AI governance in procurement
For most suppliers the first real AI governance deadline does not arrive from a regulator. It arrives in a customer security questionnaire, on the customer’s timetable, with a deal attached, and it does not move when Brussels moves a date.
Why this is the driver, not the regulation
The EU AI Act moved its high-risk deadline from August 2026 to December 2027. Nothing in enterprise procurement moved with it.
| Regulatory pressure | Procurement pressure | |
|---|---|---|
| Timetable | Set by legislators; has already moved once | Set by your customer; tied to a contract date |
| Consequence of failure | A fine, eventually, after enforcement capacity exists | The deal does not close |
| Who asks | An authority that may not yet be designated | A buyer with a purchase order |
| What answers it | Conformity assessment, technical file, registration | Inventory, policy, oversight records, independent assurance |
The clearest example
Microsoft’s SSPA programme covers AI Systems in Section K of its Data Protection Requirements, and for new suppliers, work cannot start until the compliance cycle is complete. ISO/IEC 42001 is named as an assurance route and is required for AI-sensitive cases. The detail →
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
What buyers actually ask
Expert analysis: a composite of what we see in questionnaires, not a standard.
- Which AI systems are involved in delivering this service? The inventory question. Almost nobody can answer it quickly the first time.
- What is each system for? Intended purpose, stated the same way in your documentation and your marketing.
- Is personal data processed, and on what basis? Privacy overlap.
- What human oversight exists? Who reviews what, with what authority to override.
- How was it tested and how accurate is it? The declared figure, and when it was last measured on production data.
- What happens when it fails? Incident path, notification timing, who calls whom.
- Are third-party or foundation models involved? The subprocessor question, applied to models.
- What independent assurance do you hold? Increasingly this names ISO/IEC 42001 specifically.
Question 1 is the one that costs you the deal
Not because the answer is bad, but because it takes three weeks. A supplier who returns an AI inventory in two days looks governed. A supplier who needs a fortnight to assemble one has answered a different question than the one asked. Build the inventory →
Answer once, not per deal
Practical recommendation. The economics only work if the answer is reusable. A supplier answering these ad hoc pays the cost every deal; a supplier with a management system pays once and updates.
| Artefact | Answers |
|---|---|
| AI system inventory | Questions 1, 2, 7 |
| AI policy and roles | Governance framing across all of them |
| Risk and impact assessment records | Questions 3, 5 |
| Human oversight definition and override records | Question 4 |
| Incident procedure | Question 6 |
| Statement of Applicability and certificate | Question 8 |
That list is an ISO/IEC 42001 management system, described from the buyer’s side rather than the auditor’s.
Status labels on this page
Verified fact: That Microsoft's SSPA covers AI Systems in DPR Section K and names ISO/IEC 42001 as an assurance route; that the EU AI Act high-risk date moved to 2 December 2027.
Expert analysis: The eight-question composite, the artefact mapping, and the argument that procurement is the durable driver.
Unsettled: How widely ISO/IEC 42001 is being specified by name in questionnaires beyond the programmes we can verify.
The inventory is the gateway
Every question above starts with knowing what AI you run. It is a spreadsheet at ten systems and a project at a hundred, which is an argument for starting now rather than at the first questionnaire.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
What do enterprise customers ask about AI governance?
Typically: an inventory of AI used in delivering the service, the intended purpose of each system, whether personal data is processed and on what basis, what human oversight exists, how the system was tested and what its accuracy is, what happens when it fails, whether any third-party or foundation models are involved, what the incident notification path is, and what independent assurance the supplier holds. Increasingly the last question specifies ISO/IEC 42001.
Does ISO 42001 help with customer questionnaires?
It answers the assurance question directly and it produces the artefacts that answer most of the others. A certified AI management system generates an AI system inventory, an AI policy, risk and impact assessment records, life-cycle controls and a Statement of Applicability, which is most of what a questionnaire asks for. Microsoft's SSPA programme names ISO/IEC 42001 as an assurance route for AI supplier requirements, which is the clearest evidence of its procurement value.
When does AI governance become a sales blocker?
Earlier than most companies expect, and it is contractual rather than regulatory. Enterprise security reviews, supplier assurance programmes and vendor questionnaires operate on their own timetable and do not move when a regulatory deadline moves. For many suppliers the first real AI governance deadline arrives in a customer questionnaire rather than from an authority.