Claude

IntuitionLabs is now a member of the Claude Partner Network – AI training and upskilling with Claude for pharma and biotech. Book a call.

IntuitionLabs
Security and compliance reviewers assembling evidence for a life-science supplier questionnaire

Security Questionnaire Readiness: Answer Once, Answer Consistently

Most life-science companies do not need a certificate. They need to survive the questionnaire a pharma partner, CRO or acquirer sends at the worst possible moment in a deal. We build the control narrative, the evidence pack and the answers. We are not an auditor and not a certifying body.

What readiness actually means

Readiness is not a certificate and not a policy binder. It is the ability to answer any instrument accurately, quickly and identically, and to show the evidence behind each answer without a scramble.

01
One control narrative
A written statement of what you do and why, per control area, with a named owner. Every questionnaire maps back to it instead of being answered from scratch by whoever is free that week.
See the security practice
02
An evidence index
Policies, pen test results, access reviews, restore tests and contracts, versioned, dated and findable. Assembly cost usually dominates answer cost, so this is where the hours go.
Where pen test evidence comes from
03
The GxP layer
The part a generic security pack is missing: supplier qualification documentation, audit trail specification, inspection support, exit strategy and pre-release testing for new versions.
Validation services
04
An honest gap list
A written record of where the correct answer today is no, who owns closing it and by when. Overclaiming is the failure that discredits every other answer on the form.
Our own Trust Center

Why questionnaires stall life-science deals

A security questionnaire is rarely lost on the merits. It is lost because it arrives at a moment of maximum leverage loss, into an organisation that has controls but has never written them down, and it is answered inconsistently by people who have other jobs. Understanding the specific failure modes is the fastest route to fixing them, because each one has a different remedy and only one of them is about actually improving security.

Failure modes

Six ways a questionnaire goes wrong, in the order they appear

These failures are structural rather than moral. A clinical-stage company with thirty people and a real product almost always has adequate controls and almost never has the artefacts that let someone else verify it. The gap between having controls and being able to evidence them is the entire problem, and it widens quietly until the first serious buyer asks.

The first failure is the absence of a control narrative. The company encrypts data at rest, reviews access quarterly and runs change management through pull requests, but no document says so. Every questionnaire is therefore an act of original composition. The second failure follows immediately: evidence is scattered. Policies live in Notion, screenshots in a Slack thread, the penetration test PDF in somebody’s inbox, the data processing agreement in a signed-contract folder nobody can search. The cost of assembling the evidence dominates the cost of writing the answer, which is why a questionnaire that looks like a two-hour job consumes a week.

The third failure is that nobody owns it. In a twenty-person biotech the questionnaire lands on the CTO, who is also the constraint on shipping. Vanta, drawing on its own analysis of the burden, puts the effort at five to fifteen hours per questionnaire; in a small company those hours come directly out of engineering capacity at the exact moment the deal needs the product to keep moving.

The fourth failure is inconsistency across instruments. The Standardized Information Gathering questionnaire, the Consensus Assessments Initiative Questionnaire and a customer’s bespoke Word document ask the same underlying question in three vocabularies. Without a canonical answer bank the company contradicts itself, and a buyer who receives two questionnaires six months apart notices. Contradiction reads as incompetence or concealment, and neither impression is recoverable inside a deal cycle.

The fifth failure is timing. Diligence is discovered at the point of maximum leverage loss: after the internal champion has sold the project, before signature. What should have been a project becomes a schedule risk, and the pressure to give a fast confident answer is precisely the pressure that produces the sixth and most damaging failure, which is overclaiming. Saying SOC 2 compliant when there is no report. Saying ISO certified when a consultant performed a gap assessment. Saying HIPAA compliant, which is a category error because HIPAA has no certification and nobody can issue one. A reviewer who catches a single overclaim discounts every other answer on the form, including the true ones.

There is a strategic point buried in the burden data that is worth stating directly. In the same analysis, Vanta cites RiskRecon research finding that only 34 percent of third-party risk management professionals believe questionnaire responses are accurate. The instrument is distrusted by the people who send it. That is not a reason to answer it badly; it is the reason that verifiable evidence beats additional prose. A current penetration test with a remediation record, a published self-assessment, and a policy set with real approval dates move a reviewer further than another thousand words of assertion.

No control narrative

Controls exist, but nothing written says what they are, so every questionnaire is composed from scratch.

Evidence scattered

Policies, screenshots, test reports and contracts live in five systems. Assembly cost dominates answer cost.

No owner

The form lands on the person who is already the shipping bottleneck, and the hours come out of engineering.

Inconsistent answers

Three instruments, three vocabularies, no canonical answer bank, and a buyer who compares two submissions.

Arrives mid-deal

Diligence surfaces after the champion has sold internally, converting a project into a schedule risk.

Overclaiming

One caught overstatement discounts every other answer, including the accurate ones.

