Guide

Would your internal AI survive an audit?

Seven questions a CIO, a large client, an insurer or a regulator will eventually ask about your AI tool, and how to answer them before they arrive.

Published July 20, 2026

An AI tool enters the company in a few days. The questions arrive later: a large client's security questionnaire, the cyber-insurance renewal, an internal control review, the deployer obligations of the European AI regulation. The test is simple: if you cannot answer the seven questions below with evidence, your AI tool is a risk waiting to be examined. Here they are, in the order an auditor asks them.

1. Which model runs, in which version?

An innocent-looking question that is often fatal: many buyers of packaged solutions do not know which model processes their data, nor whether the vendor can swap it without notice. A model that changes silently is behaviour that changes silently, on processes that commit the company.

2. Where is your data processed, and under which law?

Hosting alone does not answer this. Data stored in Europe but processed by a US operator remains exposed to US law. The full question has three layers: where the servers are, who the operator is, under which jurisdiction. This is the core of the sovereign-risk grid.

3. Does your data train someone else's model?

Depending on the plan and the settings, what your teams submit may be used to improve the service, and therefore leave your control. The answer must be written in the contract, not inferred from a marketing page. If your provider cannot produce it, you have your answer.

4. Is there an audit log?

Who asked what, when, on which files, and which sources the answer cited: without that log you can neither trace an incident, nor prove your seriousness to a client, nor answer a regulator. An AI tool without an audit log is a black box sitting in the middle of your processes.

5. How do you leave?

Export of your data, in which formats, within what delay, with what assistance: reversibility is read in the contract, before signing. The absence of an exit clause is the true measure of dependence. The subject deserves a full guide: switching AI solutions without losing everything.

6. Who operates the system?

A name, a service commitment, an incident procedure. Between the tool deployed and left to itself and the system operated, monitored and updated, the difference is invisible at the demo; it shows at the first incident. An auditor will ask who is accountable; "the vendor, probably" is not an answer.

7. Are your teams using something else?

The question CIOs rightly dread. When the official tool disappoints, teams go back to consumer tools, with company data. This shadow AI is the worst line of an audit: the exposure exists, and nobody measures it. An internal tool that actually works is the only durable answer; the causes of the disappointment are known and fixable.

Answer before you are asked

These seven questions fit in one map: for every process where AI intervenes, which model runs, where, under which law, with which log and which exit door. Establishing that map is precisely the first step of the root offer: the Sovereignty Map. The benefit goes beyond compliance: the day the question arrives, you do not undergo an audit, you produce a document.

Frequently asked questions

Who actually asks these questions?

Today: procurement departments of large accounts, cyber insurers at renewal, CIOs in committee, statutory auditors on financial processes. Tomorrow: the regulator, as the deployer obligations of the European regulation come into force. The frequency increases; the meaning of the question does not change.

Our provider cannot answer. Is that serious?

It is valuable information: the absence of an answer is an answer. A serious supplier produces these elements in a few days, contract and architecture in hand. A supplier who cannot is transferring the risk to you without transferring the means to manage it.

Doesn't the GDPR already cover all of this?

The GDPR covers personal data: necessary, and insufficient. Your strategic non-personal data - client files, contracts, figures - is not protected by it, and the question of the operator's jurisdiction remains fully open even under perfect GDPR compliance. If you want to run your current tool through this grid, let's talk.