Enterprise procurement now sends an AI section alongside the security review — model inventory, training-data rights, human oversight, AI subprocessors. Most vendors answer the SOC 2 part in their sleep, then lose three weeks to six questions nobody can answer. We produce the evidence behind those answers, in three weeks.
Compliance platforms give you a control checklist. Questionnaire automation retrieves answers from a content library. Both assume the underlying material already exists.
For most companies that shipped AI features in the last eighteen months, it doesn't. Nobody has written down which vendors touch customer data, what the retention terms actually say, whether a human is required to review output or merely able to, or what happens when the model gets something wrong.
So the checklist stays empty and the automation returns blanks — or worse, invents something a reviewer later catches.
Somebody has to sit down with your engineering lead, open the vendor dashboards and the actual contracts, and write the truth down. That is the work. It is not automatable, and at your size nobody sells it.
A traditional GRC firm quotes thirty thousand and up, and takes four months. We do the evidence layer only — the part that actually unblocks the deal — and we do it before your close date.
A working session with your engineering lead, screen shared. We read the vendor contracts, check the account configurations, and capture a real request payload. Anything critical — a missing BAA, a retrieval path that crosses tenants — comes to you the day we find it, not in the final report.
Register, data flow map, policies, impact assessments. Written from what your company actually does. Reviewers recognise boilerplate, and it costs you more credibility than having nothing.
Your questionnaire filled, every answer backed by an artifact we can point to. Plus the answer bank, so the next one takes an afternoon instead of three weeks.
I'm an engineer, not an auditor. I've built and run AI systems on my own infrastructure — self-hosted language models, an automated end-to-end video pipeline, and all the GPU and driver work underneath both. None of it was theoretical, and none of it was tidy.
That's why this firm exists. Most people doing AI assurance came out of audit and have never deployed a model, so when they ask whether customer data is used for training, they write down the answer they're given. I ask to see the request payload, the vendor's plan tier, and the account configuration. Those three things disagree with each other more often than anyone expects — and a reviewer who discovers that before you do has already cost you the deal.
I'm not a clinician and I don't pretend to be. What I bring to healthcare work is the ability to sit down with your engineering lead and establish what is actually true about your system. That has to happen before any of the documentation means anything.
Scope. Provenance produces readiness documentation and identifies gaps. We do not provide legal advice, issue certifications, or render audit opinions, and we do not determine whether you comply with any law or standard — your counsel and your auditors do that. Being clear about this is not a disclaimer. It's the reason our documentation survives a reviewer reading it closely.
We'll come back with a gap list and draft answers for the worst five. Free, no pitch, and you'll know within a week whether this is worth paying for.
admin@provenanceusa.comRedact the customer name, keep the questions.