All resources
Written for: A customer sent an AI or security questionnaire with a deadline

The AI questionnaire your customer will send you

Enterprise buyers added an AI section to their vendor reviews. Here is what they are actually asking, what a good answer looks like, and what to do when the honest answer is "we do not have that yet."

A supplier's guide to the AI section that has appeared in enterprise vendor reviews — what each question is really asking, and what a credible answer looks like.


Why you got this

Nothing about your business changed. Your customer's process did.

Through 2026, enterprise procurement teams added an AI block to the vendor reviews they already ran. It shows up inside instruments most suppliers have seen before — the Standardized Information Gathering questionnaire, the Cloud Security Alliance's CAIQ, and the internal templates large companies build on top of them. If you have filled in a security questionnaire before, this is the same envelope with a new section inside it.

Two things follow from that, and they matter for how you respond.

It is not personal, and it is not a signal that they distrust you. Everyone in your category is getting it. The team that sent it is working through a supplier list.

It is also not optional. The AI block sits inside the review that gates the contract. An unanswered section is an open item on someone's tracker, and open items delay signature.

The good news is that most of these questions have short, factual answers. The difficulty is rarely writing the answer. It is that answering honestly requires knowing things about your own business that nobody has written down yet.


What they are actually worried about

Underneath thirty or forty questions there are four concerns. Recognising them makes the whole section easier to answer, because you can tell which questions are load-bearing and which are box-ticking.

  1. Does our data end up somewhere we did not agree to? In a model, in a log, in a subprocessor, in a human reviewer's queue.
  2. If your AI gets something wrong, who catches it? They want to know whether a person is in the loop, and where.
  3. Can you tell us what is actually running? Which models, whose, which version, and what happens when that changes without notice.
  4. If this goes wrong, will you tell us? Notification, logs, and whether anyone at your company owns the problem.

A questionnaire is a proxy for those four questions. Answers that speak to them read as competent even when the underlying practice is young.


The nine sections, annotated

Wording varies. The substance does not.

1. Data usage and model training

Is customer data used to train, fine-tune or improve any model? Is it used for human review or quality evaluation? Can we opt out?

What they are asking. Whether their confidential material becomes part of a model that later serves someone else — including a competitor.

A good answer names the specific tools, states the setting, and says where it is written down. "We use [tool] under a business agreement that excludes customer content from training; the training opt-out is confirmed in writing in our data processing agreement, section X. No customer data is submitted to any consumer-tier AI account."

A weak answer is a general assurance — "we take data privacy seriously and do not misuse customer data." It does not answer the question, and reviewers read it as a no.

What you need on hand. A list of the AI tools your business actually uses, and for each one, whether it is a business or consumer tier and what the contract says about training. Most suppliers discover at this point that the answer differs by tool, and that at least one tool is on somebody's personal account.


2. Model provenance and the AI supply chain

Which foundation models do you use, and from which providers? Do you host them, or call an API? List all AI subprocessors with access to customer data.

What they are asking. Your customer inherits every vendor you use. They are extending their own supply-chain review one layer down.

A good answer is a table: model, provider, hosted or API, what data reaches it, and whether that provider appears on your subprocessor list.

A weak answer names only the household-brand model and omits the smaller tools — the transcription service, the meeting-notes assistant, the support-ticket summariser. Those are subprocessors too, and omitting them is the kind of gap that surfaces awkwardly later.

What you need on hand. A current AI system inventory. This is the single most reused artifact in the whole exercise: it answers questions in at least four of these nine sections.


3. Retention, deletion and logging

How long are prompts, outputs and logs retained? Where? Can data be deleted on request, and does deletion propagate to subprocessors?

What they are asking. Whether their data has a defined end, and whether your deletion promise reaches everything downstream.

A good answer gives a number and a mechanism. "Prompts and outputs are retained for N days in [system], then deleted. Deletion requests are actioned within N days and passed to subprocessors under clause X."

A weak answer says "as long as necessary." Every reviewer has seen that phrase and none of them accept it.

What you need on hand. The actual retention setting in each tool — not the one you assume is set. These frequently default to longer than people expect.


4. Human oversight and automated decisions

Does AI make or materially influence decisions about individuals? Is there human review before an outcome takes effect? Can a person contest the outcome and reach a human?

What they are asking. Whether you have created an automated decision that carries legal consequences for someone — and, if so, whether a competent person can override it.

This is the section where an incorrect answer is most expensive, because it also engages obligations that apply to you directly and not only through your customer's contract.

A good answer distinguishes clearly between AI that drafts something a person then decides on and AI that decides. The first is common and easy to defend. The second requires you to describe the review route, who staffs it, and what authority they have to overturn the output.

A weak answer claims "a human always reviews everything" when the reality is that a human clicks approve on a queue of two hundred items. Reviewers probe this, and the follow-up question is usually how often does the human disagree?

What you need on hand. An honest map of where AI output goes straight into an outcome without anyone meaningfully looking at it.


5. Accuracy, hallucination and output controls

How do you evaluate output quality? What controls exist against fabricated content? How are users told the output is AI-generated?

What they are asking. Whether a confidently wrong answer can reach their customers with your name on it.

A good answer describes a control, not an intention: retrieval grounded in your own documents, a required citation, a confidence threshold that routes to a person, a review step before anything external goes out.

A weak answer describes prompt engineering as if it were a control. It is not, and reviewers who have been doing this for a year know it.


6. Bias and discriminatory outcomes

Has the system been tested for disparate impact across protected groups? How often, by whom, and what were the results?

