What they are really asking, and why you keep rebuilding the answer.
You are selling into a bank, an insurer or a large enterprise, and the deal is going well until security and procurement get involved. A questionnaire arrives. It might be a SIG, a CAIQ, a bespoke AI governance addendum, or a page of questions a customer’s risk team wrote themselves. Somewhere in it: how does your model make decisions, what oversight sits around it, how do you manage model change, and what happens when it gets something wrong.
You answer it. Then the next customer sends a different questionnaire asking the same things in a different order, and you answer that one too, from scratch, pulling policies out of one place, tickets out of another, screenshots out of a third, and a founder’s memory out of a meeting. The deal waits while you assemble it.
The questionnaire is not really the problem. The problem is that the evidence behind your answers does not exist as a record you can reuse. Every buyer is asking you to reconstruct it, and you are reconstructing it every time.
What the questionnaire is actually asking for
Under the specific questions, an enterprise buyer is asking one thing: if we depend on your AI, can you show us what it does, on what basis, under whose authority, and how you know. They are not looking for a promise that your governance is good. They are looking for evidence they can put in their own file, because when their regulator or their board asks about the AI they brought in, the answer becomes their problem.
That is why “we take AI governance seriously” does not move a serious reviewer, and a screenshot of a policy does not either. The reviewer wants the underlying facts, organised, with each one showing how it is known. Describing your posture is not the same as evidencing a decision, and the questionnaire is really a request for the second thing wearing the clothes of the first.
Answer it once, from a record that already exists
Decision provenance is a record of what your system did, on what basis, under whose authority, and how each item was captured, kept so it can be reconstructed later. When that record exists, a questionnaire stops being a rebuild and becomes a mapping exercise: the request comes in, and each item is matched to evidence that is already there, marked present, partial or absent.
An honest record does not dress every fact up as equally solid. Some items come from the infrastructure that ran the decision, some are captured close to the event, some are reconstructed, and some are stated by a person. The record shows which is which. That honesty is not a weakness in front of a good reviewer. It is what makes the record credible, because a reviewer who has seen plenty of all-green dashboards trusts the one that admits where the evidence is thinner.
Custara prepares, structures and preserves that record and produces a scoped pack for the review in front of you. It does not answer the adequacy question for you. Whether your governance is good enough is the buyer’s call, not the record’s and not Custara’s.
Working papers you keep, not an audit you repeat
The reason you keep rebuilding is that you are treating each questionnaire as a fresh audit. The better model is one finance has used for a long time. Behind an audit sits a body of working papers: the underlying evidence, organised so someone else can follow how a conclusion was reached. You do not rebuild the working papers for every person who asks. You keep them, and you hand over what the question needs.
Decision provenance is the working papers for your AI. Keep the record current as the system changes, and each new questionnaire draws from the same evidence base rather than sending you back to policies and screenshots. A standard can define what the record should contain and how evidence quality is described, which is the work of the Decision Standards Institute, and an independent assessor can review the record separately, which is the role of Attestra. Custara prepares the record. It does not assess it, and it does not decide whether your buyer should accept it.
What this changes in a deal
The record exists before the question is asked, so the questionnaire stops setting your timeline. You are mapping a request to evidence you already hold, not manufacturing evidence under deal pressure. The same record answers the next buyer, the insurer at renewal, and your own board, because it was built once and kept, not rebuilt for each audience.
None of this promises the buyer will wave you through. It means that when they look, there is something real to look at, structured the way a reviewer reads it, and honest about how each fact is known. That is what turns an AI governance questionnaire from a recurring fire drill into a record you own.
See the enterprise-questionnaire walkthrough in the worked examples, or read how the Governance Evidence Record is built.
The framework behind this approach, and the book that sets it out, are forthcoming. This article is general information, not legal, insurance or investment advice.