What Do Customers Expect Us to Have in Place for AI Security?

What enterprise buyers check on AI security, what evidence satisfies them at each contract size and how to answer a questionnaire before your programme is ready.

Enterprise buyers check four things, in order: a written AI policy, a register of where AI is used, evidence that you control AI in your own supply chain and independent certification or third-party assessment. Smaller contracts stop at the first two. This page covers the evidence that satisfies each.

What do customers expect us to have in place for AI security?

Those four artefacts, requested in that sequence. Buyers read the sequence as a maturity ladder: a supplier with a policy but no register looks like it wrote a document to pass procurement, and a supplier with a register but no policy looks unmanaged. The pairing signals that someone owns the question internally.

The same order shapes our AI Security Programmes.

What AI evidence do clients ask for most often?

The first request is nearly always documentary: your AI policy or acceptable-use standard, plus a statement of whether your product uses AI, which models sit behind it and whether customer data reaches them. Second comes your register of AI use, showing systems, owners and purposes. Beyond that, requests split by sector, with financial services and healthcare buyers asking about data residency, retention and human oversight of automated decisions, and public sector buyers asking about lawful basis and equality impact.

Shadow AI undermines every answer here. A register that excludes what staff actually use will not survive a follow-up question on a technical call.

What is sufficient at each contract size?

Requirements scale with contract value. Smaller contracts test whether a policy exists, mid-sized contracts test whether it is operated and the largest contracts test whether it is independently verifiable. The pattern below is illustrative rather than a fixed rule.

  • Smaller contracts: a policy, a short statement of AI use and confirmation that AI-related incidents fall under your existing security incident process.
  • Mid-sized contracts: a completed AI questionnaire, a register extract and named accountability for AI risk.
  • Largest contracts, or any deal where your system informs decisions about the buyer’s customers: audit rights, evidence of supplier-level AI controls and questions about certification.

Some buyers accept a documented gap analysis with dates against ISO 42001 in place of the certificate, provided the plan is credible and someone senior signs it.

Do we need ISO 42001 certification to win enterprise deals?

Not yet, in most markets. Certification closes off a line of questioning rather than winning the contract on its own. What wins contracts today is answering specific questions consistently and showing that the answers come from a managed system with a named owner.

The calculation changes when certification appears as a mandatory tender requirement, when a strategic customer signals it will require it at renewal or when a competitor holds it and you are asked to explain the difference. An AI Security Gap Analysis will tell you how far you are from certifiable, which is often the more useful number early on. Our comparison of ISO 42001 and ISO 27001 covers what an existing certificate already gives you.

How do we handle questions about AI in our own supply chain?

Buyers increasingly ask whether your subprocessors apply AI to their data and whether your contracts permit it. That question defeats many suppliers because the contracts predate the issue and say nothing either way.

The defensible position is a supplier inventory recording, for each material third party, whether AI processing occurs, what data it touches and what your agreement allows. Where the contract is silent, note that and flag it for the next renewal. Buyers accept honest gaps that carry an owner and a date, and they punish confident answers that later prove wrong.

What happens if a questionnaire arrives before our programme is ready?

Answer what you can evidence, mark the rest as in progress with a date and never guess. Procurement teams cross-check answers against your documentation and against what your engineers say on technical calls, and an inconsistency costs more trust than an admitted gap.

A practical holding position: issue an interim AI acceptable-use statement, run a discovery exercise across your environment to build a first-pass register and name an owner for AI risk. Those three steps are achievable in weeks and cover most of what mid-market questionnaires ask. Verifying that deployed systems behave as documented, through AI Behaviour Verification, turns a paper answer into something defensible under scrutiny.

Does the EU AI Act affect us if we only sell in the UK?

Direct obligations arise mainly where you place a system on the EU market, put one into service there or the output is used in the EU, and the precise tests sit in the Act itself. Indirectly the effect is frequent, because UK buyers with EU operations push their obligations down through supplier terms.

UK suppliers therefore receive questions framed in EU AI Act language, including risk classification, technical documentation and human oversight, from customers who must satisfy those requirements themselves. Being able to state your classification and point to matching documentation shortens those conversations.

Who inside our business should own the answers?

One named person, with authority to commit to remediation dates. In mid-sized organisations this is usually the head of information security, the DPO or a senior technology leader, supported by whoever owns the product roadmap.

What fails is distributed ownership, where sales answers commercial questions, engineering answers technical ones and nobody reconciles them. Buyers detect this quickly because the answers disagree. A single owner with a maintained evidence pack turns each questionnaire into a retrieval task, which is one of the outcomes AI governance is meant to produce.

How do we prove our AI controls actually work?

Documentation proves intent and testing proves behaviour. Mature buyers ask for both, and the gap between them is where most suppliers are exposed. Evidence that satisfies scrutiny includes access-review records for AI tools, logs showing that prohibited data types are blocked, results from adversarial testing and records of AI-related incidents with their outcomes.

The CIA+EFT framework gives you a structure for deciding what to test, extending confidentiality, integrity and availability with explainability, fairness and traceability. Our answers on what AI governance involves day-to-day and on ISO 42001 audit evidence cover how those records are kept. This page is general guidance on what buyers commonly ask for rather than legal, compliance or regulatory advice.

An evidence pack buyers accept

Our AI Security Programmes build the policy, register and control evidence that supplier questionnaires and contract renewals keep asking for.