Supply chain security questionnaires have quietly grown an AI section. If you handle customer data and use AI anywhere near it, the questions are coming, and they will arrive attached to a renewal with a deadline rather than as a friendly enquiry.

In short: Expect to be asked five things: whether you have an AI use policy and when it was last reviewed, which AI tools have access to customer data, whether customer data is used to train any model, whether any decision affecting people is automated, and who is accountable when AI assisted output is wrong. None of these require sophisticated AI governance. They require you to have written down what you already do. The organisations that struggle are not the ones doing risky things, they are the ones that cannot evidence the sensible things they are doing.

Why this is happening now

Two forces are pushing in the same direction. Regulation has become concrete: the EU AI Act's transparency duties applied from August 2026, which we covered in what actually started, and the UK's rules on automated decisions were rewritten by the Data (Use and Access) Act, covered in what changed for UK employers.

The second force is simpler. Once a large customer has to answer these questions about itself, it pushes them down its supply chain, because your use of AI on their data is their exposure. That is how security questionnaires have always spread, and AI is following the same path faster than most.

The five questions

Do you have an AI use policy, and when was it last reviewed?

The date matters as much as the existence. A policy written eighteen months ago and untouched reads as a compliance artefact rather than a control. A short policy reviewed quarterly is a stronger answer than a long one reviewed never, which is the argument in writing an AI use policy people will actually follow.

Which AI tools have access to our data?

This is the one that catches people, because the honest answer requires an inventory most organisations have not built. It includes AI features inside products you already licensed, not just tools you consciously adopted. If you have not run a discovery pass, finding shadow AI is where to start, and it is considerably easier to do now than in the week a questionnaire lands.

Is our data used to train models?

Know the answer for each tool, and be able to point at where the vendor says so. For Microsoft 365 Copilot, prompts and responses stay within the tenant boundary and are not used to train the foundation models, which is a materially different answer from a free consumer tool. That distinction is the entire argument for providing a sanctioned option.

Is any decision affecting people automated?

Hiring, credit, access, service levels. If the answer is yes, expect follow ups about human review and the ability to contest, because those are now statutory safeguards in the UK rather than good practice.

Who is accountable when the output is wrong?

The expected answer is a named human role, not a process. "The AI drafts, a named person reviews and signs" is a complete answer. "We use AI responsibly" is not.

"Nobody expects a small business to have an AI governance function. They expect you to know which tools can see their data, and to be able to say so without a two week delay."

Three areas AI supply-chain questionnaires focus on: data use, governance and sub-processors
Supply-chain questionnaires cluster around the same three areas. Answer them once, properly.

Prepare the answers once

The cost of being asked is not the risk, it is the scramble. Every questionnaire is slightly different and they all arrive at the worst moment.

  • Build the tool inventory and keep it somewhere findable, with the vendor's training and data residency position recorded next to each entry.
  • Write the policy short and date it. One page, reviewed quarterly.
  • Record where automated decisions happen, including vendor features you did not commission.
  • Name the accountable roles, not individuals, so the answer survives someone leaving.
  • Keep a standard response document. Most questionnaires ask the same five things in different words. Answer them once properly and reuse.

The commercial angle

There is an upside worth naming. Most of your competitors will answer these badly, because they will answer them from memory in a hurry. Being able to respond quickly, specifically and with dates on things is a differentiator in a procurement process, and increasingly it is a qualifier rather than a bonus.

Treat it as sales enablement rather than compliance overhead and the work gets funded far more easily. If you want help building the inventory and the standard responses, that sits across our AI advisory work and our compliance packs and audit readiness service, and the compliance pack starter kit is a practical place to begin.

RM
Ryan Mangan

Founder & CTO of Systech IT Solutions, Microsoft MVP and Chartered Fellow of the BCS, and author of the bestselling Mastering Azure Virtual Desktop. Ryan has spent nearly two decades helping organisations adopt Azure, Microsoft 365 and modern workspace technology pragmatically.