What they are asking. Whether you have created discrimination exposure that they will inherit by association.

This section is short in most questionnaires and disproportionately important. If your AI touches hiring, credit, insurance, housing, education or access to a service, it is not a box-tick — there are jurisdictions where testing and disclosure are specific legal duties rather than good practice, and where the obligation lands on the deployer rather than the model provider.

A good answer states what was tested, against which groups, when, and what happened next. A weak answer asserts fairness because no complaint has been received.

What you need on hand. Whether any of your AI affects people's access to something. If it does, this is the question to work on before the questionnaire arrives, not after.


7. Governance and accountability

Do you have an AI policy? Who owns AI risk? Do staff receive AI training? Do you maintain an inventory of AI systems?

What they are asking. Whether AI at your company is governed or merely happening.

These four questions are the cheapest to fix and the most frequently answered badly. A named owner, a written policy that staff have actually seen, a training record, and an inventory — none of it requires a department, and having it changes how the rest of the questionnaire reads.

A good answer names a role and a date. "AI risk is owned by [role]; our AI acceptable-use policy was approved on [date] and is acknowledged by all staff at onboarding and annually."

A weak answer is "yes" with nothing behind it. If a reviewer asks to see the policy — and increasingly they do — a "yes" you cannot evidence is worse than an honest "not yet."


8. Incident response and notification

How would you detect an AI-related incident? What is your notification commitment to us, and in what timeframe?

What they are asking. Whether you would tell them, and how fast.

An AI incident is not only a breach. It includes a model producing harmful output at scale, staff pasting confidential material into a public tool, and a provider changing a model in a way that breaks your controls.

A good answer ties AI incidents into the incident process you already have and states a notification window. A weak answer treats AI as outside the existing process, which invites the follow-up: so nobody would notice?


9. Framework alignment

Do you align to ISO/IEC 42001, the NIST AI Risk Management Framework, or the EU AI Act? Are you certified? Can you share evidence?

What they are asking. Whether there is an external reference point behind your answers, so they do not have to take all of this on trust.

A good answer is precise about status, because this is where suppliers most often overstate and get caught. There is a real difference between certified by an accredited body, aligned to a framework, and assessed against one. Claiming the first when you mean the third is discoverable, and it contaminates every other answer you gave.

If you are working toward something, say so with a date. Reviewers respond well to "we have completed a structured assessment against ISO/IEC 42001 and NIST AI RMF and are closing the gaps on this timeline" — it is more credible than a bare yes, because it comes with detail a bluff would not survive.


The three that stop people

In practice, most suppliers move quickly through the questionnaire and then stall in the same three places.

"List every AI tool in use." Almost nobody can, first time. Tools arrive through individual sign-ups, free tiers and features switched on inside software you already had. The list you can produce from memory is reliably shorter than the real one.

"Is customer data used for training?" Easy for your main platform. Hard for the six smaller tools, where the answer depends on the tier and the contract, and where at least one is likely to be on a personal account.

"Who owns AI risk?" A question with no correct answer if nobody has been given the job. It is also the cheapest of the three to fix — it takes a decision, not a project.


When the honest answer is "not yet"

You will not be able to answer everything. Suppliers routinely assume a gap means losing the deal. It usually does not.

What loses deals is a confident answer that turns out to be wrong. Reviewers verify. A supplier who overstated on training data and got found out is in a materially worse position than one who said "not yet" and gave a date.

The pattern that works:

"We do not have this today. Here is what we do have that partially covers it. Here is what we are putting in place, and by when."

That answer is credible because it is checkable. It also gives the reviewer something to write down, which is what they need in order to close the item.

Two things to avoid. Do not say "compliant" about anything unless you can name the obligation and show you meet it. And do not describe an assessment as an audit or a certification — those are specific things with specific issuers, and a procurement reviewer knows the difference even when a marketing page does not.


What to do this week

Even without a questionnaire on your desk:

  1. Build the AI inventory. Every tool, who uses it, what data it touches, which tier, what the contract says about training. This one artifact answers questions in four of the nine sections above.
  2. Name an owner. One person accountable for AI risk. Write it down.
  3. Write the acceptable-use policy and have staff actually read it. One page is enough to start.
  4. Find where AI output reaches an outcome without a person in between. If any of it affects a person's access to something, start there.

Doing those four things before the questionnaire arrives converts a two-week scramble into an afternoon.


What this guide does not do

It tells you what is being asked and what a credible answer looks like. It does not tell you which obligations apply to your business — that depends on where you operate, what sector you are in, what data you hold and what your AI actually does, and it is genuinely different for a twelve-person recruiting firm and a sixty-person software company selling into Germany.

It is also not legal advice, and nothing here certifies anything.


If you want the answers rather than the questions

Atolus runs a structured assessment that produces the artifacts this questionnaire asks for — the AI inventory, the governance evidence, the gap list with the clause behind each item, and a prioritized plan for closing them. It scores your business on three separate axes and tells you which regulations actually reach you, which is usually the part owners find most surprising.

If a questionnaire has landed and there is a date on it, that is the fastest conversation to have.

Book a free 30-minute call — we will look at the questionnaire you were sent, tell you which sections you can already answer, and be honest about whether you need help with the rest.


Atolus Intelligence LLC. This guide describes what enterprise buyers are asking suppliers as of August 2026. It is general information, not legal advice, and it does not certify or establish compliance with any regulation.

Written:
Tue Aug 04 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Want the answer for your own business?

A free 30-minute call. We will work through which of this actually applies to you, and be honest if none of it does.

Book a free 30-minute call