The Loom · #2

The AI questionnaire is the new security questionnaire

Enterprise buyers have started asking suppliers to prove how they govern AI. Most companies under 500 people cannot answer yet. Here is what the questions ask, and what we built to answer them.

Published September 18, 2026 · written and approved by RiskWoven, sources checked when published

Four stages from scan to evidence: Scan free, Assess 299 dollars, Document 499 dollars, Prove 899 dollars, with a note that every document passes an independent review before release.

For ten years, winning an enterprise customer meant surviving a security questionnaire. Answer the two hundred questions, show the SOC 2 report, get through procurement.

A second questionnaire has appeared beside it. It asks about AI.

Which of your systems use it. What it can decide on its own. Who reviews the output. Where our data goes. What happens when the model changes. And the line that ends most conversations: show us evidence, not assurances.

The companies sending these questions are not being difficult. They carry their own obligations under the EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework. What arrives on a supplier's desk is that obligation, passed down the chain.

What the questions really ask

Strip the wording and an AI questionnaire wants six things:

  • what AI you run, including the features embedded in tools you already bought
  • what each one is used for, and who it affects
  • what could go wrong, beyond a security breach
  • which controls reduce that, and who owns them
  • how you would know if a control stopped working
  • what you can put in front of an auditor

An AI policy answers about half of one of those.

Why the PDF does not survive contact

Most companies under 500 people respond by writing a policy. It is a reasonable first move, and it is usually where the effort stops.

The gap shows up at the evidence line. A policy states an intention. A buyer is asking for a record: this system, this assessment, this control, this owner, this date, this next review. When that record does not exist, the honest answer is "we are working on it", and the deal slows down.

What we built

RiskWoven is for the company that has no compliance team and has just been sent one of these questionnaires. It works in four stages.

  1. Scan. Twelve questions, about ten minutes, scored in your browser. It tells you where you stand before you spend anything.
  2. Assess. A structured intake across your systems, data, oversight and vendors. Every score shows its factors, its weights, and why it is not higher or lower, with a gap report and a remediation plan.
  3. Document. Policies, standards and procedures shaped by your own intake rather than a template with your name dropped into the header. Twenty-eight document types.
  4. Prove. The risk register, the evidence expected against each gap, the cross-framework mapping, and a certification-readiness report for ISO 27001, ISO 42001, ISO 27701 or ISO 22301.

Then the parts that keep working after the first push. An evidence register that rejects a mapping that does not hold. Questionnaire answers drafted only from evidence you actually hold, with anything unsupported flagged rather than filled in. Vendor intake that reads a supplier's SOC report, privacy policy and terms, and flags training practices, retention periods and subprocessors.

If you run agents rather than assistants, there is a pack for that: an agent inventory, per-class scoring on autonomy, tool access, data sensitivity and blast radius, and the policy and procedures around them.

The part we care most about

Every document passes an independent review before it is released. Questionnaire answers come only from evidence you hold. The framework library records when a change to a standard was substantive and when it was cosmetic.

That matters because the failure mode of AI in this field is a confident document nobody can defend. A governance artefact that invents a control is worse than no artefact, because someone will rely on it in front of an auditor.

When a customer, a board or an auditor needs a human name on the work, a governance professional reviews that specific output and countersigns it.

What it costs

The scan is free. The assessment is $299 and the policy pack is $499. The readiness bundle, which is both of those plus the register, the evidence requirements and the mapping, is $899. The agent governance pack is $1,299 bundled and covers up to 25 agent classes. Professional review starts at $600. Vendor reviews run on credits, from $99 for 100. Consultants and managed providers have a partner tier at $199 per seat per month plus $49 per client per month.

Where to start

Run the free scan at riskwoven.com/assess. Twelve questions.

If the score is where you expected, you have your answer for the questionnaire sitting in your inbox. If it is not, the gap report tells you which three things to fix first.

Share on LinkedInRun the free 12-question scan
Post text to copy
For ten years, winning an enterprise customer meant surviving a security questionnaire.

A second questionnaire has appeared beside it, and it asks about AI. Which of your systems use it. What it can decide on its own. Who reviews the output. What happens when the model changes. Show us evidence, not assurances.

The buyers sending these are passing down their own obligations under the EU AI Act, ISO/IEC 42001 and the NIST AI RMF.

An AI policy answers about half of one of those questions. Our new Loom issue sets out what the rest of the answer looks like, and how RiskWoven gets a company with no compliance team from a free scan to evidence it can show.

What is the hardest question on the questionnaires you are receiving?