Microsoft Teams

Faster than full certification

A security questionnaire is asking about your AI. You need an answer this quarter, not an 8–14 week programme.

Nearly every company now has AI vendors in its register whether it planned to or not — and enterprise procurement teams have quietly added an AI governance section to their security questionnaires. Full ISO 42001 certification is the right answer if you're building or embedding AI as a core part of your product. If you just need a defensible, evidence-backed answer to a live procurement question, a scoped AI vendor risk assessment gets you there faster.

  • Weeks, not months
  • Fixed price
  • Procurement-ready output
  • Upgrades to ISO 42001 later
Book a Scoping Call Compare to Full ISO 42001

Why this exists as its own engagement

Enterprise procurement and GRC teams didn't add an AI section to their vendor questionnaires because it's trendy — they added it because their own customers, regulators and boards started asking. If your product embeds a language model, calls a third-party AI API, or uses AI to make any decision touching customer data, that's now part of your customer's own AI supply chain risk. Most vendors have a strong answer to every other section of the questionnaire and stall on this one specifically.

Not every business needs full ISO 42001

If AI is a small, incidental part of your product rather than a core feature, full certification is genuine overkill for the problem in front of you right now.

Deals don't wait 8–14 weeks

A stalled enterprise deal usually needs an answer inside the sales cycle, not after it — a scoped assessment fits inside a live procurement timeline.

It's a natural first step, not a dead end

Everything captured in the assessment — the AI system register, the risk ratings, the vendor mapping — becomes the foundation if you move to full ISO 42001 certification later.

What the assessment covers

AI system & vendor register

Every AI capability in your product and every third-party model or API you call — what data it touches, who owns it, and its risk rating.

Subprocessor & data-flow mapping

Where does the data actually go — which models, which subprocessors, which jurisdictions. The exact question procurement teams ask and most vendors can't answer cleanly.

Human-in-the-loop review

Whether — and where — a human reviews AI output before it reaches a customer or informs a decision about them.

Existing certification cross-check

If your AI providers already hold SOC 2 or ISO 27001, we capture that evidence so you're not re-proving what's already been proven upstream.

A procurement-ready answer pack

A document built specifically to answer the AI section of a vendor security questionnaire — not a generic policy PDF nobody in procurement will read end to end.

A clear upgrade path

If a bigger deal or a recurring pattern of these questions makes full ISO 42001 the right next step, this work carries forward directly into that engagement.

Common questions

How is this different from full ISO 42001?

ISO 42001 is a certifiable management system covering your entire AI governance programme. This assessment answers a specific, live procurement question — faster and at a fraction of the cost.

Will this satisfy every customer's questionnaire?

It answers the substance of what's being asked with real evidence. Some enterprise buyers will still eventually want formal certification — this buys you the time to get there on your own schedule.

What if we later need full certification?

Nothing from this engagement is wasted — the AI register and risk mapping become the starting point for an ISO 42001 programme rather than a parallel exercise.

Related

ISO 42001 Full AI governance certification Free AI Governance Checklist Score your readiness in 12 minutes Why questionnaires changed The AI vendor questionnaire shift

Deal stalled on an AI question right now?

A 30-minute scoping call tells you exactly what's needed and how fast it can be turned around.

Book a Scoping Call