Your Enterprise Customer's Security Questionnaire Now Asks About AI — Are You Ready?
7/28/2026 · Compliance365
If you sell software to enterprise customers, you already know the drill: a security questionnaire lands in your inbox before the contract does. What's changed in the last year is what's on it.
Buried among the usual encryption, access control and business continuity questions, there's now a new section — AI governance. What AI do you use in your product? Whose data does it touch? Who reviews its output? What happens if it gets something wrong?
Most vendors have a strong product and a strong answer to everything else on the form. This section is the one that stalls the deal.
1 Why this happened so fast
Enterprise procurement and GRC teams didn't add an AI section because it's trendy — they added it because their own customers, regulators and boards started asking them. A large enterprise buying your SaaS product is, from their risk team's point of view, extending their own AI supply chain into your codebase. If your product embeds a language model, calls a third-party AI API, or uses AI to make any decision that touches their data, that's now their problem too — and they know it.
The EU AI Act's extraterritorial reach, ISO 42001 becoming an actual, auditable standard rather than a set of AI ethics principles, and a run of very public "the AI feature did something nobody signed off on" stories have all pushed this from "nice to ask" to "standard line item" in about eighteen months.
2 What's actually being asked
Strip away the varying wording and almost every enterprise AI questionnaire section is asking the same five things:
| They ask | What they're really checking |
|---|---|
| "What AI/ML capabilities does your product use?" | Do you even know your own AI footprint — internal features and embedded third-party models? |
| "Whose data trains or is processed by these models?" | Could our data end up training a model we never approved, or leak to a third party? |
| "Is there human review before an AI decision affects a customer?" | Is there a human-in-the-loop control, or does the model just act unsupervised? |
| "How do you assess and mitigate AI risk?" | Is there an actual risk process, or is this the first time anyone's written it down? |
| "Do you hold ISO 42001, or an equivalent AI governance certification?" | Can we skip re-verifying all of the above ourselves, because a third party already did? |
That last question is the one that matters most commercially. Answered "yes, and here's the certificate," the rest of the section closes in one line. Answered with four paragraphs of prose written on the spot by whoever picked up the questionnaire, it turns into a follow-up call, a security review, and weeks added to the deal cycle — if it doesn't quietly become the reason the deal goes to a competitor instead.
3 ISO 42001 is built to answer exactly this
ISO 42001 is the world's first certifiable AI management system standard — the AI equivalent of what ISO 27001 did for information security. It doesn't ask you to prove your AI is perfect. It asks you to prove it's governed: that you know what AI you're running, who's accountable for it, what could go wrong, and how you'd catch it.
Practically, that's four things a vendor questionnaire is fishing for anyway:
- An AI system register — every AI capability in your product (and every third-party model you call), what data it touches, who owns it, and its risk rating.
- Human-in-the-loop controls — documented review gates wherever an AI output reaches a customer or makes a decision on their behalf.
- An AI risk assessment process — not a one-off exercise, a live process that runs every time a new model or feature is added.
- Evidence, not assurances — an auditor's sign-off that this is actually happening, not a policy document nobody's followed since it was written.
Why this doesn't need to be its own project
If you're already running ISO 27001, most of the scaffolding ISO 42001 needs already exists — a risk register, a management review cycle, an internal audit programme, evidence retention. ISO 42001 extends that same machinery to your AI systems specifically, rather than starting from nothing. Built inside Microsoft 365 (SharePoint as the register, evidence captured as it's generated rather than assembled after the fact), most organisations get to AI-readiness in 6–10 weeks — faster again if it's layered onto an existing ISMS.
Next steps
If an enterprise deal is currently stalled on an AI governance question, or you'd rather have the answer ready before it's asked:
- Need an answer this quarter, not an 8–14 week programme? See our AI vendor risk assessment — a faster, scoped alternative that upgrades into full certification later
- Explore our ISO 42001 services
- Try the ISO 42001 readiness checklist
- Book a 15-minute intro call to map your path to certification
Found this useful? Get the ISO/Privacy/AI readiness checklists.
Browse resources