The eleven AI questions your clients will ask this year
Client due-diligence questionnaires and PI insurers have started asking about AI controls directly. Here are the questions we are seeing, what a good answer looks like, and what happens when you cannot give one.
Something changed in the last eighteen months. AI governance stopped being a topic that came up at conferences and started being a topic that comes up in procurement.
We now see three separate channels putting the same pressure on mid-sized businesses in the Gulf: client due-diligence questionnaires, professional indemnity insurers at renewal, and — for regulated sectors — the regulator directly. The questions are becoming standardised, which means they are also becoming answerable.
This is the list we see most often, what a defensible answer sounds like, and what it costs you to not have one.
1. Do you have a written AI usage policy?
What a good answer looks like. Yes, here it is, it is eight pages, it was last reviewed in the current quarter, and every member of staff has acknowledged it.
What most firms say. “We have guidelines.” Guidelines that are not written down are not guidelines. If you cannot attach it to an email, you do not have one.
The bar here is genuinely low. A usable policy is short, specific, and covers approved use, prohibited use, what data must never leave the business, and how someone requests a new tool. It does not need to be a compliance artefact. It needs to be something a fee earner will read.
2. Which AI tools are in use across your organisation?
This is the one that catches people. Most firms can produce a policy. Almost none can produce an inventory.
What a good answer looks like. A list, with the owner of each tool, the data category it touches, and the date it was approved.
Why it is hard. Because the honest answer for most businesses is “considerably more than management thinks”. Every governance engagement we run turns up tools nobody in the leadership team knew about. That is not a failure of the staff; it is what happens when useful tools are available on a personal credit card.
You cannot answer question one credibly without answering this one first, which is why discovery comes before policy in any sensible sequence.
3. Is client or customer data entered into third-party AI tools?
What a good answer looks like. Yes, into these specific approved tools, configured with training disabled and retention set to this period, under these contractual terms.
What is unacceptable. “No” — when you have not checked. An unverified no is worse than a qualified yes, because it will eventually be contradicted by a member of your own staff.
4. Are those tools configured on business terms, or consumer ones?
An underrated question with a very concrete answer. Most of these products behave completely differently on their enterprise tier: training on your inputs disabled, retention configurable, admin visibility, contractual commitments.
Most businesses have never changed the defaults. Moving your approved tools onto business terms and turning off training is possibly the highest-value hour of work available in this entire subject.
5. Where is data processed, and does it leave the country?
What a good answer looks like. Named regions per tool, mapped against your obligations, with the ones that cannot meet your residency requirements explicitly excluded from the approved list.
For UAE businesses handling regulated data this is increasingly the binding constraint on which tools you can use at all. It is better to discover that during a policy exercise than during an audit.
6. Who is accountable for AI in your organisation?
What a good answer looks like. A named person, with the responsibility written into their role, and a defined route for staff to request a new tool.
What most firms say. “IT” — which usually means nobody. Accountability that is not assigned to a person is not accountability.
This does not need to be a new hire or a new committee. For a fifty-person firm it is a named individual with a few hours a month.
7. What review applies to AI-assisted work before it reaches a client?
Increasingly asked by clients in professional services, and increasingly asked by insurers.
What a good answer looks like. A defined review step, proportionate to matter risk, that someone signs. Not “our people check their work” — a step that exists in the process and leaves a trace.
The failure mode here is not obviously wrong output. It is plausible output that nobody checked because it looked fine.
8. Do you disclose AI use to clients?
The market has not settled on a single answer, but it has settled on the fact that you need a position. Being asked and having no view is the bad outcome.
What a good answer looks like. Either “yes, in our engagement terms, in these circumstances” or “no, because we treat it as a tool like any other, and here is why that is consistent with our obligations”. Both are defensible. Silence is not.
9. What happens if an AI tool produces something harmful or wrong?
What a good answer looks like. A named escalation path, a defined containment step, and — if the output reached a client — a disclosure decision made by a person with the authority to make it.
Most firms have an incident process for a data breach and nothing at all for this.
10. How do you prevent staff pasting confidential material into public tools?
What a good answer looks like. A combination: a sanctioned alternative good enough that nobody needs the unsanctioned route, technical controls where your stack supports them, and training that explains the reasoning rather than just issuing a prohibition.
Why bans fail. A prohibition with no approved alternative does not stop the behaviour. It moves it onto personal devices, where you have no visibility whatsoever. You have traded a manageable risk for an invisible one.
11. When did you last review this?
The quiet one. A policy written eighteen months ago, in this field, is a historical document.
What a good answer looks like. A scheduled review with a date, and evidence that the last one actually happened and changed something.
What happens when you cannot answer
For most of our clients the consequence has not been losing the work outright. It has been slower: an extra round of questions, a security exception that has to be escalated internally, a procurement process that takes six weeks instead of two, and occasionally a clause that shifts risk onto them.
For insurance the effect is more direct. Underwriters are asking, and the answers are starting to be reflected in terms.
What it takes to be able to answer
Less than most people expect. A business with nothing in place today can have a written policy, a tool inventory, an approved list configured properly, a named owner and a review cycle inside four weeks. None of it requires a certification and none of it requires a full-time hire.
The harder part is what comes after: changing the habits of people who have been doing this their own way for two years. That is a quarter’s work, not a fortnight’s, and it is the part that determines whether the policy is real.
If you want a blunt read on where you would currently score against this list, our AI Readiness Scorecard covers most of it in about two minutes, and our governance engagement is built around closing the gaps it finds.