How to answer the AI section of a customer due-diligence questionnaire

A customer's procurement team has sent a questionnaire with an AI section on it, and a deal is sitting behind your answer. Here's how to approach it.

If you’re reading this, a customer’s procurement or security team has probably just sent over a due-diligence questionnaire, and somewhere in it is a section asking about AI: what models you use, what data goes into them, who reviews the outputs, how you handle incidents.

A deal is sitting behind your answer, and the straight response to most of it is “we’re not sure.”

That’s a normal position to be in. Here’s how to work through it without either overclaiming or stalling the deal.

Separate what you can answer from what you can’t

Before writing anything, go through the questionnaire line by line and sort each question into one of three piles:

  • Answerable today, from something you already have in writing (a policy, a data processing agreement, an architecture diagram).
  • Answerable, but nobody’s written it down yet: you know the answer, it just doesn’t exist as a document you can point to.
  • Nobody knows: nobody in the business could currently give a confident, consistent answer if two different people were asked.

Most organisations are surprised by how much falls into the second and third piles even when the underlying practice is fine.

That’s usually a documentation gap rather than a governance failure, and it’s worth knowing which one you’re dealing with before you respond to anyone.

Don’t guess, and don’t stall

Two responses are both worse than a straight partial answer.

Guessing at something that turns out to be wrong is discoverable, and it damages trust permanently. Going silent while you scramble to build a policy from scratch reads as evasion to a procurement team that’s seen it before, and it’s usually the slower path anyway.

The better move is a direct one: answer what you can from real evidence, say plainly which questions need a short follow-up, and give a realistic date for the rest.

Most procurement processes have room for that if you’re upfront early. They have very little room for it if you stop responding and it turns out to have been avoidable.

What the questions are testing

Underneath the specific wording, most AI due-diligence questionnaires are checking for the same handful of things:

  • Do you know what AI is in use across your business, including tools that weren’t formally approved?
  • Is there a human in the loop for decisions that affect the customer, and is that documented rather than assumed?
  • What happens to the customer’s data once it touches an AI system, and does any of it leave your control?
  • If something goes wrong, is there a known process, or does it get handled ad hoc?
  • Who is accountable for AI risk internally, by name, not by department?

If you can answer those five in plain language, you can answer most of what’s in the questionnaire, whatever words it uses to ask.

Where this leads

Answering one questionnaire under time pressure is manageable.

The pattern that catches most software companies out is answering the same questions from a different customer three months later, having changed nothing in between.

If this is the first time you’ve been asked, treat it as the moment to build the answer properly rather than the moment to survive one deal.


We’re 10 Kinds, a UK AI consultancy. We map where AI is being used in a business, put governance around it, get you to the point where you can prove it to a customer or a regulator, and then build the systems that make it pay. If you want a second pair of eyes on a specific questionnaire, book a free call, or take the free AI Readiness Checklist to find the gaps before the next one arrives.