What is the VSA questionnaire?
Where you'll meet it
The VSA is the questionnaire tech-sector buyers reach for when they want a standard heavier than a homepage badge but lighter than a full SIG Core. It exists because a group of companies decided the industry could not keep answering incompatible questionnaires and pooled a shared one. If your buyer is a technology firm running a modern vendor-security programme, the VSA is a common default.
The version your buyer sent is what you should answer against; the coalition maintains the questionnaire and updates it over time, and buyers pin to whichever release fits their internal review pack.
What it covers
The VSA covers the standard security perimeter — security policy and governance, data handling and protection, application security, and incident response — and, in the current generation, AI use as well. The AI content is not a bolt-on: reviewers use it to test whether the vendor has a governance model behind the AI they ship, not simply an engineering one behind the code.
Treat the AI questions in a VSA with the same evidence discipline as those in a CAIQ or SIG: cite the artefact, name the owner, date the record. The reviewer is the same person reading the same shape of answer across every questionnaire on their desk; what looks defensible in one place looks defensible everywhere.
Answer it from a record
Import your controls and vendors, answer each question cited to a sealed record, and hold open honestly the ones you cannot yet ground. When the reviewer spot-checks, the citation opens; when a gap is real, the interim control and the date read as maturity, not evasion. This is the motion Hael runs: one record, sealed documents, cited answers, honest gaps.