The instrument is already distrusted. Verifiable evidence persuades where additional prose does not.

Related evidence and next steps

The instruments

What is actually going to land in your inbox

There is no single questionnaire. There is a small set of published instruments, a large set of bespoke ones derived from them, and one archived project that keeps appearing in vendor-risk articles as though it were current. Knowing which one you have received changes what you should do about it, because two of them can be pre-empted for free and the rest cannot.

The Standardized Information Gathering questionnaire is published by the Shared Assessments Program as part of its third-party risk management toolkit, on an annual release cycle, with SIG Lite as the low-risk screening tier and SIG Core as the comprehensive tier for higher-risk providers. Both can be scoped by risk domain and control family. It is licensed rather than free: access requires membership or a product subscription, which is also why its exact question counts are not publicly published and should be treated with suspicion when quoted. The most significant change in the 2026 release, per Mitratech’s analysis of it, is a comprehensive mapping to ISO/IEC 42001, which pushes AI governance into every SIG-based programme in a single step. In March 2026 Shared Assessments launched SIG Evolution, moving the questionnaire from a spreadsheet to a browser-based platform while retaining Excel compatibility.

The Consensus Assessments Initiative Questionnaire is the Cloud Security Alliance’s instrument, aligned one-to-one with the Cloud Controls Matrix. CCM v4.1, released on 27 January 2026, contains 207 controls across 17 security domains. CAIQ v4 contains 261 questions, down from 310 in v3.1, and CAIQ-Lite contains 124 questions while still addressing all of the matrix domains. This is the instrument to build your answer bank around, for a structural reason: CAIQ maps to CCM, and CCM maps to almost everything else, so answering CAIQ once produces reusable answers for instruments you have not seen yet.

The AI-specific successor arrived on 9 July 2025, updated on 30 October 2025. The CSA AI Controls Matrix contains 243 control objectives across 18 security domains for cloud-based AI systems, and ships with a companion AI-CAIQ and a STAR for AI Level 1 submission guide. For an AI vendor selling into life sciences it is currently the closest thing to a standard AI-specific self-assessment, and it costs nothing.

The Higher Education Community Vendor Assessment Toolkit is published by EDUCAUSE with Internet2 and REN-ISAC, currently at HECVAT 4, revision 4.1.5, and version 4 explicitly added privacy and AI questions. It is free to colleges, universities and their vendors, though third-party risk platforms need a licence to embed it. It matters to life sciences whenever the counterparty is an academic medical centre or a university research office, which for a biotech is a very common partner and a frequently unanticipated instrument.

Google’s Vendor Security Assessment Questionnaire is the one to be careful about. It was an influential open-source interactive questionnaire application under an Apache 2.0 licence, and it popularised the conditional branching questionnaire that most modern platforms now use. Its repository was archived by its owner on 25 November 2022 and is read-only. It is still listed as a current instrument in vendor-risk articles, and quietly correcting that in a conversation with a reviewer is a small but real credibility marker.

SIG and SIG Lite

Shared Assessments, annual cycle, licensed. The 2026 release added an ISO 42001 mapping; SIG EV launched 17 March 2026.

CAIQ v4

261 questions aligned to CCM v4.1 (207 controls, 17 domains, released 27 January 2026). CAIQ-Lite is 124 questions.

AICM and AI-CAIQ

243 control objectives across 18 domains, published 9 July 2025 and updated 30 October 2025. Free.

HECVAT 4.1.5

EDUCAUSE, free to institutions and their vendors, with privacy and AI questions added in version 4.

VSAQ

Archived 25 November 2022 and read-only. Historically influential, not a current instrument.

Related evidence and next steps

The pharma variant

The supplier questionnaire nobody publishes

There is no pharmaceutical equivalent of the SIG for information security, and assuming there is one leads to a specific and avoidable embarrassment in front of a quality lead. What exists instead is three separate strands that are frequently confused with each other, only one of which is the instrument that will actually arrive.

The Pharmaceutical Supply Chain Initiative is a member-driven scheme whose Principles for Responsible Supply Chain Management cover ethics, labour and human rights, health and safety, environment, and management systems. Data privacy and security appears within it as a sub-principle under ethics, not as a security framework. PSCI runs a shared audit programme so that one audit can serve many members, which is genuinely useful, but a page or a sales conversation that presents PSCI as a security questionnaire will be wrong in a way a pharma quality lead spots instantly. It is a responsible-business instrument.

Rx-360 is an international pharmaceutical supply chain consortium that runs an audit operations working group and a shared audit programme, oriented to good manufacturing practice and material-integrity supply chain risk rather than to information security.

