SecurityDraft / Resources / Deal stuck in security review
Founder's guide

Why your enterprise AI deal is stuck in security review — and how to unstick it

31 July 2026·7 min read·For B2B AI founders

You closed them on the product. Then their security team sent a spreadsheet, and the deal went quiet. Here's what's actually happening on the other side of that questionnaire — and a practical, honest way to get moving again.

Every founder selling AI into the enterprise hits the same wall. The demo went well. The champion loves you. Procurement even mentioned a start date. And then an email lands from someone you've never spoken to — "our security team just needs you to complete this" — with a 200-line questionnaire attached, and suddenly your deal is somebody else's ticket in somebody else's backlog.

A stalled deal doesn't feel like a lost deal, which is exactly why it's dangerous. It feels like a delay. But a questionnaire that sits idle for three days can slide a deal into the next quarter, and enterprise budget cycles are unforgiving about quarters. The revenue you've already earned — the product they want, the champion who's sold internally — is now frozen behind an artifact you haven't produced. So it's worth understanding precisely what that artifact is and why it stops deals cold.

Why security review exists — and why AI made it harder

Enterprise security review isn't bureaucracy for its own sake. A buyer's security team owns a real risk: they are about to route their data, and sometimes their customers' data, through your systems. If something goes wrong, they answer for it. The questionnaire is how they build a defensible record that they did their diligence before signing.

For years that record was cloud-shaped: where do you host, how do you encrypt, who are your sub-processors, show me your SOC 2. If you're an AI vendor, you can answer most of that — but your buyer's reviewer now has a second layer of questions that didn't exist three years ago:

  • Do you train your models on our data? The single most-asked question, and the one most likely to kill a deal if the answer is vague.
  • Which model providers do you call? If you're an application-layer vendor calling OpenAI, Anthropic or Bedrock, that's now part of their supply chain, and they need to see it.
  • Where is our data processed and stored, and for how long? Including whatever leaves your boundary to reach a model provider.
  • How do you handle prompt injection, model output safety, and tenant isolation? AI-specific attack surface a cloud questionnaire never covered.
  • Where's your governance? Increasingly framed against the EU AI Act, ISO/IEC 42001 or the NIST AI Risk Management Framework.

The reviewer isn't trying to catch you out. They're trying to close a gap in their own knowledge with evidence they can file. The deal stalls not because your answers are bad, but because you haven't given them anything to file at all.

Why founders freeze here specifically

If you're a twelve-person company, you almost certainly don't have a GRC hire, a compliance function, or a trust page. So the questionnaire lands on the founder or the head of sales — the two people whose time is worth the most and whose calendars are the fullest. It's genuinely hard work: each question needs a precise, defensible answer assembled from architecture you carry in your head, a sub-processor list that lives in three places, and a DPA you signed and never reread.

So it slips. It's never the most urgent thing on any given day, right up until the buyer's champion emails to say the security team has "paused" the review. By then you're not answering a questionnaire, you're reviving a deal.

The honest bit More than half of companies report losing deals to unfinished security questionnaires, and most take more than two weeks to complete one by hand. The instrument is real, the delay is real, and the cost — often quoted at tens to hundreds of thousands in delayed revenue per stalled deal — is why this is worth solving properly rather than winging.

How to unstick it

You don't need to become a compliance company. You need to produce three things a reviewer can actually accept, and produce them once so the next deal doesn't restart from zero.

1. Answer the AI-CAIQ, not just their spreadsheet

Most enterprise AI questionnaires are converging on a common source: the Cloud Security Alliance's AI-CAIQ, the AI companion to the questionnaire enterprises have used for cloud vendors for years. If you answer that well — across its 18 control domains — you've answered most of what any buyer will send you, in the structure their reviewer already recognises. Our free AI-CAIQ starter worksheet walks through the twenty highest-frequency questions in plain language, so start there.

2. Publish a trust page so you pre-answer the first question

A single page on your own domain — posture, AI-specific controls, sub-processors, data-handling, model governance — turns the reviewer's opening email into a link your sales team sends before they even ask. It won't finish the review, but it changes the tone of it from "prove you're safe" to "confirm what I already read."

3. Map your answers to the frameworks the reviewer works from

A reviewer working against the EU AI Act, ISO/IEC 42001 or NIST AI RMF is looking for your answers indexed to their framework. A short cross-framework appendix means whichever of the three they use, they find what they need without a follow-up email — and every follow-up email is another week.

The goal isn't to pass an audit. It's to hand the reviewer a complete, credible, filed-and-forgotten record — fast — so the deal moves before the quarter turns.

Answer it once, verify it, and own it

Whatever route you take — a weekend with our free worksheet, a contractor, or us — hold onto one principle: the answers have to be yours. A security questionnaire is a set of representations you make to your buyer. Nobody can honestly certify those for you off a stack of your docs, and you should be wary of anyone who says they can. What you can do is get the whole pack drafted from your own material, then review, verify, correct and sign off every line so it's genuinely true — and genuinely yours.

That's the entire idea behind SecurityDraft: we turn the documentation you already have into the completed AI-CAIQ, the trust page and the framework mapping, drafted and ready. You review it, sign off, and it's yours to hand your buyer — your representations, in your voice, on your domain. We draft; you own and verify. We don't audit, attest, assure or certify, and we'll always say so plainly.

Unstick the deal

Send us your docs. Hand your buyer a finished pack this week.

A completed AI-CAIQ, a public trust page, and EU AI Act / ISO 42001 / NIST AI RMF mapping — drafted from your own material, for you to verify and sign off. Fixed price from £900 ex-VAT, turnaround in days.

Free Prefer to start yourself? Grab the AI-CAIQ starter worksheet — the 20 most-asked questions, what each is really probing, and an honest answer pattern for each. Free, no sign-up.

enquiries@securitydraft.com

SecurityDraft drafts prepared responses from information you supply. You review, verify, correct and sign off every answer; the answers are your representations to your buyer. Not an audit, attestation, assurance or certification.