AI Governance
Your Client's Security Questionnaire Now Has an AI Section
Quick Answer
The AI section on a vendor security questionnaire asks four things: which AI tools you use, what data goes into them, who checks the output before a client sees it, and what you have written down about all three. It arrived in 2026 through the standard templates rather than through any one customer, so every client using those templates asks it in the same words. The answers rest on four documents: an acceptable use policy, an AI policy, an inventory of the tools you actually use, and an impact assessment where AI takes part in decisions about people.
Your team uses ChatGPT. Nobody has written down what they can put in it. That costs you nothing at all, until the day a customer asks you to explain it in writing.
Before a big company signs with you, it sends you a checklist. Every question on it is about their data. It asks where you keep it, who in your company can open it, and what you do on the day something goes wrong. You fill it in, you send it back, and the contract goes ahead. This year that checklist grew a new section, and the new section is about AI.
What Changed in the Questionnaires
Enterprise buyers did not each decide to start asking this. The forms your clients send you are mostly not written by your clients. They come from standard templates that get passed around procurement teams, and in 2026 those templates picked up AI governance sections: the SIG questionnaire, the Cloud Security Alliance's CAIQ, and the internal templates that most large companies copied from those two.
Why This Matters More Than One Client Asking
A single nervous customer is a conversation. A template is a pattern. Every client using that template will ask you the same thing, and they will ask in the same words, because it is the same form.
Which also means the work is reusable. Answer it properly once and you have answered it for everyone who sends you that form.
Where the questions point: the AI sections in those templates reference ISO/IEC 42001 and the NIST AI Risk Management Framework. You are being measured against a published checklist, which is better news than it sounds, because a published checklist can be read in advance.
What the AI Section Actually Asks
Underneath the wording, the questions cluster into four things.
1. Which tools, and at what tier
Naming ChatGPT is not enough, because a free consumer account and a business account often handle your data completely differently, and the person reading your form knows that. They want the product and the plan.
2. What goes in
This is the question with real teeth. If you have been pasting client briefs, contracts, or customer lists into a chat window, that is the answer, and the follow-up asks what stops it happening on a tool nobody approved.
3. Who checks the output
They want a job title. Name the person who checks the work before it goes to a client, and say what that person looks for: whether the facts match a source, whether the figures add up, whether the quotes are real.
4. Whether any of it is documented
This is where most small firms stop, because the first three can be answered honestly from memory and the fourth cannot.
Why "We Use AI Responsibly" Is Not an Answer
A questionnaire answer is only worth as much as the document behind it, because the reply to a good answer is a request to attach the policy you just described.
That is the part people underestimate. The form itself is survivable. You can write something reasonable in the box and send it back the same afternoon. What catches you is the email two days later asking for the policy, the tool list, and the date it was last reviewed. At that point either the document exists or the conversation changes, and it changes in front of a procurement team that has now seen a gap between what you said and what you hold.
What the buyer wants is a file they can put in a folder. You might handle all of this carefully and sensibly. Careful is real, and careful cannot be attached to an email. They have to show somebody else that they checked you.
The Documents Behind the Answers
ISO/IEC 42001 expects an organisation to hold 11 documents covering how it governs AI. You do not need certification for any of this to matter. The questionnaire is borrowing the standard's checklist, so the checklist is what you are being measured against whether you have ever read it or not.
Four of the 11 answer most of what an agency gets asked.
An acceptable use policy
Says which tools staff may use, what may never be entered into them, and what must be checked before output is relied on. The one clients request most often and the cheapest to produce. What goes into it, section by section.
An AI policy
Sits above it, and states the company's position and who is accountable. In a firm of eleven people that is one named person, not a committee.
An inventory of what you actually use
Almost nobody has this, and it is usually the first thing that gets asked for, because every other answer depends on it. It also tends to be the moment a founder discovers three tools they did not know were in the building.
An impact assessment
Where your AI takes part in decisions about people rather than just drafting copy. If you screen applicants, rank candidates, or route customers, this one applies to you. How it differs from a risk assessment.
If You Have Nothing Written Down
Write the acceptable use policy first. It is two to four pages, it answers the largest share of what you will be asked, and it is the document you can produce this week without anyone's permission.
Then write the inventory, because it is the shortest and because every other document quietly depends on knowing what you use. Ask everyone what AI tools they have open, promise nobody is in trouble, and write down what comes back. That conversation is usually more revealing than the document.
The test worth running before you sign anything
Read every sentence as if a customer has asked you to demonstrate it. Cut or soften anything you could not show within a day.
Whatever you write, it has to describe the company you actually run. A policy full of confident legal-sounding language about a company you do not run is worse than a plain one about the company you do, because everyone assumes it was checked.
FAQ
Do I need ISO 42001 certification to answer these questions?
Which document should I write first?
How long should an AI acceptable use policy be?
Does any of this apply to a company with fewer than 20 people?
What if my clients have not asked yet?
Find Out Which Documents You Already Have
A free 3-minute check that names all 11 documents and marks yours as in place, partly there or missing.
No email needed to see your result.
Take the GEO Readiness Quiz →60 seconds · Personalized report · Free
Continue Learning
Dive deeper into AI search with these related articles:
Trust Signals for AI: Security, Transparency, and Credibility
AI engines evaluate trust through security, transparency, and credibility signals before citing your content.
E-E-A-T in the AI Era: How to Build Machine Trust
85% of AI-cited sources show strong E-E-A-T signals. Learn how to build Experience, Expertise, Authoritativeness, and Trust that AI engines recognize.
Building Expertise Signals That AI Engines Trust
AI engines evaluate expertise through demonstrated knowledge, topical depth, and verifiable credentials.