The instrument that actually arrives for a software or AI vendor is the GxP supplier qualification questionnaire and audit, and it is a company-specific document rather than a published standard. It is driven by EU GMP Annex 11 sections 3 and 7, EU GMP Chapter 7, ICH Q10 section 2.7 and GAMP 5 Appendix M2. Because every regulated company writes its own, the questions are unpredictable, the format varies, and answering cold is expensive. That unpredictability is exactly why a control narrative written once in the quality register as well as the security register pays for itself: the underlying facts are the same, and the work is translation rather than rediscovery.

Related evidence and next steps

Four instruments, four different things being proven

Published details as of 27 August 2026, taken from the standards bodies and, where a standard is paywalled, from the secondary sources named in the section below. These are structural differences rather than a ranking. The right instrument is the one your buyer has actually asked for, and frequently the honest answer is that none of them addresses the question being asked.

QuestionSOC 2ISO/IEC 27001:2022ISO/IEC 42001:2023HITRUST
What is the artefactAn attestation report containing an opinionA certificateA certificateA certification issued centrally
Who may issue itA licensed CPA firm onlyAn accredited certification body under ISO/IEC 17021-1An accredited body under 17021-1 plus ISO/IEC 42006:2025HITRUST itself, via an approved External Assessor
Criteria appliedTrust Services Criteria, TSP section 100, 2017 with 2022 revised points of focusClauses 4 to 10 plus Annex A, reported as 93 controls in four themesManagement system clauses plus Annex A, reported as 38 controls in groups A.2 to A.10The HITRUST CSF control library
How scope is setWhich of the five trust services categories the organisation selectsThe scope statement on the certificate plus the Statement of ApplicabilityScope statement plus Statement of ApplicabilityScope plus risk factors; e1 has 43 controls, i1 has 182, r2 is tailored
How long it is good forThe Type 2 window itself, then a management-signed bridge letterA three-year cycle with annual surveillance auditsA three-year cycle on the 17021-1 modele1 one year, i1 one year, r2 two years
What it provesControls were suitably designed, and for Type 2 operated, over a stated periodA governed information security management system exists and is auditedA governed AI management system exists and is auditedPrescriptive controls verified and centrally quality-assured
What it does not proveThat there were no exceptions, that unselected categories are covered, or GxP fitnessThat any particular control was applied; read the Statement of ApplicabilityAny individual model’s accuracy, safety or fitness for a clinical purposeAnything outside the assessed scope
Where it carries most weightGeneral technology procurement, especially in the United StatesInternational enterprise procurement and EU buyersAI-specific diligence, and increasingly inside SIG-based programmesUS healthcare, payer and provider procurement
What a GMP buyer still needs after itSupplier qualification documentation, inspection support, exit strategyThe same, plus scope evidence that covers the product rather than corporate ITThe same, plus model change control and pre-release testing rightsThe same; EU GMP expectations are Annex 11 and Chapter 7, not HITRUST

What each instrument actually proves, and what it quietly does not

Almost every argument about certification goes wrong in the first sentence, because the words are used loosely. SOC 2 is not a certification. ISO 27001 is one, but two certificates with the same logo can cover entirely different things. ISO 42001 certifies a process rather than a model. HITRUST is issued by a different kind of body than either. If you are going to spend six figures on one of these, it is worth twenty minutes on what you would be buying.

SOC 2

An attestation report, not a certificate

SOC 2 is an attestation examination performed under AICPA attestation standards, and the deliverable is a report containing a practitioner’s opinion. Only a licensed CPA firm can issue one. The criteria are the AICPA’s Trust Services Criteria, formally TSP section 100, the 2017 criteria with revised points of focus published in 2022; that revision changed the points of focus rather than the criteria or the categories themselves.

There are five trust services categories: security, availability, processing integrity, confidentiality and privacy. Security, known as the common criteria, is required in every SOC 2 report. The other four are elective and appear only if the service organisation selected them. This is the first thing to check when you receive somebody else’s report and the first thing a buyer will check on yours: a SOC 2 covering security only says nothing whatsoever about availability or privacy, and presenting it as though it does is an overclaim.

A Type 1 opinion covers the suitability of the design of controls as of a point in time. A Type 2 opinion covers design and operating effectiveness throughout a period, normally three to twelve months per A-LIGN’s own description. The practical consequence is that a Type 1 is evidence that controls existed on one particular day, and that a first-year vendor with a three-month Type 2 window has demonstrably less evidence than one with a twelve-month window. The period end date matters as much as the opinion.

The report has five sections and only two of them repay careful reading. Section 1 is management’s assertion. Section 2 is the independent service auditor’s report, which contains the opinion, and that opinion can be unqualified, qualified, adverse or a disclaimer. Section 3 is the system description, written by management. Section 4 sets out the criteria, the controls, the tests performed and the results of those tests, which is where exceptions live. Section 5 is other information not covered by the auditor’s opinion, which means it is unaudited and can contain management’s own framing. A serious reviewer reads the opinion paragraph and the exceptions.

