New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Ongoing operations

Approved answer library and auto-fill

Security questionnaires from prospects and auditors tend to ask overlapping questions. Answering the same question from scratch every time is the real cost, not the questionnaire itself, and it is also the easiest place for an answer to quietly drift from what is actually true.

Transcript

Security questionnaires ask the same questions from every prospect and every auditor. Answering the same question from scratch every time is the actual cost, not the questionnaire itself.

Every approved answer lives in one library: the question, the approved answer, and who approved it. Add one directly, and it's saved straight in, ready for the next questionnaire that asks something close to it.

Nothing here is written by an AI or locked in once saved: edit an answer as your policy changes, or delete one outright, and every questionnaire matched against it afterward sees the update.

A new questionnaire can start from a condensed starter template, so even an empty library has something real to answer against on day one, rather than a blank page.

Indexing a published document turns it into searchable evidence. This AI Governance Policy gets embedded right now, on the spot, so a question with no library match can still search its actual content later.

Paste text, or upload a vendor's questionnaire file directly, CSV, Excel, or Word, and any question matching one already in the library is filled in instantly, exact matches first, close-but-not-identical wording second, both flagged so nothing is accepted blind.

That policy is searchable the moment it finishes indexing: this question has no library match, but its content is close enough to a real passage in the policy to surface it here, extracted verbatim, confidence-capped below a library answer, and still needing a human to accept it.

Accepting or editing an answer writes it straight back into the library, and a question with no match at all can also auto-answer from your own live scan evidence. The first questionnaire you complete becomes the seed that auto-fills every one after it.

Why this is required

This is a practical extension of the same accountability principle behind a trust center: an approved, current answer that is reused consistently is more defensible than the same question being answered slightly differently by different people over time.

Vendor due diligence under ISO 27001 A.5.20 is only as good as the answers behind it; a library of approved, attributable answers is what keeps those answers accurate and current rather than reinvented under time pressure.

What EuroCompliant does

Every approved answer lives in one library: the question, the approved answer, and who approved it. Nothing here is written by an AI; every entry starts as something a person on your team actually wrote and signed off on.

A new questionnaire can start from a condensed starter template, so an empty library still has something real to answer against on day one rather than a blank page.

Pasting text, or uploading a vendor's questionnaire file directly (.csv, .xlsx, or .docx), matches each question against the library: an exact match auto-fills instantly, a close-but-not-identical match is flagged for a quick check, and accepting or editing any answer writes it straight back into the library. The first questionnaire completed becomes the seed that auto-fills the next one. A question with no library match at all can still surface an extracted suggestion from your own published documents, clearly labelled and never auto-submitted.

A question can also be answered directly from your own platform evidence, not just from past answers: something like "are databases encrypted at rest?" is checked against your actual, current scan results and answered accordingly, clearly labelled as evidence-based rather than library or extracted. The uploaded file itself is never stored. It is read once to pull out the questions, then discarded.

Walking through it

1

Add or import approved answers

Start from a starter template, or add answers directly as your team approves them.

Open /answer-library →
2

Paste text, or upload a questionnaire file

CSV, Excel, or Word all work. Matching questions auto-fill instantly; everything else is flagged for review.

Open /answer-library →
3

Accept or edit each answer

Every accepted or edited answer is written back into the library for next time.

Open /answer-library →
4

Export the completed questionnaire

Download a clean CSV, XLSX, or DOCX with every question, answer, confidence, and source column filled in.

Open /answer-library →

The law

Frequently asked

Are the answers generated by AI?

No. Every answer in the library starts as something a real person on your team wrote and approved. Matching against the library, against your platform evidence, or against your documents is automated; writing the underlying answer or generating the evidence itself is not.

What happens to a question with no match at all?

It is left blank for you to answer directly. It may also surface an extracted suggestion from your own published documents, always labelled as extracted and never submitted automatically.

Is the uploaded questionnaire file kept?

No. The file is parsed in memory to extract its questions and is never written to storage. Only the extracted questions and their answers are saved.

Why do some questions briefly show "Checking your documents..."?

A question with no library or evidence match is looked up against your indexed documents in the background rather than holding up the import. It resolves within a few seconds and the review table updates on its own.

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial