Answer guide

"Do you have an AI governance policy?" — the governance question

In some wording, this appears across the standard AI vendor assessments — the AI-CAIQ governance domain, the SIG 2026 AI domain, custom buyer spreadsheets — usually with "if yes, please attach." In a vendor of 10–50 people with no compliance hire, the honest answer is often "not as a document yet." Structured correctly, that is the kind of answer procurement teams routinely accept.

Why buyers ask this

The buyer's third-party-risk team needs evidence of one thing: that someone at your company owns AI risk, and a policy is the cheapest proxy. Around it they typically request the supporting artifacts — AI inventory, model provenance, AI subprocessors, data flows toward models, output controls — and increasingly want controls documented for a while (on the order of 90 days), not written the week the questionnaire arrived.

Worth knowing: Regulation (EU) 2024/1689 does not require a limited-risk vendor to have a document called an "AI governance policy." It imposes specific duties — Article 50 transparency from 2 August 2026 (not postponed by the Digital Omnibus), Article 4 AI literacy since 2 February 2025 — and the policy is how you show those duties have an owner.

What a minimum credible policy covers

Five elements. If your eventual document covers these and matches reality, it survives cross-checking:

The honest answer structure

Use the gap formula procurement accepts: current state + compensating controls + "in progress" + a target date your leadership actually approved.

Template — orientation only. Adapt every bracket to what is actually true for your company; delete anything you don't do. Draft language for your review, not legal advice.

"A standalone AI governance policy document is not yet adopted. The following practices are in place today: we maintain an inventory of the AI capabilities in [your product], covering model, provider, purpose and the customer data each one processes; new AI features and AI subprocessors require approval by [named role]; AI-generated output in [workflow] is reviewed by [role] before it reaches customers; and staff working with AI systems complete an AI briefing, with completion recorded, in line with Article 4 of Regulation (EU) 2024/1689 (applicable since 2 February 2025). Consolidation of these controls into a formal AI governance policy is in progress, with adoption targeted for [date approved by your leadership]."

Every clause is checkable — exactly why it works. If a practice doesn't exist, don't write it: name the gap and give it its own dated step.

The mistake that costs deals

Attaching a template policy someone downloaded and nobody implemented. It feels like the fast "yes"; it is the expensive one. Reviewers read the policy against the rest of your answers: a document promising "all AI output is human-reviewed" while your product page advertises auto-send is a contradiction, and one contradiction taxes the credibility of every other answer — answers you may later be asked to warrant at contract stage. "Not yet, here is what runs today and the date" reads as competence; a fake policy reads as concealment. Same for certifications: if you don't hold ISO/IEC 42001, say so and describe what your governance program covers — never promise a certification date nobody approved.

Mini-FAQ

Is an AI governance policy legally required under the EU AI Act?
No — the Act imposes specific duties (Article 50 transparency from 2 August 2026; Article 4 literacy since 2 February 2025), not a document by that name. Buyers use the question to check those duties have an owner. ISO/IEC 42001 is voluntary too, though increasingly preferred in enterprise procurement.

We have real practices but no written policy — can we answer "yes"?
No. "Yes" implies a document the buyer can request and cross-check. State today's practices factually, then commit to consolidation with a date leadership has approved.

What does a minimum credible policy cover?
Inventory, roles, review cadence, data rules, and transparency-plus-literacy — the five elements above. A short document that matches reality beats a long one that doesn't.

Related: "Does your product make automated decisions about individuals?" · Just received the questionnaire? Start with the first-24-hours playbook.

Sources
  • Regulation (EU) 2024/1689 — Art. 4, Art. 50, Art. 113
  • Digital Omnibus, adopted 16/29 June 2026 (Art. 4 softened to "supporting the development"; Art. 50 dates unchanged)
  • CSA AI-CAIQ (Oct 2025); Shared Assessments SIG 2026; ISO/IEC 42001

This question is one of sixty in front of you?

Send the questionnaire — first 3 answers free within 24h, full delivery in 48h for $490 flat (up to 60 questions), paid after delivery. Judge the work on the public sample first.

Send your questionnaire →