For AI-native SaaS companies

Enterprise buyers now vet your AI. Your deal stalls in security review until you can answer.

The vendor security questionnaire has a new section: how you govern the AI in your product. If your AI features aren’t mapped and your governance isn’t written down, the deal waits — in the security review, behind an answer you can’t yet give. We fix that by mapping your AI and giving you an ISO/IEC 42001-aligned AI management system and the answers to match — answer-ready within 30 days (max), before your deal stalls.

Book a 20-minute callFixed price · Answer-ready before your deadline, or you don’t pay

The gate you’re already at

You don’t need to be certified for AI governance to be a deal problem.

Some enterprise buyers now name ISO/IEC 42001 in the questionnaire. Many just fold AI questions into the data, security and subprocessor sections. It makes less difference than teams assume, because the thing that stalls the deal doesn’t depend on being asked directly.

The security review is now the gate

SOC 2 became table stakes; the AI section is the new hold-up. Procurement teams have added AI-governance questions to vendor security reviews and RFPs, and the deal doesn't move until they're answered to the reviewer's satisfaction.

Enterprise procurement, 2026

AI is the thing nobody documented

You shipped the AI features fast. The governance behind them — what data trains them, who oversees them, how risk is assessed — was never written down. Models get added inside the stack the way shadow AI arrives anywhere: quietly, unregistered, unassessed.

Shadow AI

And "we take it seriously" isn't evidence

Reviewers want artefacts: an AI inventory, a management system, risk assessments, oversight records. An assurance in a sales call doesn't clear the review. The gap between what you say and what you can produce is exactly what the questionnaire surfaces.

Assertions aren't evidence

What you’re already being asked

The questions are on the questionnaire today. AI is what makes them hard to answer.

These aren’t exotic questions. They’re the technology-and-security section of a standard enterprise vendor review — and every one gets harder once you accept that AI is in your product and nobody has mapped how it’s governed.

AI management system

Do you operate a documented AI management system aligned to a recognised standard?

You tick yes. Aligned to what — and can you show the system, or just the intention?

Data & IP

What data trains or feeds your models, and how are confidentiality and IP protected?

Including the customer data your feature quietly sends to a third-party model API?

Human oversight

How is human oversight applied to AI outputs, and who is accountable for them?

Named and evidenced — or a gap the reviewer finds before you do?

Risk & monitoring

Provide evidence of AI risk assessment and ongoing monitoring of model behaviour.

Can you produce the document today, or would you be writing it during the review?

Subprocessors

List the AI models and subprocessors in your product and how each is risk-assessed.

The model API in your stack is a subprocessor. Have you assessed it as one?

Phase one

The Enterprise AI-Trust Sprint

Answer-ready, before the review stalls the deal. In 30 days: your AI mapped, an ISO/IEC 42001-aligned management system in place, and the security-review answers written to drop straight in. Fixed price. You keep everything, whether or not you go further.

AI footprint & systems inventory

The inventory buyers ask for

Every model, tool and AI feature in the product and the business — in which process, on what data, with an owner against each. The document the reviewer wants to see, and the one nobody could produce before.

ISO/IEC 42001-aligned AI management system

The artefacts the review demands

AI policy, controls, risk assessments and human-oversight records — a real management-system baseline aligned to ISO/IEC 42001, crosswalked to NIST AI RMF and the EU AI Act where they apply. Not a template; a system you can stand behind.

Completed security-review answers + evidence pack

The deliverable you submit

The AI section of the questionnaire, drafted to submit and backed by the artefacts underneath each answer — so a follow-up from the reviewer has a documented response, not an improvised one.

Certification path, costed

Makes the next decision concrete

A fixed-price scope for full ISO/IEC 42001 (or SOC 2 / ISO 27001) certification readiness, with handoff to an accredited certification body or auditor — so the bigger decision is a known quantity, not open-ended fees.

Duration
30 days (maximum)
Price
Fixed — [PRICE]
Guarantee
Answer-ready before your deadline, or you don’t pay
If you proceed
Sprint fee credited against certification support

Phase two · optional

Then: the certification, and the team.

Phase one makes you answer-ready. Phase two turns the baseline into a certifiable system and gets your team to run it — aligned with ISO/IEC 42001, without pretending certification is something we issue.