The bridge letter, sometimes called a gap letter, covers the interval between the end of the last Type 2 period and today. It is written and signed by management rather than by the CPA firm, the CPA firm is not involved, and it carries no opinion. Secureframe notes these typically do not cover more than three months. A vendor whose only current evidence is a bridge letter is offering a self-assertion, and that is worth knowing whether you are reading one or writing one.

What SOC 2 does not prove is a longer list than most people expect. It is not a certification. It does not prove the absence of exceptions. It says nothing about categories that were not selected. It does not evaluate the functional correctness of the product or the quality of any model inside it. HIPAA, GDPR and AI-specific obligations are not part of the Trust Services Criteria, and neither is GxP fitness.

Read the opinion

Section 2 carries the opinion: unqualified, qualified, adverse or disclaimer. Everything else is context.

Read the exceptions

Section 4 holds the tests performed and their results. Exceptions live there and nowhere else.

Check the categories

Security is mandatory. Availability, processing integrity, confidentiality and privacy are elective.

Check the window

A three-month Type 2 window is not a twelve-month window, and the period end date matters.

Related evidence and next steps

ISO/IEC 27001:2022

A certificate is only as meaningful as its scope statement

ISO/IEC 27001:2022 is Edition 3, published in October 2022, titled Information security, cybersecurity and privacy protection — Information security management systems — Requirements. Unlike SOC 2 it genuinely is a certification: an accredited certification body issues a certificate, normally on a three-year cycle with annual surveillance audits, following a Stage 1 documentation audit and a Stage 2 implementation audit.

The mandatory requirements are in clauses 4 to 10, covering context, leadership, planning, support, operation, performance evaluation and improvement. Annex A is a reference set of controls, and this is where the single most consequential misunderstanding lives. The standard itself is paywalled by ISO, so the control counts below are as reported by Secureframe rather than quoted from the standard: 93 controls in four themes, being organizational at 37, people at 8, physical at 14 and technological at 34, reduced from 114 controls across 14 domains in the 2013 edition, with 11 new controls including threat intelligence, information security for use of cloud services, and data masking.

Annex A is not a mandatory checklist. Applicability is decided by the organisation’s own risk assessment and recorded in the Statement of Applicability, which must justify exclusions. The practical consequence is that two ISO 27001 certificates are not comparable until you have read the scope statement on the certificate and the Statement of Applicability behind it. A certificate scoped to the corporate IT function at a company’s London office tells a buyer nothing at all about the SaaS platform they are purchasing.

This cuts both ways, and it is worth being honest about it when you are the one being assessed. Narrow scoping is legitimate and often sensible, but a narrowly scoped certificate presented as though it covered the product is an overclaim of exactly the kind described earlier on this page. If your certificate does not cover the platform, say so, and say what does cover it.

The economics follow the audit-day model rather than a fixed price. High Table, writing from a UK perspective, puts the total range at £5,000 to £50,000 and reports a 2026 baseline of £1,500 per auditor day, with roughly five audit days at the smallest end and around 28 at very large organisations. Stage 1 is approximately 20 to 30 percent of certification fees and Stage 2 approximately 70 to 80 percent, with annual surveillance around a third of the initial fee and a full recertification in year three. That surveillance and recertification cost is the part that turns a certificate into a standing operating expense rather than a project.

Edition 3, October 2022

The current edition. Clauses 4 to 10 are the mandatory management-system requirements.

Annex A is a reference set

Reported as 93 controls in four themes. What applies to you is decided by risk assessment.

Ask for the SoA

The Statement of Applicability, with justified exclusions, is what makes a certificate readable.

Ongoing cost is real

Annual surveillance at roughly a third of the initial fee, plus recertification in year three.

Related evidence and next steps

ISO/IEC 42001:2023 and 42006:2025

The AI management system certificate, and the body that may issue it

ISO/IEC 42001:2023, Information technology — Artificial intelligence — Management system, is Edition 1, published in December 2023, 51 pages, developed by ISO/IEC JTC 1/SC 42. It is a management system standard using Plan-Do-Check-Act, structurally parallel to ISO 27001, and ISO describes it as the world’s first AI management system standard.

Its Annex A is reported by Vanta, again as a secondary source because ISO paywalls the standard, as containing 38 controls organised into nine control-objective groups running A.2 to A.10: policies related to AI, internal organization, resources for AI systems, assessing impacts of AI systems, AI system life cycle, data for AI systems, information for interested parties, use of AI systems, and third-party and customer relationships. That last group, A.10, is the one that shows up in vendor questionnaires most often.

