Your enterprise deal is stuck on the AI questionnaire.

Enterprise procurement now sends an AI section alongside the security review — model inventory, training-data rights, human oversight, AI subprocessors. Most vendors answer the SOC 2 part in their sleep, then lose three weeks to six questions nobody can answer. We produce the evidence behind those answers, in three weeks.

The problem

The tooling you already bought can't answer these.

Compliance platforms give you a control checklist. Questionnaire automation retrieves answers from a content library. Both assume the underlying material already exists.

For most companies that shipped AI features in the last eighteen months, it doesn't. Nobody has written down which vendors touch customer data, what the retention terms actually say, whether a human is required to review output or merely able to, or what happens when the model gets something wrong.

So the checklist stays empty and the automation returns blanks — or worse, invents something a reviewer later catches.

Somebody has to sit down with your engineering lead, open the vendor dashboards and the actual contracts, and write the truth down. That is the work. It is not automatable, and at your size nobody sells it.

The engagement

AI Evidence Sprint

Three weeks, fixed fee

$12,00050% on start
  • AI system register — every model, vendor, and data path, including the ones nobody remembered
  • Data flow map — what leaves the building, to whom, under what contractual terms
  • Subprocessor register — with the actual agreement terms pulled and summarised
  • BAA gap review — every AI vendor touching PHI, checked at the plan tier
  • AI governance policy and acceptable use policy — written from your practice, not a template
  • Impact assessments — for each high-impact system
  • Incident response addendum — because a wrong answer is an incident even when it isn't a breach
  • Answer bank — roughly 190 pre-written responses mapped to NIST AI RMF and ISO 42001, in your voice, ready to paste
Assurance retainer — $1,500–2,500/month. The register stays current as you ship, new vendors get reviewed, and inbound questionnaires get answered for you. Most clients take this after the first sprint, because the questionnaires never stop arriving.

A traditional GRC firm quotes thirty thousand and up, and takes four months. We do the evidence layer only — the part that actually unblocks the deal — and we do it before your close date.

How it runs

Three weeks, start to delivery.

  1. Week one — find out what's true

    A working session with your engineering lead, screen shared. We read the vendor contracts, check the account configurations, and capture a real request payload. Anything critical — a missing BAA, a retrieval path that crosses tenants — comes to you the day we find it, not in the final report.

  2. Week two — write it down

    Register, data flow map, policies, impact assessments. Written from what your company actually does. Reviewers recognise boilerplate, and it costs you more credibility than having nothing.

  3. Week three — answer the questionnaire

    Your questionnaire filled, every answer backed by an artifact we can point to. Plus the answer bank, so the next one takes an afternoon instead of three weeks.

Fit

Who this is for.

A good fit

  • You sell software with AI features into health systems, payers, or other regulated enterprises
  • Roughly 20–200 people, with SOC 2 already done or underway
  • There is a specific deal, with a number and a date, waiting on this
  • Your engineering lead can give us half a day and honest answers

Not a good fit

  • You want a certification. We don't issue one, and anyone who says they can in three weeks is selling you something else.
  • You want answers written that the underlying facts don't support. We will tell you what's true and help you fix it — that's the entire product.
  • You're large enough for a Big Four engagement. Go and get one.
  • Nothing is actually blocked. Come back when something is; you'll get more from it.
Who you'd be working with

Brian

I'm an engineer, not an auditor. I've built and run AI systems on my own infrastructure — self-hosted language models, an automated end-to-end video pipeline, and all the GPU and driver work underneath both. None of it was theoretical, and none of it was tidy.

That's why this firm exists. Most people doing AI assurance came out of audit and have never deployed a model, so when they ask whether customer data is used for training, they write down the answer they're given. I ask to see the request payload, the vendor's plan tier, and the account configuration. Those three things disagree with each other more often than anyone expects — and a reviewer who discovers that before you do has already cost you the deal.

I'm not a clinician and I don't pretend to be. What I bring to healthcare work is the ability to sit down with your engineering lead and establish what is actually true about your system. That has to happen before any of the documentation means anything.

Scope. Provenance produces readiness documentation and identifies gaps. We do not provide legal advice, issue certifications, or render audit opinions, and we do not determine whether you comply with any law or standard — your counsel and your auditors do that. Being clear about this is not a disclaimer. It's the reason our documentation survives a reviewer reading it closely.

Start

Send us the questionnaire that's giving you trouble.

We'll come back with a gap list and draft answers for the worst five. Free, no pitch, and you'll know within a week whether this is worth paying for.

admin@provenanceusa.com

Redact the customer name, keep the questions.