Manage Documents and Security Questionnaires

Learn how to manage AI system documents, requests, and security questionnaires in Sprinto using uploads, document requests, and questionnaire workflows.

The AI Systems module in Sprinto includes document and questionnaire management workflows that help organisations maintain governance evidence and conduct AI-related security reviews.

You can:

  • Upload governance documents and links

  • Request documents from vendors

  • Track request submissions

  • Create security questionnaires

  • Upload questionnaire templates

  • Fill and submit questionnaires

  • Maintain audit-ready evidence

These workflows help organisations centralise AI governance documentation and vendor assessment activities.


To access AI system documents and questionnaires:

  1. Log in to the Sprinto dashboard.

  2. Navigate to Data Library.

  3. Select AI Systems.

  1. Open an AI system from the All AI Systems tab.

  2. Select the Documents & links tab.

The Documents & links tab contains:

  • Documents

  • Requests


Documents Tab

The Documents tab displays all documents and evidence associated with the AI system.

This includes:

  • Uploaded documents

  • Submitted documents

  • Governance evidence

  • Compliance artefacts

  • Linked URLs

The table also displays:

  • Document status

  • Expiry dates

  • Sources

  • Request details

  • Added by information


Request Documents from Vendors

Sprinto allows organisations to request documents directly from AI vendors.

Start a Document Request

To request documents:

  1. Navigate to the Documents & links tab.

  2. Click Request.

  1. Select the required documents.

  2. Configure the request details.

  3. Click Preview & send request.

Sprinto sends the request after confirmation.


Configure Requested Documents

You can configure:

  • Required documents

  • Optional documents

  • Custom questionnaires

  • Notification recipients

  • Email templates

Examples of supported documents include:

  • SOC 2 reports

  • ISO 27001 certifications

  • GDPR agreements

  • HIPAA agreements

  • Security whitepapers

  • PCI DSS reports


Configure Request Emails

Sprinto supports configurable request emails.

You can configure:

  • Recipients

  • CC recipients

  • Submission notifications

  • Email subject

  • Email header

  • Email body

You can also configure whether selected documents are displayed inside the email.


Preview and Send Requests

Before sending the request:

  1. Click Preview & send request.

  2. Review the generated email.

  3. Click Send request.

Sprinto sends the document request to the vendor.


Requests Tab

The Requests tab displays all document requests associated with the AI system.

The table includes:

  • Request name

  • Request status

  • Submission details

  • Requested by information

  • Reminder tracking

This helps organisations track the lifecycle of document requests and submissions.


Sprinto supports manual uploads for governance evidence.

To upload documents:

  1. Navigate to the Documents tab.

  2. Click Add.

  1. Select Add document or link.

  2. Upload the required files or add URLs.

  3. Click Save.

The uploaded evidence is stored within the AI system record.


Supported Upload Types

Sprinto supports:

  • File uploads

  • URL-based evidence

  • Multiple uploads

Supported formats may include:

  • PDF

  • DOC/DOCX

  • XLS/XLSX

  • CSV

  • PPT/PPTX

  • ZIP

  • PNG

  • JPG

  • JSON

  • MSG


Add Multiple Documents

To upload additional evidence:

  1. Click Add another document/link.

  2. Repeat the upload process.

This helps organisations centralise all governance evidence for the AI system.


Security Questionnaires

Sprinto supports reusable AI security questionnaires for vendor and AI system assessments.

Questionnaires help organisations:

  • Standardise vendor assessments

  • Collect governance responses

  • Maintain audit-ready records

  • Evaluate AI security posture


Fill a Questionnaire

To complete a questionnaire:

  1. Navigate to the Documents & links tab.

  2. Click Add.

  1. Select Fill questionnaire.

  2. Choose the required questionnaire.

  3. Complete the questionnaire.

  4. Click Finish.

Sprinto saves the questionnaire submission within the AI system record.


Questionnaire Features

The questionnaire workflow supports:

  • Progress tracking

  • Search

  • Filters

  • Attachments

  • Additional comments

  • Draft saving

This helps teams complete large assessments efficiently.


Submit Questionnaire Responses

After completing all mandatory questions:

  1. Click Finish.

  2. Review the confirmation message.

  3. Click Submit.

Sprinto finalises the questionnaire response.

After submission:

  • Responses become read-only

  • Submission history is maintained

  • Evidence remains linked to the AI system


Create a Custom Questionnaire

Sprinto supports CSV-based questionnaire creation.

Add a Questionnaire

To create a questionnaire:

  1. Navigate to the Questionnaire tab inside AI Systems.

  2. Click Create custom questionnaire.

  1. Download the CSV template.

  2. Populate the questionnaire.

  3. Upload the CSV file.

Additional configuration options appear after the upload.


Configure Questionnaire Metadata

After uploading the questionnaire:

  1. Configure the questionnaire details.

  2. Click Preview & add questionnaire.

You can configure:

  • Questionnaire name

  • Recommended frameworks

  • Recommended vendor risk levels

  • Recommended vendor categories

The recommendation fields support multiple selections.


Preview Questionnaires

Sprinto validates uploaded questionnaires before publishing.

The preview includes:

  • Question IDs

  • Domains

  • Questions

  • Descriptions

  • Mandatory status

  • Question types

This helps organisations review the questionnaire structure before publishing.


Publish a Questionnaire

After validating the questionnaire:

  1. Click Add questionnaire.

The questionnaire becomes available for:

  • AI vendor assessments

  • Document request workflows

  • Due diligence reviews


Questionnaire Recommendations

Questionnaires can be recommended based on:

  • Compliance frameworks

  • Vendor risk levels

  • Vendor categories

This helps organisations standardise governance workflows across different AI systems.


AI Governance Best Practices

When managing AI governance evidence:

  • Maintain updated compliance documents

  • Use standardised questionnaires

  • Periodically review uploaded evidence

  • Configure document expiry tracking

  • Centralise governance artefacts

  • Reuse questionnaires across vendors

  • Track request completion regularly


Last updated