B BROCENT

How to Use Gemini to Draft Client Security Questionnaire and RFP Responses

How to answer 200-row security questionnaires in a day and a half instead of two weeks — building an answer library from real policies and audit output, and the verification step no AI can take over.

Two people reviewing printed business documents at an office desk
The short answer: Build an answer library from your real policies, audit output and evidence, keep it in Drive, and let Gemini draft each questionnaire answer from those sources rather than from general knowledge. Drafting time drops from days to hours. What does not change is that a named person still has to confirm every control claim is actually true before it goes back.

The security questionnaire arrives attached to a deal you have already half-won. Two hundred rows, some of them asking whether you enforce multi-factor authentication on administrative accounts, some asking for your data-retention schedule, one asking for your most recent penetration test report. The deadline is Friday. Nobody at your company owns compliance, and the person who understands your infrastructure best is also the person who has to keep it running this week.

So it gets answered the way these always get answered: by pattern-matching against last year's responses, guessing at the ones nobody is sure about, and marking a few as "in progress" in the hope that nobody follows up. It takes two weeks of stolen hours and it comes back with follow-up questions anyway.

Gemini genuinely helps with this, and it helps with a specific half of it. Writing the prose of an answer — clear, complete, in the register a security reviewer expects — is fast work for a language model. Knowing whether the answer is true is not, and that gap is where the actual risk sits.

Why Security Questionnaires Take Two Weeks and Still Come Back With Follow-Ups

The delay is rarely about writing. It is about four other things.

The answers live in people's heads. What your backup retention actually is, whether that one legacy server still has local admin accounts, who has access to the production database — this is known, but not written down anywhere a salesperson can reach.

Every questionnaire asks the same things differently. One asks "Do you enforce MFA?", the next asks "Describe your authentication controls for privileged access", the third wants it mapped to a framework control number. The underlying fact is identical and the answer has to be rewritten each time.

Nobody knows which answers are still current. Last year's response set is the obvious starting point and also a trap: your stack has changed, a tool was replaced, a policy was drafted and never finished. Reusing an answer that was true in 2025 is how a company ends up contractually committed to a control it does not have.

The evidence is missing. A reviewer who accepts "yes, MFA is enforced" today may ask for a screenshot, a policy document or an audit report next quarter. If nobody has actually checked, the answer and the evidence part ways quietly.

The follow-up questions come back because reviewers can tell the difference between an answer written from evidence and an answer written from optimism. Vague, hedged or copy-pasted responses generate more questions, not fewer.

Building an Answer Library Gemini Can Actually Draft From

The output quality is decided almost entirely by what you point the model at. A questionnaire drafted from general knowledge produces plausible, generic, unverifiable text — exactly the kind that triggers follow-ups.

Which Three Inputs Actually Matter?

Your written policies. Access control, data retention, incident response, acceptable use, vendor management, business continuity. Even short, imperfect policy documents are far better than nothing, because they let the model quote what you have committed to rather than what companies typically commit to.

Your audit and assessment output. The most recent security assessment, vulnerability scan summary, or configuration review — the documents that say what is actually configured, not what is intended. This is the input that separates a defensible answer from a hopeful one.

Your evidence inventory. A simple list of what you can produce on request: MFA enforcement settings, a backup restore test record, an offboarding checklist, training completion records. Answers that cite available evidence are the ones reviewers stop probing.

Keep all three in one Drive folder with a clear structure, because that folder is the thing you will maintain for years. The library is the asset here; the drafting is the easy part. The same discipline that keeps a document library organised and correctly tagged is what keeps this from decaying into a folder nobody trusts.

Should You Do This in Google Docs or Buy a Questionnaire Platform?

For most SMEs, start in Docs and Drive. Gemini's side panel in Docs and Drive can work against files you point it at, which is the whole mechanism this needs — check what your specific Workspace edition includes, because AI features and their availability change and differ by plan. NotebookLM is worth knowing about too, as a way to work strictly from a fixed set of source documents.

A dedicated questionnaire platform earns its cost at a different scale: when you are answering several questionnaires a month, need answer approval workflows and expiry dates, or want automatic mapping between framework control sets. Below that volume the maintenance burden of the platform exceeds the benefit, and the answer library is the same work either way.

A Worked Example — From a Blank Questionnaire to a Reviewed, Evidenced Response Set

A 120-person software supplier receives a 180-row questionnaire from an enterprise prospect. Their answer library is a Drive folder holding six policy documents, last quarter's security assessment report, and a one-page evidence index.

First pass — draft everything. The questionnaire is pasted into a Doc, and Gemini is asked to draft each answer using only the library files, in the requested format, and to mark clearly any question it cannot answer from those sources. That last instruction is the important one. Roughly 60% come back as usable drafts, 25% as drafts needing a specific fact the model does not have, and 15% flagged as unanswerable from the library.

Second pass — the gap list. The 15% is the useful output of the whole exercise. These are the questions where the company has no policy, no evidence, or no control. They go to the IT manager as a list, and answering them honestly takes an afternoon: three are "yes, but undocumented", two are "no, and we should", one is "not applicable to our architecture".

Third pass — verification. Every answer asserting a control gets checked against a real setting or document by someone who can see the system. This is the step that cannot be skipped and cannot be delegated to the model. It is faster than it sounds, because the drafts have already grouped the questions by control area.

Fourth pass — sign-off. One named person reads the completed set and signs it. Their name matters more than their title: an answer set with an owner is one someone will keep current.

