What AI Supplier Questionnaires Are Now Asking, and How to Answer Them
If you supply enterprise clients, regulated bodies or public sector buyers, your next security questionnaire will almost certainly contain a section on AI. UK buyers have moved on from a single token question about whether you use machine learning anywhere in your stack. They now ask for policy documents, use-case risk assessments, named accountable owners and evidence of change control.
The central shift is this: procurement has stopped asking whether you have AI governance and started asking you to show it. That is a commercial problem before it is a compliance one. Organisations that cannot produce answers within the deadline of a tender lose the tender.
What the questions actually ask
The AI questions now appearing in third-party risk assessments cluster around four areas: whether a policy exists, whether risk assessment happens per use-case, what controls sit around data and automated decisions and how changes to AI systems are governed. Roughly fifteen questions do the work, and they repeat across buyers because assessment platforms have standardised them.
Here are the five that cause the most trouble.
Does your organisation have a documented AI policy?
A documented AI policy names what staff may and may not do with AI tools, who approves new tools and where the boundary sits for handling client data. It must exist as a controlled document with a version, an owner and a review date.
This question fails in a specific way. Many organisations have something: a paragraph in the acceptable use policy, an email from the CTO, a message telling people not to paste client data into public chatbots. None of that survives an assessor asking for the document reference. If your answer needs a caveat about the policy being in draft, treat it as a no.
A credible answer names the document, its approval date, the approving body and the review cycle.
Have you conducted risk assessments for each AI use-case?
Buyers want per-use-case assessment, not a single organisational AI risk entry. The risk profile of a summarisation tool used on internal meeting notes bears no relation to a model influencing eligibility decisions about individuals.
Most organisations cannot answer this because they do not have a complete list of AI use-cases to assess. Shadow AI adoption runs ahead of any register. The first task is inventory, the second is assessment against a consistent method. Assessors will accept a partial register with a documented discovery process in progress. They will not accept a claim of completeness that a five-minute conversation with your staff would disprove.
Do you have guardrails in place on automated decision-making?
This question asks where a model output affects a person or a commercial outcome without a human reviewing it. Buyers expect a documented answer describing which decisions are automated, what the human review point is and how a decision can be challenged or reversed.
Answer this one carefully, because it carries regulatory weight alongside contractual weight. If nothing in your estate makes automated decisions about individuals, say so plainly and describe the control that keeps it that way. Silence reads as uncertainty.
Does customer or client data train your AI models?
The question behind the question is whether your buyer’s data could surface in an output delivered to someone else. Your answer needs to cover the models you build and the tools you buy, because a third-party service with training enabled by default puts your client’s data into a training set regardless of your intentions.
A strong answer states the position, names the contractual and technical controls that enforce it and confirms which supplier settings have been checked. This is where AI procurement security becomes a chain: your buyer is assessing you, and the same questions should be going out to the tools you have licensed.
Do you have a formal AI change management process?
AI systems change without you changing anything. A supplier updates a model, alters a default or adds a feature that routes data somewhere new. A change management process for AI has to account for supplier-driven change as well as your own releases.
Assessors look for a named approval route for new AI tools, a trigger for reassessing existing ones and a record of decisions. If new AI tools enter your organisation through a corporate card and a browser tab, the process does not exist yet, whatever the policy says.
Why the commercial case moves faster than the compliance case
Compliance deadlines allow for a remediation plan. Procurement deadlines do not. A questionnaire attached to a tender carries a fixed return date, and a response with unanswerable AI questions competes against responses that answer them fully. The buyer has no reason to carry your risk when an alternative supplier does not present it.
The organisations gaining ground here hold a policy reference, a use-case register and a data position ready before a questionnaire lands, rather than assembling them once the clock is running. Speed of evidence is the advantage.
Key questions on AI supplier assessments
Who should own the answers to AI questions in a supplier questionnaire?
Ownership usually sits with the person accountable for information security, working with legal and the AI system owners. The critical point is that one named person maintains the evidence pack between tenders. Where answers are assembled from scratch each time, quality varies by whoever is available and inconsistencies across responses undermine buyer confidence.
What tends to slow organisations down in becoming able to answer?
The work is largely discovery and documentation rather than technical build, so the constraint is rarely engineering capacity. The longest element is completing an AI use-case inventory, since it depends on staff disclosing tools they adopted without approval. Policy drafting and approval move faster once that inventory exists and the scope is settled.
What if our answer to one of these questions is weak?
A documented weakness with a dated remediation plan reads better than an evasive answer. Assessors are practised at spotting vagueness, and an answer that collapses under a follow-up question damages trust more than the original gap did. State the position, name the control you are adding and give the date.
Where to start
Run the questions above against your own organisation and count how many you could evidence this week. The same themes recur in every AI supplier questionnaire UK buyers issue, so the preparation carries across tenders. Our AI Security Gap Analysis identifies which questions you cannot yet answer and what evidence each one requires. Where the gaps are substantial, our AI Security Programme closes them in a sequence that puts the questions buyers ask first. Contact us to discuss which of the two fits your position.
This post is general guidance on supplier assurance practice and is not legal or regulatory advice.
Answer the questions before they arrive
Our AI Security Programmes close the gaps behind the questions buyers ask, in the order procurement asks them.