Legal playbook · AI Employee: Lex

Customer Security Questionnaire Support

Questionnaire turnaround < 2 days

The problem

Customer security questionnaires are the enterprise-sales tax. Every prospect over $50K sends 100-400 questions covering the same ground as SOC 2 + ISO 27001 + your trust page. Sales pings security; security pings engineering; engineering complains about writing the same 47-word answer for the fourth time this quarter. Deals stall 2-6 weeks waiting for the response. Answers get copy-pasted from stale docs. The evaluator sees a slow, inconsistent security posture.

At a glance
Trigger
Form
Approvals
Security review before send
What it does
Writes to your systems
Systems
Vanta · Drata · Security KB
How it feels in production

An hour-by-hour walkthrough.

Deal DEAL-9812 arrives at security review: Acme Corp attached a 240-question CAIQ-derived questionnaire. Lex opens it, parses each question, and matches against the answer library — a maintained corpus of every question you've answered in the past, plus your trust page, SOC 2, ISO 27001, DPAs, and internal security documentation. For each question: - 180 questions: high-confidence match to a prior answer or public document. Lex fills in with citation to the source. - 42 questions: partial match, needs light editing (product-specific detail, date update). Lex drafts and flags for review. - 18 questions: no clean match — genuinely new questions or vendor-specific asks. Lex drafts a best-effort answer and routes to the subject-matter expert (data-handling to CISO, resilience to CTO). Reviewer opens the draft. 180 questions already answered with citations they can spot-check. 42 to lightly edit. 18 to actually think about. What was a two-week grind becomes a two-hour review. Once submitted, every answered question feeds back into the library. Next quarter's Acme-like questionnaire has 220 high-confidence matches instead of 180. The library gets sharper by simply being used.
How it works

Step by step.

  1. 01

    Parse the questionnaire into individual questions

    Handle CAIQ / SIG / VSA / custom XLSX / PDF / web forms. Extract each question with its section, response-format expectation (yes/no, freeform, N/A allowed). Normalise to a common question record.

    Document parsing · Questionnaire format library
  2. 02

    Match against the answer library

    Every prior questionnaire answer + trust portal contents + SOC 2 + ISO 27001 + internal security docs. Match by semantic similarity + question intent. Confidence score per match.

    Answer library · Reasoning · Trust portal · Compliance docs
  3. 03

    Draft answers by confidence tier

    High confidence: filled with citation. Medium confidence: drafted with edit flag. Low or no confidence: routed to the SME with a draft-if-possible + the specific gap in the source material.

    Reasoning · Confidence model · SME routing
  4. 04

    Reviewer edits + submits

    Security lead reviews the draft. Edits inline. Approves. Submits in the required format (some customers want XLSX back, some their portal, some PDF). Lex delivers.

    Web UI · Excel export · Portal submission
  5. 05

    Feed accepted answers back to the library

    Every submitted answer feeds the library with the question + response + reviewer edits. Trust-portal source materials updated where the library reveals a gap. Library gets sharper over time.

    Answer library · Trust portal · Compliance docs
Systems and wiring

What you connect to make this run.

Answer library · Trust portal

read+write

Master corpus: every past questionnaire answer, published trust-portal contents, SOC 2 / ISO 27001, DPAs, subprocessor list. Read for matching; write with new answers accepted through this playbook.

Salesforce · HubSpot

read+write

Opportunity context: customer, deal value, timeline. Write questionnaire status back to the opportunity so sales sees blocker state. Deal-level SLA (typically 5 business days) drives urgency.

Slack · Teams · Email

read+write

Reviewer + SME notifications. Draft handoff for edits. Final submission notification to sales. SME question-answering happens in Slack thread; answer becomes library material.

Vendor portals · DocuSign · Email

write

Submit in the format the customer wants — some portals (Whistic, OneTrust) accept API submission, some want XLSX upload, some accept PDF via email. Lex delivers per each.

What changes

Before and after, honestly.

Time from questionnaire receipt to submission
Before
10-30 business days
After
1-3 business days
Security team hours per questionnaire
Before
12-40 hours
After
2-4 hours (review only)
% of questions answered without SME involvement
Before
20-40%
After
75-90% (library-driven)
Deals delayed by security review
Before
30-50%
After
Under 10%
Frequently asked

Answers about this playbook.

What if the customer's questionnaire asks about features we don't have?

Lex drafts an honest N/A with brief context ("Feature X is on our 2027 roadmap; compensating control is Y"). SME reviews and adjusts. Never fabricates a yes.

How does it handle contradictory answers we've given historically?

Surfaces the contradiction to the reviewer with both past answers + dates + who approved each. Reviewer resolves and the library update creates a single source of truth for next time.

Can we use it for RFPs and RFIs too?

Yes — same mechanism. RFPs have more freeform business questions; those route more often to SMEs, but the security portion (usually 30-40% of an enterprise RFP) is handled the same way.

How does confidentiality work when answers are reused across customers?

The answer library never quotes another customer's questionnaire or contract. Source materials are internal + public (trust portal, SOC 2, DPAs). Customer-specific claims (e.g., "we integrate with your specific system") stay in that customer's answer only.

What about very early-stage prospects (no NDA yet)?

Lex distinguishes public-safe answers from NDA-required ones. For pre-NDA questionnaires, only trust-portal-level answers auto-fill; NDA-gated answers wait for the NDA to complete before drafting.

See it run on your data.

Free plan, no credit card. Connect the systems this playbook needs and run it against a past event first.