Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Procurement · the durable driver

AI governance in procurement

For most suppliers the first real AI governance deadline does not arrive from a regulator. It arrives in a customer security questionnaire, on the customer’s timetable, with a deal attached, and it does not move when Brussels moves a date.

Contractual, not statutorydate-independent

Why this is the driver, not the regulation

The EU AI Act moved its high-risk deadline from August 2026 to December 2027. Nothing in enterprise procurement moved with it.

 Regulatory pressureProcurement pressure
TimetableSet by legislators; has already moved onceSet by your customer; tied to a contract date
Consequence of failureA fine, eventually, after enforcement capacity existsThe deal does not close
Who asksAn authority that may not yet be designatedA buyer with a purchase order
What answers itConformity assessment, technical file, registrationInventory, policy, oversight records, independent assurance

The clearest example

Microsoft’s SSPA programme covers AI Systems in Section K of its Data Protection Requirements, and for new suppliers, work cannot start until the compliance cycle is complete. ISO/IEC 42001 is named as an assurance route and is required for AI-sensitive cases. The detail →

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

What buyers actually ask

Expert analysis: a composite of what we see in questionnaires, not a standard.

  1. Which AI systems are involved in delivering this service? The inventory question. Almost nobody can answer it quickly the first time.
  2. What is each system for? Intended purpose, stated the same way in your documentation and your marketing.
  3. Is personal data processed, and on what basis? Privacy overlap.
  4. What human oversight exists? Who reviews what, with what authority to override.
  5. How was it tested and how accurate is it? The declared figure, and when it was last measured on production data.
  6. What happens when it fails? Incident path, notification timing, who calls whom.
  7. Are third-party or foundation models involved? The subprocessor question, applied to models.
  8. What independent assurance do you hold? Increasingly this names ISO/IEC 42001 specifically.

Question 1 is the one that costs you the deal

Not because the answer is bad, but because it takes three weeks. A supplier who returns an AI inventory in two days looks governed. A supplier who needs a fortnight to assemble one has answered a different question than the one asked. Build the inventory →

Answer once, not per deal

Practical recommendation. The economics only work if the answer is reusable. A supplier answering these ad hoc pays the cost every deal; a supplier with a management system pays once and updates.

ArtefactAnswers
AI system inventoryQuestions 1, 2, 7
AI policy and rolesGovernance framing across all of them
Risk and impact assessment recordsQuestions 3, 5
Human oversight definition and override recordsQuestion 4
Incident procedureQuestion 6
Statement of Applicability and certificateQuestion 8

That list is an ISO/IEC 42001 management system, described from the buyer’s side rather than the auditor’s.

Status labels on this page

Verified fact: That Microsoft's SSPA covers AI Systems in DPR Section K and names ISO/IEC 42001 as an assurance route; that the EU AI Act high-risk date moved to 2 December 2027.

Expert analysis: The eight-question composite, the artefact mapping, and the argument that procurement is the durable driver.

Unsettled: How widely ISO/IEC 42001 is being specified by name in questionnaires beyond the programmes we can verify.

Next step

The inventory is the gateway

Every question above starts with knowing what AI you run. It is a spreadsheet at ten systems and a project at a hundred, which is an argument for starting now rather than at the first questionnaire.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

What do enterprise customers ask about AI governance?

Typically: an inventory of AI used in delivering the service, the intended purpose of each system, whether personal data is processed and on what basis, what human oversight exists, how the system was tested and what its accuracy is, what happens when it fails, whether any third-party or foundation models are involved, what the incident notification path is, and what independent assurance the supplier holds. Increasingly the last question specifies ISO/IEC 42001.

Does ISO 42001 help with customer questionnaires?

It answers the assurance question directly and it produces the artefacts that answer most of the others. A certified AI management system generates an AI system inventory, an AI policy, risk and impact assessment records, life-cycle controls and a Statement of Applicability, which is most of what a questionnaire asks for. Microsoft's SSPA programme names ISO/IEC 42001 as an assurance route for AI supplier requirements, which is the clearest evidence of its procurement value.

When does AI governance become a sales blocker?

Earlier than most companies expect, and it is contractual rather than regulatory. Enterprise security reviews, supplier assurance programmes and vendor questionnaires operate on their own timetable and do not move when a regulatory deadline moves. For many suppliers the first real AI governance deadline arrives in a customer questionnaire rather than from an authority.