Three things converged to make 42001 appear suddenly in diligence during 2025 and 2026. It is the only certifiable AI governance standard, which makes it the natural box for a procurement team to tick. ISO/IEC 42006:2025, published on 7 July 2025 and running to 31 pages, now sets the additional requirements for bodies that audit and certify AI management systems, building on ISO/IEC 17021-1 rather than replacing it, so certificates are moving from self-declared to accredited; ANAB names both standards in its accreditation programme. And the Shared Assessments SIG 2026 release added a comprehensive ISO 42001 mapping, which put AI governance questions into every SIG-based programme at once.

What it does not prove needs stating as plainly as what it does. It is a management system certification. It certifies that a governed process for AI risk exists: policies, impact assessments, lifecycle controls, third-party management. It does not certify any individual model’s accuracy, safety or fitness for a clinical or GxP purpose, it is not a substitute for an EU AI Act conformity assessment, and it is not a GxP qualification. A vendor presenting a 42001 certificate as evidence that its model is safe for a regulated use has misunderstood the instrument, and so has a buyer who accepts it as such.

Edition 1, December 2023

Developed by ISO/IEC JTC 1/SC 42, using the Plan-Do-Check-Act management system pattern.

Annex A, groups A.2 to A.10

Reported as 38 controls. Group A.10 covers third-party and customer relationships.

ISO/IEC 42006:2025

Published 7 July 2025. Supplements 17021-1 with AI-specific requirements for certification bodies.

Not a model assurance

It certifies the governance process, not the accuracy or clinical fitness of any model.

Related evidence and next steps

HITRUST

A different structure, and a different centre of gravity

HITRUST publishes the HITRUST CSF, a harmonised control library, and runs a three-tier assessment portfolio. The e1 is a foundational assessment with 43 core controls, valid one year. The i1 is a leading-practices assessment with 182 controls, also valid one year. The r2 is the tailored, risk-factor-driven assessment, valid two years. Assessments are traversable, so work from an e1 or i1 can be applied toward a more comprehensive assessment.

The structural difference from both SOC 2 and ISO 27001 is who issues the result. A SOC 2 opinion is issued by the CPA firm that performed the examination. An ISO certificate is issued by the certification body. A HITRUST assessment is performed by a HITRUST-approved External Assessor, but HITRUST itself performs central quality assurance and issues the certification. That central quality assurance step is the source of both its reputation for consistency and its reputation for taking longer than people expect.

HITRUST maps its control library to a large number of authoritative sources including ISO/IEC 27001 and 27002, NIST SP 800-53 revision 5, HIPAA, PCI and GDPR. We deliberately do not quote a count of harmonised sources on this page: HITRUST’s own site gives different figures in different places, and a number we cannot reconcile is not a number worth printing. We also do not print a CSF version number, for the same reason.

HITRUST also now offers a purpose-built AI Security Assessment and Certification using prescriptive controls to validate security for deployed AI systems and platforms. Whether it is worth pursuing depends almost entirely on who is asking. HITRUST matters disproportionately in United States healthcare, payer and provider procurement. It matters much less in European pharmaceutical manufacturing, where Annex 11 and Chapter 7 are the operative expectations and a HITRUST certificate will not be the thing a quality unit asks for.

The right instrument is the one your buyer has asked for. Collecting instruments nobody requested is a cost, not a strategy.

Related evidence and next steps

What this engagement is and is not

We prepare clients for security questionnaires, supplier audits and certification examinations. We build the control narrative, assemble the evidence pack, and produce the answers in the form each instrument wants. IntuitionLabs is not an auditor and not a certifying body. We do not issue SOC 2 reports, ISO certificates, HITRUST certifications or AI Act conformity assessments, and we never certify anything. A full SOC 2 attestation stays a referral to an actual audit firm, and we will tell you which ones we have seen do good work.

IntuitionLabs was founded in 2023 and does not hold SOC 2 or ISO 27001 itself. We would rather state that on a page about certification than let a reader infer otherwise. Our own posture is documented on our security page and in our Trust Center. Everything here describes work we do for clients, not accreditations we hold.

Discuss Your Situation

We prepare

Control narrative, evidence pack, canonical answer bank, gap list with owners and dates, and the GxP layer a security pack is missing.

We never certify

No SOC 2 report, no ISO certificate, no HITRUST certification, no conformity assessment. Those come from independent bodies, by design.

Named technical lead

Where depth is needed, work is led by a named independent security architect on our expert bank rather than by generalists.

Your auditors are forbidden from building your programme

The most common objection to readiness work is that it sounds like paying someone to grade their own homework. The opposite is true, and the reason is written into the rulebooks of both professions rather than being a matter of opinion. Certification bodies and CPA firms are explicitly prohibited from building the thing they assess. That prohibition is what creates a legitimate preparation role, and it is also the boundary that a preparer has to respect for the arrangement to work at all.

AICPA independence

A threat that no safeguard can cure

The AICPA Code of Professional Conduct does not treat the independence of a SOC 2 examiner as a matter of degree. Interpretation 1.295.030, on management responsibilities, states that if a member were to assume a management responsibility for an attest client, the management participation threat would be so significant that no safeguards could reduce the threat to an acceptable level and independence would be impaired.

