The Loom · #2
The AI questionnaire is the new security questionnaire
Enterprise buyers have started asking suppliers to prove how they govern AI. Most companies under 500 people cannot answer yet. Here is what the questions ask, and what we built to answer them.
For ten years, winning an enterprise customer meant surviving a security questionnaire. Answer the two hundred questions, show the SOC 2 report, get through procurement.
A second questionnaire has appeared beside it. It asks about AI.
Which of your systems use it. What it can decide on its own. Who reviews the output. Where our data goes. What happens when the model changes. And the line that ends most conversations: show us evidence, not assurances.
The companies sending these questions are not being difficult. They carry their own obligations under the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework. What arrives on a supplier's desk is that obligation, passed down the chain.
What the questions really ask
Strip the wording and an AI questionnaire wants six things:
- what AI you run, including the features embedded in tools you already bought
- what each one is used for, and who it affects
- what could go wrong, beyond a security breach
- which controls reduce that, and who owns them
- how you would know if a control stopped working
- what you can put in front of an auditor
An AI policy answers about half of one of those.
Why the PDF does not survive contact
Most companies under 500 people respond by writing a policy. It is a reasonable first move, and it is usually where the effort stops.
The gap shows up at the evidence line. A policy states an intention. A buyer is asking for a record: this system, this assessment, this control, this owner, this date, this next review. When that record does not exist, the honest answer is "we are working on it", and the deal slows down.
What we built
RiskWoven is for the company that has no compliance team and has just been sent one of these questionnaires. It works in four stages.
- Scan. Twelve questions, about ten minutes, scored in your browser. It tells you where you stand before you spend anything.
- Assess. A structured intake across your systems, data, oversight and vendors. Every score shows its factors, its weights, and why it is not higher or lower, with a gap report and a remediation plan.
- Document. Policies, standards and procedures shaped by your own intake rather than a template with your name dropped into the header. Twenty-eight document types.
- Prove. The risk register, the evidence expected against each gap, the cross-framework mapping, and a certification-readiness report for ISO 27001, ISO 42001, ISO 27701 or ISO 22301.
Then the parts that keep working after the first push. An evidence register that rejects a mapping that does not hold. Questionnaire answers drafted only from evidence you actually hold, with anything unsupported flagged rather than filled in. Vendor intake that reads a supplier's SOC report, privacy policy and terms, and flags training practices, retention periods and subprocessors.
If you run agents rather than assistants, there is a pack for that: an agent inventory, per-class scoring on autonomy, tool access, data sensitivity and blast radius, and the policy and procedures around them.
The part we care most about
Every document passes an independent review before it is released. Questionnaire answers come only from evidence you hold. The framework library records when a change to a standard was substantive and when it was cosmetic.
That matters because the failure mode of AI in this field is a confident document nobody can defend. A governance artefact that invents a control is worse than no artefact, because someone will rely on it in front of an auditor.
When a customer, a board or an auditor needs a human name on the work, a governance professional reviews that specific output and countersigns it.
What it costs
The scan is free. The assessment is $299 and the policy pack is $499. The readiness bundle, which is both of those plus the register, the evidence requirements and the mapping, is $899. The agent governance pack is $1,299 bundled and covers up to 25 agent classes. Professional review starts at $600. Vendor reviews run on credits, from $99 for 100. Consultants and managed providers have a partner tier at $199 per seat per month plus $49 per client per month.
Where to start
Run the free scan at riskwoven.com/assess. Twelve questions.
If the score is where you expected, you have your answer for the questionnaire sitting in your inbox. If it is not, the gap report tells you which three things to fix first.