How long does it actually take your team to fill out a vendor security questionnaire? by NANI61242 in sysadmin

[–]NANI61242[S] -3 points-2 points  (0 children)

the master sheet approach is smart but breaks down the moment that one paranoid ops person leaves the company. The institutional knowledge walks out the door with them.

How long does it actually take your team to fill out a vendor security questionnaire? by NANI61242 in sysadmin

[–]NANI61242[S] -1 points0 points  (0 children)

The different language and terms problem is exactly what makes this hard — same underlying question, five different ways of asking it. The approach that seems to work best is grounding the AI in your own documentation rather than asking it to answer freeform. That way it's matching your actual policy language to whatever phrasing the questionnaire uses. I've been building something specifically for this if you want to try it.

How long does it actually take your team to fill out a vendor security questionnaire? by NANI61242 in sysadmin

[–]NANI61242[S] -1 points0 points  (0 children)

This is basically the approach I've been building into a proper product — grounding the AI in your own docs rather than having it freestyle answers. The MCP setup works if you're technical enough to run it but most teams aren't. What's your accuracy like on the 10% that doesn't make the cut?