What we tell people who ask whether AI belongs in compliance work
The honest answer is that it belongs in the reading and nowhere near the deciding. Here is where we draw that line and why we draw it there.
Read the articleTwo hundred rows arrive from a customer, due Friday, and the person who knows the answers is on leave. There is a way to make this a two hour job instead, and it starts long before the questionnaire arrives.

A customer sends a spreadsheet. Two hundred and forty rows, some of them asking the same thing three different ways, due by Friday. It lands with whoever is nearest, which is usually somebody in sales who forwards it to somebody in security who was already busy.
Every organisation above a certain size does this repeatedly, most of them badly, and almost nobody budgets for it. It is one of the largest hidden costs in a security function and it is almost entirely avoidable.
The work is not really answering the questions. It is four other things that hide inside the answering.
Finding out what is true. Nobody can answer a question about backup retention from memory, so each row becomes a small investigation involving at least one other person.
Deciding what you are willing to say. There is a difference between what is true, what is provable and what you want in writing to a third party. That judgement takes longer than the lookup.
Getting the wording right. A blunt no closes a deal. A vague yes creates an obligation you cannot meet. Most rows need a considered sentence rather than a checkbox.
Doing it again. The next questionnaire asks the same things in a different order with different wording, and because nothing was kept, the whole exercise repeats.
That last one is the expensive part, and it is the one worth fixing.

The single highest return change is to stop treating each questionnaire as a new piece of work and start treating it as a lookup against something you already maintain.
An answer library is a list of the questions you actually get asked, each with an approved answer, a named owner, a date it was last confirmed, and a link to the evidence behind it. That is it. It can live in a spreadsheet to begin with.
The first one costs you a week, which you were spending anyway. Every one after that gets faster, and the answers stop drifting apart because there is only one of each.
| Keep for each answer | Why it matters |
|---|---|
| The approved wording | So three people do not answer the same question three ways |
| A named owner | So somebody can be asked when it needs to change |
| Last confirmed date | So you know whether the answer is still true |
| A link to the evidence | So you can prove it when somebody asks for proof |
Here is the part most teams get wrong. They organise the library by customer, which means the next customer with slightly different wording starts from scratch again.
Organise it by control instead. One control, one approved description, one piece of evidence, and then map the incoming question to the control rather than to a previous answer. Questionnaires vary endlessly in wording. The underlying set of things they ask about is much smaller and quite stable.
This is the same principle that makes multi framework compliance manageable, and we have written about it at more length in one control, evidenced ten times over. It is also what ControlGraph is built to hold, because a customer questionnaire is just another regime asking a question you have already answered.
If you have answered a question before, answering it again should be a lookup. Anything else means you are paying for the same work twice.
There is a strong temptation to stretch. The question asks whether you do something quarterly, you do it roughly twice a year, and the deal is close.
Resist it, for two reasons that are both practical rather than moral.
The first is that questionnaire answers have a habit of becoming contractual. What you asserted turns up in an annex, and later in a dispute, and by then nobody remembers that it was a stretch made under time pressure.
The second is that a qualified answer is usually accepted. "Not currently, planned for the second quarter, here is the interim control" is a normal thing to write and it reads as an organisation that knows its own position. An unqualified yes that turns out to be optimistic reads very differently the day somebody checks.
Once the library exists, some of this genuinely does become mechanical.
Matching an incoming question to an answer you already hold is a text similarity problem, and machines are good at it. Drafting the first version of a response from an approved answer is the same. Both save real time.
What should not be automated is the send. Somebody has to read the draft and decide the organisation is willing to stand behind it, because that is what an assertion to a customer is. The same line we hold everywhere else applies here, and we set it out in whether AI belongs in compliance work.
Worth saying, since plenty of organisations send these as well as receive them.
A questionnaire tells you what a supplier was willing to assert on a particular Tuesday, usually completed at speed by somebody under deadline pressure. It is weak assurance. If a supplier genuinely matters to you, the more useful questions are what breaks if they are unavailable for a day, who you would call, and whether that path has ever been tested. We covered why in critical infrastructure does not fail alone.
The first one will take days because you are building the library while you answer. Once the library exists and is mapped to controls rather than to customers, most questionnaires become a couple of hours, with the remaining time spent on the genuinely new questions.
Security should own the content and the approved wording. Sales should own the relationship and the deadline. The failure mode is sales answering technical questions to keep a deal moving, or security answering without knowing what has already been promised commercially.
Say so, qualify it, and say what you are doing instead. A qualified no with an interim control and a date reads as an organisation in control of its position. An optimistic yes that does not survive checking damages the relationship far more than the original gap would have.
They reduce the depth more than the number. A recognised certification lets many customers accept a shorter set of questions, because the certificate answers a large block of them. It rarely eliminates the exercise, because most organisations have their own specific concerns on top.

The honest answer is that it belongs in the reading and nowhere near the deciding. Here is where we draw that line and why we draw it there.
Read the article
They are not competing standards and you are not really choosing between them. One is a certifiable management system, the other is a way of describing where you stand. Here is how to tell which you need first.
Read the article
The phrase is used to sell dashboards. What it really describes is a change in when evidence is produced, and that change is the only part that matters.
Read the articleIf this raises a question about your own compliance position or your security operations, the quickest route is a direct conversation.