The CyberVadis AI prefill feature is designed to significantly reduce the time it takes to complete your questionnaire. By analysing the information security documentation you upload to the platform, our in-house AI engine automatically fills in the relevant controls and attaches the corresponding evidence on your behalf, so you can focus your energy on reviewing and validating, rather than answering everything from scratch.
How AI prefill works
AI prefill works in three steps:
Step 1: upload your documentation
Upload your company's information security documentation to your document library on the platform. The more comprehensive your documentation, the more controls the AI engine will be able to prefill. Useful documents to upload include:
Information security policies and procedures
Risk assessment and risk treatment reports
Access control and user management records
Incident response and business continuity plans
Audit reports and compliance certificates
Employee security awareness training records
Technical configuration records and screenshots
There is no minimum number of documents required, the AI engine works with whatever you provide and prefills the controls it can match confidently.
Step 2: the AI engine analyses your documents
Our AI engine reads the relevant passages in your uploaded documents in real time, identifies which questionnaire controls your existing evidence already addresses, and automatically:
Selects the appropriate answer options for each matched control
Attaches the relevant evidence document to that control
Nothing is stored or retained on the AI side beyond the active transaction. Your document content is never used to train our AI models. See [How CyberVadis protects your data: overview] for full details on our AI data commitments.
Step 3: review, validate, and complete
Once the AI prefill has run, your questionnaire will contain a mixture of prefilled and unanswered controls. Your role is to review what the AI has done, complete what it has not, and confirm that everything is accurate before submitting.
What you need to do
AI prefill does the heavy lifting, but the accuracy of your final submission is your responsibility. Here is how to work through your prefilled questionnaire:
For controls the AI has prefilled:
Review the selected answer and confirm it accurately reflects your company's actual practices
Check that the evidence attached is the correct document for that control and that it is current and valid
If everything looks correct, mark the question as complete using the green toggle at the top of the question page
If anything needs correcting, update the answer or swap the evidence before marking complete
For controls the AI has not prefilled:
These are controls where the AI engine could not find a confident match in your uploaded documents
Answer these manually as you would in a standard questionnaire, uploading supporting evidence where required
Mark each question as complete once you are satisfied with your answer and evidence
The AI engine is designed to be conservative, it will only prefill a control when it finds a confident match in your documentation. However no automated system is perfect. Always review prefilled answers critically rather than accepting them without checking. An inaccurate prefilled answer that is submitted without correction will be scored on the basis of what is declared, not on what the AI intended.
Is AI prefill opt-in?
Yes. AI prefill bypassed at the initial step after the qualification. If you prefer to complete your questionnaire entirely manually, simply skip that step.
How AI prefill interacts with other prefill scenarios
If you are completing a reassessment or hold a valid ISO 27001 certificate, your questionnaire may already contain prefilled answers from those sources before AI prefill runs. In this case, AI prefill will supplement the existing prefilled content rather than replace it - filling in controls that are not already addressed by your reassessment history or ISO certification scope.
For a full overview of all prefill scenarios and how they interact, see [Why do some questions already have responses?].
Frequently asked questions
Is my data used to train the AI model?
No. Your document content is never used to train our AI models. AI processing is transient - nothing is stored beyond the active transaction.
Does AI prefill guarantee a higher score?
No. The AI prefill accelerates the completion process but does not affect scoring. Your score is determined by the accuracy and quality of your declared answers and supporting evidence, reviewed by our human analysts. Prefilled answers that are not supported by credible evidence will be scored accordingly.
What if the AI prefill attached the wrong document to a control?
Review each prefilled control carefully and replace any incorrectly attached documents before submitting. See [How to upload, manage, and delete documents] for instructions on managing your evidence.
Questions
If you have questions about AI prefill or need help activating the feature, contact your account manager or at account.management@cybervadis.com.
