"Do you have an AI governance policy?" — the governance question
In some wording, this appears across the standard AI vendor assessments — the AI-CAIQ governance domain, the SIG 2026 AI domain, custom buyer spreadsheets — usually with "if yes, please attach." In a vendor of 10–50 people with no compliance hire, the honest answer is often "not as a document yet." Structured correctly, that is the kind of answer procurement teams routinely accept.
Why buyers ask this
The buyer's third-party-risk team needs evidence of one thing: that someone at your company owns AI risk, and a policy is the cheapest proxy. Around it they typically request the supporting artifacts — AI inventory, model provenance, AI subprocessors, data flows toward models, output controls — and increasingly want controls documented for a while (on the order of 90 days), not written the week the questionnaire arrived.
Worth knowing: Regulation (EU) 2024/1689 does not require a limited-risk vendor to have a document called an "AI governance policy." It imposes specific duties — Article 50 transparency from 2 August 2026 (not postponed by the Digital Omnibus), Article 4 AI literacy since 2 February 2025 — and the policy is how you show those duties have an owner.
What a minimum credible policy covers
Five elements. If your eventual document covers these and matches reality, it survives cross-checking:
- Inventory. One row per AI capability: model, provider, version, purpose, whether you fine-tune, processing region, and what customer data reaches it. This same inventory drives a third to half of any AI section — build steps in our method guide.
- Roles. Who approves a new AI feature or AI subprocessor, and who owns the policy. One named owner, not a committee.
- Review. A fixed cadence — e.g. quarterly — with the last review dated. An unreviewed policy reads as shelfware.
- Data rules. Which customer data may reach which model, your training/fine-tuning stance, and the provider agreements behind it.
- Transparency and literacy. How the product discloses AI interaction and marks synthetic content — the Article 50 duties applying from 2 August 2026; map yours with the free Article 50 checker, and note that shipping a third-party model under your own brand makes you the provider for Article 50(1). Plus AI literacy under Article 4 — applicable since 2 February 2025 and, since the Digital Omnibus, an obligation of means ("supporting the development") — evidenced by a staff briefing with completion records.
The honest answer structure
Use the gap formula procurement accepts: current state + compensating controls + "in progress" + a target date your leadership actually approved.
Template — orientation only. Adapt every bracket to what is actually true for your company; delete anything you don't do. Draft language for your review, not legal advice.
"A standalone AI governance policy document is not yet adopted. The following practices are in place today: we maintain an inventory of the AI capabilities in [your product], covering model, provider, purpose and the customer data each one processes; new AI features and AI subprocessors require approval by [named role]; AI-generated output in [workflow] is reviewed by [role] before it reaches customers; and staff working with AI systems complete an AI briefing, with completion recorded, in line with Article 4 of Regulation (EU) 2024/1689 (applicable since 2 February 2025). Consolidation of these controls into a formal AI governance policy is in progress, with adoption targeted for [date approved by your leadership]."
Every clause is checkable — exactly why it works. If a practice doesn't exist, don't write it: name the gap and give it its own dated step.
The mistake that costs deals
Attaching a template policy someone downloaded and nobody implemented. It feels like the fast "yes"; it is the expensive one. Reviewers read the policy against the rest of your answers: a document promising "all AI output is human-reviewed" while your product page advertises auto-send is a contradiction, and one contradiction taxes the credibility of every other answer — answers you may later be asked to warrant at contract stage. "Not yet, here is what runs today and the date" reads as competence; a fake policy reads as concealment. Same for certifications: if you don't hold ISO/IEC 42001, say so and describe what your governance program covers — never promise a certification date nobody approved.
Mini-FAQ
Is an AI governance policy legally required under the EU AI Act?
No — the Act imposes specific duties (Article 50 transparency from 2 August 2026; Article 4 literacy since 2 February 2025), not a document by that name. Buyers use the question to check those duties have an owner. ISO/IEC 42001 is voluntary too, though increasingly preferred in enterprise procurement.
We have real practices but no written policy — can we answer "yes"?
No. "Yes" implies a document the buyer can request and cross-check. State today's practices factually, then commit to consolidation with a date leadership has approved.
What does a minimum credible policy cover?
Inventory, roles, review cadence, data rules, and transparency-plus-literacy — the five elements above. A short document that matches reality beats a long one that doesn't.
Related: "Does your product make automated decisions about individuals?" · Just received the questionnaire? Start with the first-24-hours playbook.
- Regulation (EU) 2024/1689 — Art. 4, Art. 50, Art. 113
- Digital Omnibus, adopted 16/29 June 2026 (Art. 4 softened to "supporting the development"; Art. 50 dates unchanged)
- CSA AI-CAIQ (Oct 2025); Shared Assessments SIG 2026; ISO/IEC 42001