, security questionnaires quickly became one of my biggest pain-points. They were confusing, hard to delegate and arrived like London busses - 3 at a time!
I'm building ResponseHub so that other teams don't have to go through this. Leave the security questionnaires to us so you can get back to closing deals, shipping product and building your team.

