Procurement just asked. You have days, not months.

An enterprise customer just sent you
an EU AI Act questionnaire.

Their procurement or legal team needs answers before signing. You have a sales window of days, not weeks. You don't have a 12-week GRC project budget — and you shouldn't need one. Here are the two ways to answer the questionnaire properly this week.

The questions that just landed in your inbox

Real questions we've seen pulled from European enterprise procurement questionnaires (banking, healthcare, public sector, legal). If any of these look familiar, you're in the right place.

Question "Please describe how your AI system is classified under the EU AI Act (Regulation 2024/1689) and which Annex III high-risk categories, if any, apply to your use case."
Question "Provide your Article 26 Deployer Compliance documentation, including risk management process, data governance measures, and human oversight provisions."
Question "Confirm whether your AI system performs automated decision-making with legal or significant effect on individuals, and describe the safeguards in place under Article 14."
Question "Attach your Annex IV Technical Documentation or, if you are a deployer rather than a provider, the equivalent documentation received from your AI model provider (Anthropic / OpenAI / Mistral / etc.)."
Question "Describe your audit trail for AI interactions, retention period, and the process by which a regulator could access logs in case of an incident investigation."

You can answer all of these properly. You don't need a Big Four consultancy. You need the right document, mapped to the EU AI Act articles, in your customer's hands before they move on to the next vendor.

Two paths. Pick the one that fits this week.

Both paths produce the same end artifact: a PDF you can attach to the procurement response. The difference is who does the work.

Self-serve · Instant

Templates pack

You fill in your details using our pre-mapped templates. Best if you have an in-house technical writer or compliance lead.

97 one-time
  • Article 26 Deployer Report template (Word + PDF)
  • Annex IV Technical Documentation template
  • Vendor questionnaire response cheat sheet (15 most common questions, pre-written answers)
  • EU AI Act risk classification worksheet
  • Instant download — no setup
Buy templates — €97 →

Why not a "real" GRC platform?

You'll get demos for those too. Here's the honest comparison so you can spend your decision energy on the deal you're trying to close, not on tooling research.

AuditAI Enterprise GRC platform Big Four consultancy
Time to deliverable Instant (€97) or 48h (€199) 4–12 weeks (incl. onboarding) 8–16 weeks
Cost €97–€199 one-time €20k–€80k/year €30k–€150k engagement
Sales calls required Zero Demo + scoping + procurement Multiple partner calls
Right for AI startups (Seed–Series B), 5–200 employees, 1–3 AI products Banks, insurers, public sector with multi-product AI portfolios Regulated industries needing legal-defensible advice

How the managed audit works

1

Send us the questionnaire (or just your AI system details)

Forward the procurement questionnaire to marc@auditaisdk.com, or fill the form on the managed audit page. We accept Word, PDF, Google Docs, plain text.

2

Marc confirms scope within 24h

You'll get a confirmation email with a Stripe payment link (€199), the questions we'll address explicitly, and any clarifications we need.

3

You receive a complete response package within 48h of payment

Article 26 Deployer Report (signed PDF) + Annex IV Technical Documentation + question-by-question response document you can paste into the procurement portal.

4

One revision included if your customer pushes back

If their legal team asks follow-up questions, send us their feedback — we revise within another 48h at no extra cost.

Common questions

My customer's procurement team is asking for SOC 2 alongside EU AI Act. Can you cover both?

Yes. The audit trail and evidence package we generate maps to SOC 2 Common Criteria CC6 (logical access), CC7 (system operations), and CC8 (change management). The PDF includes a SOC 2 mapping appendix at no extra cost. We don't issue the SOC 2 attestation itself — you'll still need a CPA firm for that — but most enterprise procurement teams accept the mapping as evidence of intent and capability.

Is this enough to actually pass procurement, or just for show?

It's enough for the typical AI startup deployer scenario. The report follows the official EU AI Act text (Regulation 2024/1689) and Article 26 deployer obligations explicitly. If your customer is a Tier 1 bank or a regulator, your buyer's legal team will want supplementary specialist legal counsel — and we'll say so directly in the report. We're not in the business of overselling.

My AI system uses Claude/GPT/Mistral via API. Am I a "deployer" or a "provider"?

If you're a SaaS company using Anthropic / OpenAI / Mistral / Cohere via API and not training your own foundation model, you're almost certainly a deployer under Article 26 (not a provider under Article 16). The deployer obligations are lighter and the documentation is faster to produce. The report makes this distinction explicit so your customer's legal team can verify it.

The EU AI Act Omnibus shifted high-risk deadlines to December 2027. Why is procurement still asking?

Because procurement teams update their questionnaires once a year, in February. The Omnibus provisional agreement (May 7, 2026) hasn't propagated yet. Your customer's checklist still reflects the original August 2026 deadline. Saying "the deadline moved" doesn't unblock the deal — answering the questionnaire does.

Can I see the report template before paying?

Yes — buy the €97 templates pack first. If you decide you want it filled in for you, we apply the €97 as credit toward the €199 managed audit. Email marc@auditaisdk.com after purchase.

What if I want ongoing logging once this deal closes?

pip install auditai-sdk — three lines of code wraps your Claude / GPT / Ollama calls and produces an ongoing audit trail. Plans start at €49/mo. After this deal closes you'll get future questionnaires from future customers; the SDK turns each one into a 30-minute task instead of a 48-hour project.

Who is behind this?

Marc Dubois — auditaisdk.com / marc@auditaisdk.com. The SDK and templates are built and maintained from the same repo: github.com/marcduboistech-eng/auditai. The managed audits are produced personally by Marc — no white-labelled offshoring, no AI-only generation.

Don't let an EU AI Act question kill an enterprise deal

Start with whichever path matches your timeline. You can upgrade later.