Skip to main content

Questionnaires

The Questionnaires module answers the security questionnaires other companies send you: a CAIQ, a SIG, a customer's own spreadsheet. It uses AI that drafts each answer from your evidence and shows its work. You upload the questionnaire, the AI drafts grounded answers with citations, your team reviews and approves, and you export the finished copy to send back.

This guide covers the whole lifecycle, one stage at a time.

Questionnaires hub
The Questionnaires hub: a card for each questionnaire with its status, question count, and an answered-progress bar, above a KPI row (Total, Draft, Ready, In progress) and a search and filter bar.

The lifecycle at a glance

A questionnaire moves through six stages. Each has its own page in this guide:

  1. Upload and parse. Add the questionnaire file, and SolveGRC extracts the questions into a reviewable list.
  2. Generate answers. The AI drafts a grounded, cited answer for every question.
  3. Review and approve. Your team checks each draft, edits, and approves in the Review Center.
  4. Register evidence and export. Approved answers become reusable evidence, and you download the answered copy to return.

The status badge on each card tracks where a questionnaire is: Draft → Parsing → Ready → In progress → In review. A questionnaire reaches In review on its own once every question has an answer, and that is the finish line the module drives you to. Sending the completed copy back to whoever asked is a manual step: you download it and reply. There is no "Submit" button to hunt for.

Before you start

The AI drafts answers from the evidence you have already given SolveGRC, so the quality of your answers depends on what is in your library.

Upload your evidence first

Load your policies, standards, prior audit reports, and completed questionnaires into Documents before you generate answers. The AI retrieves from that library to ground each response. With an empty library it has nothing to cite, and it will tell you the evidence does not cover the question.

You will also need:

  • Access to the module. Questionnaires appears in the sidebar only if your role has read permission for it, and creating or parsing questionnaires needs create permission. If you do not see it, ask an administrator.
  • An active subscription. The module is gated behind your plan.

How the AI keeps itself honest

Every drafted answer carries three trust signals you will see throughout the review flow, so you are never asked to trust a black box:

  • Confidence. The model's own read on how well the evidence supported the answer, shown as a percentage.
  • Citations. Each claim quotes the exact passage it came from, and SolveGRC checks whether the quote actually appears in the cited source. A citation that contradicts its source is flagged in red.
  • Integrity. A hallucination check that flags an answer whose citations do not hold up, so a shaky draft cannot slip through as if it were verified.

These are explained in detail on the Review and approve page. The point to carry with you is simple: the AI drafts, and a person approves. Nothing leaves the Review Center as approved until someone signs off on it.