The named management responsibilities include, in terms that could hardly be more directly on point, accepting responsibility for designing, implementing, or maintaining internal control, and performing ongoing evaluations of the attest client’s internal control as part of its monitoring activities. In other words, the two activities that make up the bulk of readiness work are precisely the two activities the eventual examiner may not perform.

Interpretation 1.295.145, on information systems design, implementation or integration, extends the same logic into technology: independence is impaired if the member designs or develops an attest client’s financial information system, makes more than insignificant source-code modifications, supervises attest client personnel in the daily operation of an information system, or operates an attest client’s network.

Interpretation 1.295.040 sets out the general requirements that make any non-attest service possible at all, and its conditions describe the shape of a healthy readiness engagement from the client’s side. The client must agree to assume all management responsibilities, designate an individual, preferably within senior management, who possesses suitable skill, knowledge and experience to oversee the service, evaluate the adequacy and the results of the services performed, and accept responsibility for the results of the services. That is not fine print. It is the reason your company needs a named internal owner for this work even when an external firm is doing most of the writing.

Practitioners state the rule more bluntly. Writing on the readiness versus audit split, Atticus Rowan puts it as AICPA independence standards prohibiting the audit firm from having a material role in designing, operating or maintaining the control environment they are auditing, and summarises the consequence in a single line: the firm constructing your SOC 2 program cannot issue the report.

ET 1.295.030

Designing, implementing or maintaining internal control is a management responsibility. No safeguard cures it.

ET 1.295.145

Designing systems, modifying source code or operating a client network impairs independence.

ET 1.295.040

Non-attest services require a client owner with suitable skill who evaluates and accepts the results.

The consequence

The firm that builds your programme cannot be the firm that reports on it. Two firms, by design.

Related evidence and next steps

ISO impartiality

Clause 5.2.5, and why it is categorical

The ISO side of this is even more explicit. ISO/IEC 17021-1:2015 sets out the principles and requirements for the competence, consistency and impartiality of bodies providing audit and certification of all types of management systems, and it frames certification as a third-party conformity assessment activity performed by third-party conformity assessment bodies.

Clause 5.2.5 admits of no exceptions. As quoted by European Accreditation in its own guidance on the clause, the certification body and any part of the same legal entity and any entity under the organizational control of the certification body shall not offer or provide management system consultancy. The standard then defines management system consultancy in a way that closes the obvious loopholes: participation in establishing, implementing or maintaining a management system, with preparing or producing manuals or procedures, and giving specific advice, instructions or solutions towards the development and implementation of a management system, given as examples.

Read that list against what an information security management system implementation actually involves and the picture is clear. The body that will certify you cannot write your policies, cannot write your procedures, and cannot tell you specifically how to implement a control. It can audit what you built and say whether it conforms. For AI management systems the same architecture is extended by ISO/IEC 42006:2025, which supplements 17021-1 with AI-specific competence and process requirements for the bodies certifying against 42001.

So the market structure is not an accident and it is not a gap someone should close. There are meant to be two parties: one that helps you build a real management system, and one, entirely independent of the first, that examines whether it works. The uncomfortable version of this for consultancies is that it also means no preparation firm can promise you a certificate, because no preparation firm controls the decision. Anyone who promises one is either describing something other than certification or is telling you something about how they treat other claims.

Two parties by design: one builds the management system, an entirely separate one decides whether it conforms.

Related evidence and next steps

The evidence pack

What we actually build, in priority order

The output of readiness work is a small number of artefacts that answer many different instruments. This is the list we work through, ordered so that the earliest items carry the most weight per hour spent. Most companies discover that items one to three answer the majority of what actually arrives, and that the later items are what turn a passable submission into one that closes the diligence rather than extending it.

It starts with a one-page security overview and a system or architecture description: what the system is, where its boundaries are, how data flows through it, and which sub-processors are involved, named. Then the canonical answer bank, keyed to CAIQ v4 questions, because CAIQ maps to the Cloud Controls Matrix and the Cloud Controls Matrix maps to nearly every other instrument. Answering once and mapping many is the whole economic argument for doing this work as a project rather than reactively.

Third, and this is the highest-leverage single move available to a small vendor, publish a completed CAIQ to the CSA STAR Registry. A STAR Level 1 submission is a self-assessment, it is free, and it is publicly listed and machine-findable, which means it pre-empts a share of inbound questionnaires before they are sent. For an AI product, submit an AI-CAIQ as well. STAR Level 2 is third-party audited and comes in variants: STAR Certification, which leverages ISO/IEC 27001 together with the Cloud Controls Matrix and carries three-year validity, STAR Attestation, which uses SOC 2 engagements with AICPA criteria plus the matrix and carries one-year validity, and C-STAR for Greater China.

