Home > Insights

Insights

When an enterprise buyer sends an AI governance questionnaire

An enterprise AI governance questionnaire is a request to prove what your system did, not just describe it. How to answer it once, from a record you keep and reuse.

What they are really asking, and why you keep rebuilding the answer.

You are selling into a bank, an insurer or a large enterprise, and the deal is going well until security and procurement get involved. A questionnaire arrives. It might be a SIG, a CAIQ, a bespoke AI governance addendum, or a page of questions a customer’s risk team wrote themselves. Somewhere in it: how does your model make decisions, what oversight sits around it, how do you manage model change, and what happens when it gets something wrong.

You answer it. Then the next customer sends a different questionnaire asking the same things in a different order, and you answer that one too, from scratch, pulling policies out of one place, tickets out of another, screenshots out of a third, and a founder’s memory out of a meeting. The deal waits while you assemble it.

The questionnaire is not really the problem. The problem is that the evidence behind your answers does not exist as a record you can reuse. Every buyer is asking you to reconstruct it, and you are reconstructing it every time.

What the questionnaire is actually asking for

Under the specific questions, an enterprise buyer is asking one thing: if we depend on your AI, can you show us what it does, on what basis, under whose authority, and how you know. They are not looking for a promise that your governance is good. They are looking for evidence they can put in their own file, because when their regulator or their board asks about the AI they brought in, the answer becomes their problem.

That is why “we take AI governance seriously” does not move a serious reviewer, and a screenshot of a policy does not either. The reviewer wants the underlying facts, organised, with each one showing how it is known. Describing your posture is not the same as evidencing a decision, and the questionnaire is really a request for the second thing wearing the clothes of the first.

Answer it once, from a record that already exists

Decision provenance is a record of what your system did, on what basis, under whose authority, and how each item was captured, kept so it can be reconstructed later. When that record exists, a questionnaire stops being a rebuild and becomes a mapping exercise: the request comes in, and each item is matched to evidence that is already there, marked present, partial or absent.

An honest record does not dress every fact up as equally solid. Some items come from the infrastructure that ran the decision, some are captured close to the event, some are reconstructed, and some are stated by a person. The record shows which is which. That honesty is not a weakness in front of a good reviewer. It is what makes the record credible, because a reviewer who has seen plenty of all-green dashboards trusts the one that admits where the evidence is thinner.

Custara prepares, structures and preserves that record and produces a scoped pack for the review in front of you. It does not answer the adequacy question for you. Whether your governance is good enough is the buyer’s call, not the record’s and not Custara’s.

Working papers you keep, not an audit you repeat

The reason you keep rebuilding is that you are treating each questionnaire as a fresh audit. The better model is one finance has used for a long time. Behind an audit sits a body of working papers: the underlying evidence, organised so someone else can follow how a conclusion was reached. You do not rebuild the working papers for every person who asks. You keep them, and you hand over what the question needs.

Decision provenance is the working papers for your AI. Keep the record current as the system changes, and each new questionnaire draws from the same evidence base rather than sending you back to policies and screenshots. A standard can define what the record should contain and how evidence quality is described, which is the work of the Decision Standards Institute, and an independent assessor can review the record separately, which is the role of Attestra. Custara prepares the record. It does not assess it, and it does not decide whether your buyer should accept it.

What this changes in a deal

The record exists before the question is asked, so the questionnaire stops setting your timeline. You are mapping a request to evidence you already hold, not manufacturing evidence under deal pressure. The same record answers the next buyer, the insurer at renewal, and your own board, because it was built once and kept, not rebuilt for each audience.

None of this promises the buyer will wave you through. It means that when they look, there is something real to look at, structured the way a reviewer reads it, and honest about how each fact is known. That is what turns an AI governance questionnaire from a recurring fire drill into a record you own.

See the enterprise-questionnaire walkthrough in the worked examples, or read how the Governance Evidence Record is built.


The framework behind this approach, and the book that sets it out, are forthcoming. This article is general information, not legal, insurance or investment advice.

Register interest

If this is the workflow your team needs, register interest.