Certification support

The build that takes you from answer-ready to certification-ready — the full AI management system, evidence and audit preparation for ISO/IEC 42001 (and SOC 2 / ISO 27001 readiness alongside), with handoff to the accredited certification body or CPA / ISAE 3000 auditor who issues the report.

  • Full ISO/IEC 42001 management system and evidence base
  • SOC 2 / ISO 27001 readiness, using the shared control overlap
  • Audit / certification-body coordination and preparation
  • The permanent evidence pack, so the next questionnaire is a copy-paste

Team enablement

Practical and role-level, not a compliance lecture — because the risk is an engineer wiring a new model into the product with no oversight step, or a rep promising controls that don’t exist.

  • What the approved models and tools are, and how to use them
  • Data, IP and what never leaves your environment into a public model
  • EU AI Act AI-literacy for teams with EU exposure
  • Attendance records you can evidence to a buyer

Honest fit

Who this is for — and who it isn’t.

A good fit if

  • You’re an AI-native or AI-enabled B2B SaaS company, roughly Seed to Series B
  • You sell into enterprise or regulated buyers — or want to
  • AI is in your product, and the governance behind it isn’t written down
  • A deal has stalled (or you expect one to) on the AI part of a security review
  • You have no in-house GRC or AI-governance function doing this actively

Not a good fit if

  • You have a mature security/GRC function already running this
  • You’ve already got an AI management system and can evidence it
  • You want us to issue a SOC 2 report or ISO certificate — we can’t; that’s the auditor’s, and we hand you off
  • You want a policy document with nothing behind it

Who you’d be working with

We don’t sell paperwork.

A policy that claims a control you don’t run is worse than none. In a security review it isn’t a documentation problem — it’s an answer the reviewer can test. Everything we build is real, evidenced, and defensible. And where a report or certificate has to be issued, we’re honest that it comes from an accredited auditor, not from us — we get you ready and hand you over clean.

Certified ISO/IEC 42001

Standards

Committee member, BSI & ISO technical committees

Delivery

Regulated, sensitive-data environments

Questions

What founders ask us.

There's no AI question on the security reviews we're getting.

There may not be a labelled one yet — some buyers name ISO/IEC 42001, many fold AI into the data, security and subprocessor sections. But the review already asks what data feeds your systems, how third parties are assessed, and who's accountable. AI doesn't need its own question to make those answers harder to stand behind — and the deal still waits on them.

We're not selling to enterprise yet. Why now?

Because it's a gate on your first enterprise deal, and you can't build an AI management system in the fortnight a hot deal gives you. Doing it cold, mid-review, is where answers get overstated — and an overstated security answer is the kind of thing that surfaces later, at the worst possible time. Answer-ready on the shelf turns the review from a scramble into a copy-paste.

We already have an AI policy.

Then you're ahead of most companies your size. The harder question is whether the policy matches what you actually ship, and whether you can produce the evidence behind it. A policy that doesn't reflect real usage is a written statement a reviewer can measure you against — and it isn't a management system either.

Does this make us ISO 42001 certified?

No. This is a lightweight, ISO/IEC 42001-aligned governance baseline that gets you answer-ready without the weight or cost of a full certification programme. It's the right foundation if you certify later — and if you do, the certificate is issued by an accredited certification body, not by us. The point of the Sprint is to let you answer buyers now.

Can't our SOC 2 tool (Vanta, Drata) handle this?

Those platforms automate evidence collection for controls you've already defined. They don't design your AI governance, decide which AI risks matter for your product, or write the AI answers a reviewer will probe. That design and judgement is the part we do — and it's the part the questionnaire is actually testing.

Will this slow the product team down?

The opposite is the intention. Most teams are stuck between a blanket "no AI tools" nobody follows and a free-for-all nobody can evidence. Approved models, clear controls and an oversight trail are what let you keep shipping AI and answer the buyer — rather than freezing every time a security review lands.

Before your next enterprise deal stalls

Could you answer the AI section of a security review today?

A 20-minute call. We’ll walk the AI questions enterprise buyers are already asking — and you’ll leave knowing whether you could answer them, on the record, with evidence. Whether or not you work with us.

Book a 20-minute call