The questionnaire in the inbox
A large customer's procurement team has sent their annual supplier questionnaire, and this year there is a new section. Do you use artificial intelligence in delivering our services? Which tools? Is our data entered into them? Is it used to train models? Where is it processed? Who approved it? The deadline is close and the account manager has forwarded it to you with a note: "can you fill in the AI bit?"
You start to answer and realise you do not know. You know the business pays for Microsoft 365, and you think Copilot is switched on for some people. The marketing team uses something for writing. Support might have an AI feature in the helpdesk. Someone mentioned transcribing client calls. Whether any of this touches this customer's data is a guess, and guessing in a document your customer may later rely on is a bad idea.
Why nobody can answer
AI arrived in most businesses sideways. It came as features switched on inside software you already had, as tools individual staff started using, and as small experiments that quietly became part of the routine. None of it went through a buying process that would have recorded what it does with data.
So the knowledge is spread across people and admin consoles. IT knows some of it, team leads know other parts, and individual staff know what they personally use. Nobody has pulled it together, because until customers started asking, there was no reason to.
What a weak answer costs
| Response | What can follow |
|---|---|
| An optimistic guess | A written statement that turns out to be untrue if something goes wrong |
| "We do not use AI" | Contradicted the first time an AI feature is spotted in your service |
| A vague answer | Follow-up questions, delays, and a lower supplier score |
| A missed deadline | Procurement reviews stall and renewals slip |
| Answers that differ by customer | Inconsistency that is noticed when customers compare notes or audit |
The questionnaires are also getting more detailed each year. An answer cobbled together once has to be cobbled together again next time, usually by someone else.
How we build the facts you answer from
- We collect evidence of AI use from the places it shows up: admin consoles for Microsoft 365, Google Workspace and your main software, expense and card data for AI subscriptions, browser and network logs where you have them, and short conversations with each team.
- For each tool we record what it is used for, who uses it, which kinds of data go into it, which company account or licence it runs under, where it processes data and what its published terms say about training and retention.
- We check which of those uses touch customer data, and which customers, because the answer to a questionnaire is often different for different contracts.
- Where we find practices you would not want to describe to a customer, such as client material going into personal accounts, we flag them and help you move that work onto an approved tool before you answer.
- We turn the result into an AI use register and a set of standard answers to the questions customers commonly ask, which your team can adapt for each questionnaire.
- We set up a light review, prompted by new software purchases and a periodic check of admin consoles, so the register stays current rather than going stale after the first questionnaire.
We describe what is actually in place. We do not write answers that promise controls you do not have, and we will point out any question where the honest answer is "not yet".
What your team has afterwards
When the next questionnaire arrives, the account manager has a register and a set of reviewed answers to work from. Filling in the AI section becomes a matter of checking which parts apply to this customer, not an investigation.
You also know things you did not know before: where customer data meets AI, where the terms are fine and where they are not. That is useful well beyond questionnaires, for your own policy, for insurance conversations, and for the board.
And because the answers come from a real picture, they are the same in every document. The response you give one customer matches the one you gave another, and both match what is actually happening.
Is this your situation?
- Customers or prospects have started asking about your AI use in questionnaires or contract reviews.
- Nobody could list every AI tool used across the business.
- AI features have been switched on inside software without a formal decision.
- You are not sure whether any customer data has gone into AI tools.
- Previous answers were written from memory and may not match each other.