Then the policy set, versioned with real approval dates: information security, access control, change management, incident response, business continuity and disaster recovery, secure development lifecycle, data retention and deletion, sub-processor management, and AI or model governance. Then the evidence artefacts, which is where most packs are thinnest: the latest penetration test report with remediation status, vulnerability scan cadence, access review records, backup restore test records, an incident response tabletop record, and training completion records.

The legal pack is next and is more contested than most companies expect. A data processing agreement carrying genuine GDPR Article 28(3) obligations, including the right under Article 28(3)(h) to allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller. A sub-processor list with a notification mechanism, because Article 28(2) requires prior authorisation and, under general authorisation, the chance to object to changes; Article 28(4) keeps the original processor fully liable for its sub-processors. A business associate agreement template where protected health information is in scope, meeting the content requirements at 45 CFR 164.504(e). Standard contractual clauses under Commission Implementing Decision 2021/914 where transfers require them, retained as a fallback even where the EU-US Data Privacy Framework applies; the General Court dismissed the Latombe challenge to that framework on 3 September 2025 while stressing that the Commission is required to monitor continuously the application of the legal framework on which the adequacy decision is based.

Two clauses in a business associate agreement break AI vendors specifically, and it is better to discover this while writing your pack than while answering a hospital’s counsel. The return-or-destroy obligation at termination, which requires retaining no copies where feasible, collides with abuse-monitoring logs and with embeddings held in vector stores. And the access, amendment and accounting-of-disclosures obligations collide with architectures where personal health information has been transformed into embeddings that cannot be individually located or amended. A pack that has a considered answer to both is meaningfully ahead of one that does not.

Finally, a trust page that is findable without a sales call and states plainly what the company does not have, and a change log, because a stale pack is worse than no pack. The gap list is part of the deliverable rather than an embarrassment: a documented no with an owner and a date reads as competence, while a vague yes reads as risk.

Overview and system description

Boundaries, data flows, named sub-processors. One page, plus the architecture behind it.

Answer bank keyed to CAIQ

Answer once, map many. CAIQ maps to CCM, and CCM maps to nearly everything else.

Published STAR Level 1 CAIQ

Free, public and machine-findable. It pre-empts questionnaires before they are sent.

Evidence, not assertions

Pen test with remediation status, access reviews, restore tests, tabletop record, training records.

Contracts that survive review

DPA with real Article 28(3)(h) audit rights, sub-processor list, BAA template, SCC fallback.

A published gap list

A documented no with an owner and a date beats a vague yes in front of any competent reviewer.

Related evidence and next steps

The AI section

The answers a 2026 questionnaire now demands

If your product involves a language model, a growing part of the questionnaire is about the model rather than about your infrastructure, and the reviewer wants clauses rather than marketing pages. The good news is that the underlying facts are usually publicly documented by the model providers themselves, which means a defensible answer is a matter of citation rather than negotiation.

Start with training. Anthropic’s commercial terms state that Anthropic may not train models on Customer Content from Services. OpenAI’s platform documentation states that as of 1 March 2023, data sent to the OpenAI API is not used to train or improve OpenAI models unless the customer explicitly opts in, and its enterprise privacy page states that it does not train on customer data by default and that custom models are the customer’s alone and are not shared. Microsoft’s Azure AI Foundry documentation states that prompts, completions, embeddings and training data are not used by providers of models sold by Azure to improve their models or services, and that the models are stateless. The point for your pack is to say which of these applies to your actual deployment, and to name the model provider.

Then retention, where the honest answer is more nuanced than the training answer and where an unprepared vendor gets caught. OpenAI documents that by default, abuse monitoring logs are generated for all API feature usage and retained for up to 30 days unless longer retention is required by law, and that Zero Data Retention and Modified Abuse Monitoring are subject to prior approval by OpenAI and acceptance of additional requirements. Azure has a parallel application path and publishes a verifiable check: a ContentLogging value in the capabilities list appears and is set to false when abuse-monitoring logging is off. If your pack claims zero retention, include the approval evidence rather than the assertion.

Residency is a deployment-type question rather than a headquarters question, and this is the single most common error in an otherwise good answer. Azure’s documentation is explicit that for any deployment type labeled Global, prompts and responses may be processed in any geography where the relevant model sold by Azure is deployed. A vendor can be genuinely hosted in the EU and still have prompts processed globally. The same documentation is a useful benchmark for the specificity a reviewer should expect elsewhere: human reviewers access flagged data only via point-wise queries using request IDs, Secure Access Workstations and just-in-time request approval granted by team managers, the abuse-monitoring data store is logically separated by customer resource, fine-tuned models are exclusively available to the customer whose data created them, and for models deployed in the European Economic Area the authorised Microsoft employees are located in the European Economic Area.

