Why your enterprise AI deal is stuck in security review — and how to unstick it
You closed them on the product. Then their security team sent a spreadsheet, and the deal went quiet. Here's what's actually happening on the other side of that questionnaire — and a practical, honest way to get moving again.
Every founder selling AI into the enterprise hits the same wall. The demo went well. The champion loves you. Procurement even mentioned a start date. And then an email lands from someone you've never spoken to — "our security team just needs you to complete this" — with a 200-line questionnaire attached, and suddenly your deal is somebody else's ticket in somebody else's backlog.
A stalled deal doesn't feel like a lost deal, which is exactly why it's dangerous. It feels like a delay. But a questionnaire that sits idle for three days can slide a deal into the next quarter, and enterprise budget cycles are unforgiving about quarters. The revenue you've already earned — the product they want, the champion who's sold internally — is now frozen behind an artifact you haven't produced. So it's worth understanding precisely what that artifact is and why it stops deals cold.
Why security review exists — and why AI made it harder
Enterprise security review isn't bureaucracy for its own sake. A buyer's security team owns a real risk: they are about to route their data, and sometimes their customers' data, through your systems. If something goes wrong, they answer for it. The questionnaire is how they build a defensible record that they did their diligence before signing.
For years that record was cloud-shaped: where do you host, how do you encrypt, who are your sub-processors, show me your SOC 2. If you're an AI vendor, you can answer most of that — but your buyer's reviewer now has a second layer of questions that didn't exist three years ago:
- Do you train your models on our data? The single most-asked question, and the one most likely to kill a deal if the answer is vague.
- Which model providers do you call? If you're an application-layer vendor calling OpenAI, Anthropic or Bedrock, that's now part of their supply chain, and they need to see it.
- Where is our data processed and stored, and for how long? Including whatever leaves your boundary to reach a model provider.
- How do you handle prompt injection, model output safety, and tenant isolation? AI-specific attack surface a cloud questionnaire never covered.
- Where's your governance? Increasingly framed against the EU AI Act, ISO/IEC 42001 or the NIST AI Risk Management Framework.
The reviewer isn't trying to catch you out. They're trying to close a gap in their own knowledge with evidence they can file. The deal stalls not because your answers are bad, but because you haven't given them anything to file at all.
Why founders freeze here specifically
If you're a twelve-person company, you almost certainly don't have a GRC hire, a compliance function, or a trust page. So the questionnaire lands on the founder or the head of sales — the two people whose time is worth the most and whose calendars are the fullest. It's genuinely hard work: each question needs a precise, defensible answer assembled from architecture you carry in your head, a sub-processor list that lives in three places, and a DPA you signed and never reread.
So it slips. It's never the most urgent thing on any given day, right up until the buyer's champion emails to say the security team has "paused" the review. By then you're not answering a questionnaire, you're reviving a deal.
How to unstick it
You don't need to become a compliance company. You need to produce three things a reviewer can actually accept, and produce them once so the next deal doesn't restart from zero.
1. Answer the AI-CAIQ, not just their spreadsheet
Most enterprise AI questionnaires are converging on a common source: the Cloud Security Alliance's AI-CAIQ, the AI companion to the questionnaire enterprises have used for cloud vendors for years. If you answer that well — across its 18 control domains — you've answered most of what any buyer will send you, in the structure their reviewer already recognises. Our free AI-CAIQ starter worksheet walks through the twenty highest-frequency questions in plain language, so start there.
2. Publish a trust page so you pre-answer the first question
A single page on your own domain — posture, AI-specific controls, sub-processors, data-handling, model governance — turns the reviewer's opening email into a link your sales team sends before they even ask. It won't finish the review, but it changes the tone of it from "prove you're safe" to "confirm what I already read."
3. Map your answers to the frameworks the reviewer works from
A reviewer working against the EU AI Act, ISO/IEC 42001 or NIST AI RMF is looking for your answers indexed to their framework. A short cross-framework appendix means whichever of the three they use, they find what they need without a follow-up email — and every follow-up email is another week.
Answer it once, verify it, and own it
Whatever route you take — a weekend with our free worksheet, a contractor, or us — hold onto one principle: the answers have to be yours. A security questionnaire is a set of representations you make to your buyer. Nobody can honestly certify those for you off a stack of your docs, and you should be wary of anyone who says they can. What you can do is get the whole pack drafted from your own material, then review, verify, correct and sign off every line so it's genuinely true — and genuinely yours.
That's the entire idea behind SecurityDraft: we turn the documentation you already have into the completed AI-CAIQ, the trust page and the framework mapping, drafted and ready. You review it, sign off, and it's yours to hand your buyer — your representations, in your voice, on your domain. We draft; you own and verify. We don't audit, attest, assure or certify, and we'll always say so plainly.
Send us your docs. Hand your buyer a finished pack this week.
A completed AI-CAIQ, a public trust page, and EU AI Act / ISO 42001 / NIST AI RMF mapping — drafted from your own material, for you to verify and sign off. Fixed price from £900 ex-VAT, turnaround in days.
enquiries@securitydraft.com