Your Enterprise Customer's Security Questionnaire Now Asks About AI — Are You Ready?

Your Enterprise Customer's Security Questionnaire Now Asks About AI — Are You Ready?

7/28/2026 · Compliance365

If you sell software to enterprise customers, you already know the drill: a security questionnaire lands in your inbox before the contract does. What's changed in the last year is what's on it.

Buried among the usual encryption, access control and business continuity questions, there's now a new section — AI governance. What AI do you use in your product? Whose data does it touch? Who reviews its output? What happens if it gets something wrong?

Most vendors have a strong product and a strong answer to everything else on the form. This section is the one that stalls the deal.


1 Why this happened so fast

Enterprise procurement and GRC teams didn't add an AI section because it's trendy — they added it because their own customers, regulators and boards started asking them. A large enterprise buying your SaaS product is, from their risk team's point of view, extending their own AI supply chain into your codebase. If your product embeds a language model, calls a third-party AI API, or uses AI to make any decision that touches their data, that's now their problem too — and they know it.

The EU AI Act's extraterritorial reach, ISO 42001 becoming an actual, auditable standard rather than a set of AI ethics principles, and a run of very public "the AI feature did something nobody signed off on" stories have all pushed this from "nice to ask" to "standard line item" in about eighteen months.

2 What's actually being asked

Strip away the varying wording and almost every enterprise AI questionnaire section is asking the same five things:

They ask What they're really checking
"What AI/ML capabilities does your product use?"Do you even know your own AI footprint — internal features and embedded third-party models?
"Whose data trains or is processed by these models?"Could our data end up training a model we never approved, or leak to a third party?
"Is there human review before an AI decision affects a customer?"Is there a human-in-the-loop control, or does the model just act unsupervised?
"How do you assess and mitigate AI risk?"Is there an actual risk process, or is this the first time anyone's written it down?
"Do you hold ISO 42001, or an equivalent AI governance certification?"Can we skip re-verifying all of the above ourselves, because a third party already did?

That last question is the one that matters most commercially. Answered "yes, and here's the certificate," the rest of the section closes in one line. Answered with four paragraphs of prose written on the spot by whoever picked up the questionnaire, it turns into a follow-up call, a security review, and weeks added to the deal cycle — if it doesn't quietly become the reason the deal goes to a competitor instead.

3 ISO 42001 is built to answer exactly this

ISO 42001 is the world's first certifiable AI management system standard — the AI equivalent of what ISO 27001 did for information security. It doesn't ask you to prove your AI is perfect. It asks you to prove it's governed: that you know what AI you're running, who's accountable for it, what could go wrong, and how you'd catch it.

Practically, that's four things a vendor questionnaire is fishing for anyway:

  • An AI system register — every AI capability in your product (and every third-party model you call), what data it touches, who owns it, and its risk rating.
  • Human-in-the-loop controls — documented review gates wherever an AI output reaches a customer or makes a decision on their behalf.
  • An AI risk assessment process — not a one-off exercise, a live process that runs every time a new model or feature is added.
  • Evidence, not assurances — an auditor's sign-off that this is actually happening, not a policy document nobody's followed since it was written.
The shift to notice: this used to be a differentiator — something you'd mention to stand out. It's rapidly becoming table stakes, the same way SOC 2 went from "nice to have" to "can't get in the door without it" for enterprise SaaS a few years ago. The vendors who get ahead of it now are the ones who won't be scrambling when it's no longer optional.

Why this doesn't need to be its own project

If you're already running ISO 27001, most of the scaffolding ISO 42001 needs already exists — a risk register, a management review cycle, an internal audit programme, evidence retention. ISO 42001 extends that same machinery to your AI systems specifically, rather than starting from nothing. Built inside Microsoft 365 (SharePoint as the register, evidence captured as it's generated rather than assembled after the fact), most organisations get to AI-readiness in 6–10 weeks — faster again if it's layered onto an existing ISMS.

Next steps

If an enterprise deal is currently stalled on an AI governance question, or you'd rather have the answer ready before it's asked:

Share this article: Share on LinkedIn

Found this useful? Get the ISO/Privacy/AI readiness checklists.

Browse resources

Ready to take the next step?

ISO 42001 AI Governance

AI Management System — model inventory, risk assessment, oversight, and policy using your existing Microsoft 365 tools.

Learn more Book a free call

Free monthly digest

Get the monthly Australian compliance digest

Practical updates on ISO 27001, Essential Eight, Privacy Act and AI governance — delivered once a month. No spam, unsubscribe any time.

No spam. Unsubscribe any time. We never share your email.

Keep reading

Microsoft Teams