Elapsed time is roughly a day and a half instead of two weeks, and the residue is more valuable than the questionnaire — a gap list and a library that makes the next one faster.

AI-Drafted Answers vs a Questionnaire Platform vs Answering From Scratch

  • Speed on the first questionnaire — AI-drafted wins. There is no implementation project and no data migration before you get value.
  • Speed at ten questionnaires a month — A platform wins. Approval workflows, answer expiry and control-set mapping are exactly what it exists for.
  • Cost — Answering from scratch is nominally free and by far the most expensive in senior time. AI drafting is the cheapest real option.
  • Consistency across questionnaires — A platform wins narrowly; AI drafting from one library is close behind, provided everyone uses the same library.
  • Catching what you do not have — AI drafting wins, and this is underrated. Ask it to flag what it cannot answer and you get a control gap list nobody had written down.
  • Accuracy of the claim itself — None of them wins. No tool knows whether MFA is enforced on your tenant. That is a verification step, and it is human either way.

The choice is really about volume. The answer library is the durable asset regardless of which you pick.

The Line You Must Not Cross

There is a difference between drafting an answer and asserting a control, and it is worth stating plainly because AI makes crossing it effortless.

A drafted answer is a proposal about what your posture is. It becomes an assertion the moment it is sent, and in a contractual context an assertion about controls is something you can be held to — through a warranty in the master agreement, an audit right, or simply the reputational cost when an incident reveals a control that was never in place.

Three rules keep this safe. Never send an answer nobody has verified. Never let "in progress" describe something that has not started. And never reuse an answer set without re-checking the claims, because the answers age even when the questions do not.

This is the argument for grounding answers in a real audit rather than in memory. An assessment that walks your environment and produces a scored, exportable report — the eight-domain shape our IT security auditor is built around — turns "we believe MFA is enforced" into a statement with a date and a document behind it. That is the difference between an answer that survives a follow-up and one that does not.

Getting This Right — Evidence, Attestation Risk, and When to Bring in IT

Three things worth settling before the next questionnaire arrives.

Where the library lives and who can see it. Your policies, audit findings and evidence index together form a fairly complete description of your security posture and its weak points. That belongs in a properly permissioned Drive location, not a shared folder half the company inherited access to years ago. Restrict it, review the access list, and check whether the AI features enabled in your Workspace edition process content in a way your client contracts allow.

Who signs, and what happens when they are wrong. Name an owner for the answer set. Give them the authority to answer "no" — most attestation problems start with a salesperson softening a "no" into a "partially" to keep a deal moving.

Closing the gaps rather than describing them. A gap list is only useful if something happens to it. Where the honest answer is "no, and we should", that is remediation work with a cost and a date, and it is exactly what our AI+ support practice and managed IT support exist to carry — including the unglamorous parts like MFA coverage, offboarding discipline and patch evidence that questionnaires ask about most. Brocent has run managed IT and security across Asia since our founding in Beijing in 2007, with headquarters in Singapore and a Hong Kong office since 2016.

Frequently Asked Questions

Is it acceptable to answer a security questionnaire with AI assistance?

Yes, in the same sense that it is acceptable to use a word processor. Reviewers care whether the answers are accurate and evidenced, not which tool typed them. What is not acceptable is sending answers nobody verified — and that would be equally unacceptable if a person had written them from memory.

What happens if an AI-drafted answer turns out to be wrong?

The same thing that happens if a human-drafted answer is wrong, which is the point: you are accountable for the claim regardless of who drafted it. Depending on the contract, a materially false control statement can mean a breach of warranty, a failed audit, or a terminated relationship. This is why verification is a required step rather than a best practice.

Can we reuse last year's answers?

As a drafting input, yes — they are one of the better sources you have. As a final answer, no, not without re-checking. Environments change more than people remember, and a stale "yes" is the most common way a company ends up committed to a control it no longer has.

How do we keep the answer library from going stale?

Give it a review cadence tied to something that already happens — your annual assessment, your insurance renewal, or a quarterly IT review. Date every document, and record which questionnaire each answer was last used in. A library nobody has touched in eighteen months is a liability, because people trust it.

Who should sign off on the final response set?

One named person with enough visibility to know whether the claims are true — usually the IT manager, the operations lead, or whoever owns the security relationship. The salesperson who owns the deal should not be the same person who approves the security answers, for the obvious reason.

Does this work for RFP security sections and due-diligence requests too?

Yes. RFP security sections, client due-diligence questionnaires and insurer application forms all draw on the same library, which is a large part of why building it is worth the effort. The format changes; the underlying facts do not.

Where to Start

Take the last questionnaire you answered and the policies you already have, put them in one folder, and ask Gemini to draft the same answers using only those files — flagging anything it cannot support. Compare its output against what you actually sent. The overlap tells you how much of your answering is already grounded; the gap list tells you the rest. If that list turns out to be longer than you expected, it is a remediation conversation rather than a documentation one — get in touch.

Share:

Ready to take action?

Turn these insights into a roadmap for your business.

Book a 15-minute no-obligation consultation with our APAC IT experts. We'll review your current setup and provide a tailored IT roadmap within 24 hours.

📋

Free Checklist

10 Critical Checks Before Expanding IT to Greater China

PIPL compliance, network segmentation, bilingual helpdesk setup, and more — everything your IT team needs before Day 1 in China.

Request the checklist →

📬 Monthly Asia IT Insights

China compliance updates, cybersecurity alerts, and IT tips for APAC teams — once a month.

No spam. Unsubscribe anytime.