Insights

The AI governance baseline: what a customer audit or board actually asks for

AI governance sounds like a problem for companies with compliance departments. Then an enterprise customer sends a security questionnaire with a new section in it, and a mid-market company with no compliance department has two weeks to answer questions it has never asked itself. This article lists what those questions are, who asks them, and what the single document that answers them contains, so you can write it before the deadline arrives rather than during.

The moment it becomes real

Governance requests arrive from three directions, usually without warning.

Enterprise customers. Standard security questionnaires now carry AI-specific sections, and specialist AI questionnaires run to 40 questions. The customer is not being difficult. Their own regulators and boards are asking them what their vendors do with data, and you are a vendor.

Your board. “What is our AI strategy” has a follow-up now: what is our AI exposure. A director who has read one article about AI liability will ask what data your tools touch and who approved them.

Regulators, if you touch Europe. The EU AI Act is mandatory for companies placing or deploying AI systems in EU markets, with penalties for serious violations reaching €35 million or 7% of global turnover. Most mid-market companies fall outside its high-risk categories, but “we checked and here is why we are out of scope” is itself a governance answer, and someone has to produce it.

The questions you will actually be asked

Across customer questionnaires the same core questions repeat, and they are worth reading twice because most companies cannot answer any of them today.

Is our data used to train your models or your vendors’ models? How long are prompts and outputs retained, and where? Which AI providers sit in the path of a request, including the ones behind your tools? What can your AI systems do without a human approving the action? What personal or regulated data do your AI tools process, and under what terms? Who approved each tool, and when was that approval last reviewed? What happens when an AI system produces a harmful or wrong result, and who gets told?

Notice what these questions have in common: none asks about your ambitions, and every one asks what is factually true about tools you already run. Answering them is an inventory exercise with consequences, which is why a strategy document, however good, answers none of them.

The gap most companies are carrying

The uncomfortable pattern in the research: a 2025 industry survey found 55% of employees admitting to AI tools their organisation never approved, while only 37% of organisations had any policy for managing or detecting such use. The gap between those numbers is unapproved tools processing company data with nobody watching, and it is the largest single exposure most mid-market companies hold right now: current, unlogged, unreviewed use, rather than any hypothetical future model risk.

This is why the questionnaire moment is dangerous. The company that discovers its real tool inventory while answering a customer’s questions has already lost control of the answer.

What the baseline document contains

The fix is one document, the governance baseline, and it is shorter than the word governance suggests. Five sections.

The tool inventory: every AI tool in use, sanctioned or discovered, with owner, cost, and data touched. The data map: which categories of company, customer, and personal data each tool processes, and what each vendor’s terms permit, including training use and retention. The policy: which uses are approved, which are banned, and how a new tool gets requested and reviewed, written in one page a normal employee will actually read. The accountability line: one named owner for AI decisions, and the escalation path when something goes wrong. The review rhythm: how often the inventory and policy get re-checked, because a baseline from last year describes a company that no longer exists.

On frameworks: you do not need to adopt one wholesale. The NIST AI Risk Management Framework is voluntary and sensibly structured, and mapping your baseline loosely to it means enterprise customers recognise the shape of your answers. ISO 42001 certification is worth considering only when large customers start requiring it in procurement, which is beginning to happen. Certification is a purchase decision. The baseline is hygiene.

Who should write it

The baseline fails when written by committee and when written by whoever had spare time. It needs one author with two qualities: enough seniority to declare a tool banned and make it stick, and enough grounding in AI governance to know what a customer’s auditor will accept. Formal credentials such as the IAPP’s Artificial Intelligence Governance Professional certification exist for exactly this grounding. This is a standing part of what a fractional Chief AI Officer produces, and it lands in month three of a normal engagement, as covered in What a fractional CAIO does in the first 90 days.

If no such person exists in your company yet, the honest sequencing question is whether the role is needed at all, which we treat in Do you really need a Chief AI Officer? And if you want the inventory and data map built independently as a one-time exercise, before any questionnaire forces the timing, that is what our diagnostic produces.

Questions this article answers

What do enterprise customers ask about AI in security questionnaires?

Whether their data trains your models, how prompts and outputs are retained, which AI providers sit behind your tools, what your systems can do without human approval, what regulated data your tools process, who approved each tool, and how failures are escalated.

What is an AI governance baseline?

A single document with five parts: a complete AI tool inventory, a data map showing what each tool processes and under what vendor terms, a one-page use policy, a named accountable owner with an escalation path, and a defined review rhythm.

Do mid-market companies need ISO 42001 or the EU AI Act?

The EU AI Act applies only if you place or deploy AI systems in EU markets, and most mid-market use falls outside its high-risk categories, though confirming that in writing is itself required work. ISO 42001 is voluntary and only worth pursuing when enterprise customers demand it in procurement. A baseline mapped loosely to the NIST AI RMF covers most companies today.

Bring independent judgment into the room.