The AI module: the questionnaire section where deals stall.
Why the module exists
Buyers did not invent the AI module to punish vendors. It exists because the buyer's own regulators, boards and customers now ask them about the AI in their supply chain — and the buyer has no way to answer without asking you. Every question in the module is a question someone senior at the buyer has been asked and could not answer without a file from the vendor. The questionnaire is how that pressure is pushed down the chain to the party that actually has the information: the AI provider.
Understanding this shifts the posture. The reviewer is not adversarial; they are trying to build a defensible file for someone above them. A vendor who makes that easy wins the review. A vendor who makes it hard, however good the underlying product, does not.
The questions it asks
The AI module tends to open along the same seams whichever questionnaire it sits inside: inventory and ownership, certification or roadmap, provenance and rights, human oversight, bias testing, sub-processors, incidents. Each of these has a right shape of answer — factual, cited, dated — and a wrong shape — a paragraph attached to nothing.
The Answer Library carries a model answer for each named question below, together with the evidence a reviewer expects to see behind it and the reason weak answers fail.
- How AI systems are inventoried, owned and reviewed →
- ISO/IEC 42001 — certified or on a documented roadmap →
- Alignment with the NIST AI Risk Management Framework →
- EU AI Act classification and the obligations that follow →
- Training-data provenance and rights of use →
- Model cards, capabilities and documented limitations →
- How human oversight is designed and operated →
- Bias testing, fairness evaluation and remediation →
- AI sub-processors and the AI supply chain →
- AI-specific incident response and buyer notification →
Why vendors fail it
These are not hard questions in isolation. Any founder can describe how their organisation reviews an AI system, in the abstract, at a whiteboard. The failure is not intellectual, it is evidential: the organisation has nothing that produces the artefacts the answers require. There is no register to point at, no dated risk assessment, no sign-off record, no supplier assessment on file for the AI sub-processor. The answers exist in the founder's head; the file the reviewer needs does not exist anywhere.
This is why the AI module is where deals stall. The buyer is willing; the product is bought; the review cannot conclude because the paper is not there.
Pass it from a record
Import your controls and vendors, answer each question cited to a sealed record, and hold open honestly the ones you cannot yet ground. When the reviewer spot-checks, the citation opens; when a gap is real, the interim control and the date read as maturity, not evasion. This is the motion Hael runs: one record, sealed documents, cited answers, honest gaps.