FL Fredrik Lindstrom


The email comes from procurement. The champion who has been walking the deal through is not on it.

Attached is a spreadsheet, and somewhere past question sixty sits a section that was not in last year’s version. It is headed artificial intelligence, it runs to a dozen questions, and nobody on the sales side can answer any of them. So it goes to engineering, where something awkward happens: the team can describe every system in detail and cannot produce a single dated record about any of them. From there the deal moves to legal review. That is where it stops.

None of this is an engineering problem. In my experience the technology is rarely the gap; the record of the technology is. A security questionnaire asks what you did, when you did it, and who signed it. That is a documentation problem, and it arrives with a clock attached to a signed contract.


What enterprise buyers are actually asking

The AI section is shorter than it looks. Four question families, repeated across buyers because the templates come from a small number of sources, and each one is testing whether a record exists rather than whether an opinion does.

Model provenance and training-data rights

Whose model sits under the feature, and who trained it on what. Buyers want the vendor named, the model and version named, and a statement on whether the training data carried rights a claim could be inherited from. A general sentence about using a leading foundation model does not clear this question, because the person reading your answer is counsel assessing indemnity exposure, not a technologist assessing architecture.

Output monitoring and hallucination controls

Buyers want roughly 90 days of documented evidence that AI-generated outputs are evaluated before they reach users: what was sampled, how it was scored, what the threshold was, and what happened the time a threshold was missed. Ninety days of history cannot be assembled in the week the questionnaire arrives. Either the logs exist or the honest answer is no.

AI subprocessor transparency

Every third-party AI vendor named, with the data flow and the contract terms behind each one. Enterprise buyers already run this discipline against cloud subprocessors under GDPR Article 28, so the machinery is familiar and the expectations are set. Aim it at a newer supply chain and it usually surfaces two or three vendors nobody had on the list.

Alignment with NIST AI RMF 1.0 and ISO/IEC 42001

Almost always phrased as alignment rather than certification, and that wording is deliberate. NIST AI RMF 1.0 has no certification mechanism at all, and ISO/IEC 42001 certification is still rare enough that a buyer requiring it would disqualify most of the market. What the question tests is whether you can name the framework you work to and show a mapping from your controls to it.

Why the answer is not a policy document

IBM’s Cost of a Data Breach 2026 studied 602 breached organizations across 16 countries, with 3,558 interviews conducted between March 2025 and February 2026. Sixty-eight percent of those organizations had no implemented AI governance policy. Thirty-five percent had nothing at all; thirty-three percent were still drafting. And every operational AI control the study tracked declined year over year, which is the finding worth sitting with, because it means the gap is widening while the questionnaires get longer.

A policy states an intent. A control produces evidence on a schedule, with a named owner, and it leaves a record whether or not anyone reads it. A security questionnaire asks for the second, and the auditor behind it will ask for the artifact the control produced rather than the document promising one.

This is the cybersecurity pattern arriving on a shorter timeline. In June 2016 I wrote about organizations answering a distributed problem with a departmental solution, and the line still holds: “However, point solutions do not work.” The AI version of the point solution is the policy PDF. Written, approved, circulated, and governing nothing, because nothing inside it runs on a cadence or reports to a person.

The four artifacts, and what each one answers

Every question family above resolves to one of four artifacts. Produce them and the AI section stops being a blocker; it becomes twenty minutes of copying from documents you already hold.

The four artifacts a vendor AI security questionnaire asks for
ArtifactThe question it closesTypical effort (estimate)
AI system inventory“What AI are you running?”Days
Model and subprocessor provenance“Whose models, what data, under what terms?”Days to weeks
Output evaluation evidence“Show us 90 days of monitoring.”Weeks. This is the one that needs lead time.
Named deployment owner and approval record“Who signs off before an AI system ships?”Days

The effort column is my judgement from advisory work, not a sourced finding. Treat it as a planning estimate and expect your own numbers to move with the size of your AI footprint.

What to do the week the questionnaire arrives

Sequence matters here, because one of the four artifacts has a clock on it and the other three do not.

  1. Day one, start the output evaluation logging. Before the inventory, and before anyone drafts a word. It is the only artifact that accrues with time, and every day you spend deciding is a day you cannot claim later.
  2. Name the deployment owner in writing. One person who approves an AI system going in front of a customer. Not a committee, not a function — a person, with the approval recorded somewhere dated.
  3. Enumerate the AI systems in production. Start from the expense reports and the identity provider rather than from what the architecture diagram says. The diagram shows what was designed; the invoices show what is running.
  4. Pull the subprocessor list from contracts, not from memory. Every vendor whose model touches customer data, and what their terms say about training on it.
  5. Answer the questionnaire honestly on the item you cannot evidence. Say the control started on a date and name the date. A dated start with an owner reads as governance. A confident claim that unravels in the follow-up call reads as something worse, and it costs you the renewal as well as the deal.

The alternative is rarely that you lose outright. The contract sits in legal review for six weeks. Your quarter moves. The competitor who published a trust page answered the same questionnaire in a day.


Questions people actually ask

Does answering an AI security questionnaire require ISO 42001 certification?

No. Documented alignment satisfies most enterprise security questionnaires. Buyers name ISO/IEC 42001 to find out whether you can point at a recognized management-system standard and show where your controls sit against it. Certification is a separate decision with a separate cost, and roughly 350 organizations worldwide hold the certificate, so a buyer who required it would disqualify most of the market. What ISO/IEC 42001 certifies, costs, and does not cover prices that decision.

What is the difference between an AI policy and an AI control?

A policy states an intent. A control produces evidence on a schedule, with a named owner, and it leaves a record whether or not anyone reads it. A security questionnaire asks for the second. An auditor reviewing your answer will ask for the artifact the control produced, not for the document that said you would produce one.

Our AI is all third-party vendors. Do we still have to answer?

Yes, and the questions get harder rather than easier. Buying the model instead of building it moves the provenance question to your vendor, but it leaves you owning the subprocessor list, the data flows to each vendor, the contractual terms behind them, and the evidence that outputs were evaluated before your customers saw them. A buyer is assessing your deployment, not your supplier’s research.

How long does it take to produce evidence we do not currently have?

Three of the four artifacts are documentation work and move in days. Output evaluation evidence does not, because buyers ask for roughly 90 days of history and history cannot be backdated. If output evaluation is not running today, the earliest honest answer to that question is 90 days from the day you start logging.


Sources. IBM Cost of a Data Breach 2026 (602 organizations, 16 countries, 3,558 interviews, March 2025 to February 2026) for the 68% figure and the year-over-year decline in operational AI controls. Aetos, 10 June 2026, for enterprise questionnaires carrying AI modules and the 90-day output-evidence expectation. ISO/IEC 42001:2023 published 18 December 2023 (iso.org/standard/42001); approximately 350 certified organizations worldwide as of spring 2026 (Atoro, 2 July 2026). NIST AI RMF 1.0 published 26 January 2023, voluntary, with no certification mechanism (nist.gov). Effort estimates are judgement, not sourced.

If the AI section is sitting on a live deal right now, the four artifacts are a two-week engagement, and I would rather you built them than lost the quarter. How I work with boards and executive teams.

Related

ISO/IEC 42001: what it certifies, what it costs, and what it does not cover — buyers name ISO/IEC 42001 in questionnaires, so this prices the decision and says which questions it actually closes.

You cannot govern what you cannot name — the inventory artifact as a board scenario, with four options scored.

The Governance Memo carries this work monthly for boards and CISOs — one breach post-mortem and two or three governance items.