The governance layer sits on top. NIST’s AI Risk Management Framework 1.0, released on 26 January 2023, is voluntary and organised around four functions, govern, map, measure and manage, with the Generative AI Profile, NIST AI 600-1, released on 26 July 2024. It confers no certification and no safe harbour, but it is a useful shared vocabulary in a questionnaire response. The OWASP Top 10 for LLM Applications, published by the OWASP Gen AI Security Project, is the best free structure for the technical half of the answer and names risks that no general questionnaire covers, including excessive agency and vector and embedding weaknesses.

On the EU AI Act, get the dates right, because most published timelines are now stale and a reviewer who spots an outdated one will assume you copied it. Regulation (EU) 2024/1689 entered into force on 1 August 2024. Prohibited practices and AI literacy obligations applied from 2 February 2025, and governance rules and general-purpose AI model obligations from 2 August 2025. The Act became generally applicable on 2 August 2026, including the Article 50 transparency obligations. Then the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, deferring the bulk of the Chapter III high-risk obligations to 2 December 2027 for stand-alone Annex III high-risk systems and 2 August 2028 for high-risk AI embedded as a safety component of a regulated product. What did not move: the Article 5 prohibitions, the general-purpose AI obligations in force since August 2025, and the Article 50 transparency duties. Penalties under Article 99 run up to €35,000,000 or 7 percent of total worldwide annual turnover for Article 5 breaches, up to €15,000,000 or 3 percent for most other operator breaches, and up to €7,500,000 or 1 percent for supplying incorrect or misleading information to authorities, whichever is higher in each case, except that for SMEs including start-ups each fine is capped at whichever figure is lower.

Name the model provider

The model provider is a sub-processor. Cite its training and retention terms by clause, not by marketing page.

Retention includes abuse logs

Default abuse-monitoring retention is real. If you claim zero retention, attach the approval evidence.

Residency is per deployment

A Global deployment type may process prompts in any geography where the model is deployed.

Model change control

A silent model version bump is a change to a validated system, and a GxP reviewer will always ask.

Related evidence and next steps

Annex 11 asks a question a security review never asks

EU GMP Annex 11 came into operation on 30 June 2011, and its section 3, Suppliers and Service Providers, is short and load-bearing. Where third parties provide, install, configure, validate, maintain or modify a computerised system, or process data, formal agreements must exist, with clear statements of the responsibilities of the third party, and internal IT departments are to be considered analogous. Competence and reliability are key factors, and the need for an audit is based on risk.
  • Section 3.4 is the clause that catches software vendors out: quality system and audit information relating to suppliers or developers of software and implemented systems should be made available to inspectors on request. A regulator can ask to see your quality system evidence, through your customer. A SOC 2 report delivered under a non-disclosure agreement does not automatically satisfy that.
  • Section 4.5 places the obligation on the customer rather than on you: the regulated user should take all reasonable steps to ensure that the system has been developed in accordance with an appropriate quality management system, and the supplier should be assessed appropriately. Your pack either makes that assessment cheap for them or expensive.
  • Other sections reach directly into a SaaS or AI product. Section 7.1 requires data to be secured and accessible throughout the retention period. Section 9 requires audit trails to be available and convertible to a generally intelligible form and regularly reviewed. Section 11 requires periodic evaluation covering upgrade history, performance, reliability, security and validation status reports. Section 12.3 requires that creation, change and cancellation of access authorisations be recorded. Section 16 requires tested business continuity, and section 17 requires archiving with proven retrievability after a system change.
  • The MHRA GxP Data Integrity Guidance, revision 1 of March 2018, adds the best single paragraph to hand a cloud vendor. Section 6.20 covers IT suppliers and service providers including cloud providers, and asks for attention to the service provided, ownership, retrieval, retention and security of data; the physical location where the data is held, including the impact of any laws applicable to that geographic location; a technical agreement ensuring timely access to data including metadata and audit trails for the data owner and national competent authorities on request; arrangements for the restoration of the software or system as per its original validated state, including validation and change control information to permit that restoration; and tested business continuity arrangements included in the contract.
  • Twenty-one CFR Part 11 supplies the electronic-records half of the same conversation, and the clauses that surprise SaaS vendors are not the famous ones. Section 11.10(b) requires the ability to generate accurate and complete copies of records in both human readable and electronic form suitable for inspection, review and copying by the agency, which is an export requirement most vendors have never been asked to build. Section 11.10(e) requires secure, computer-generated, time-stamped audit trails where record changes shall not obscure previously recorded information. Section 11.10(i) reaches into the vendor’s own training records for the people who develop and maintain the system, and section 11.1(e) makes the systems, controls and attendant documentation readily available for and subject to FDA inspection.
Quality reviewers examining supplier qualification documentation for a computerised system

Chapter 7 makes your subcontractors your customer’s business

EU GMP Chapter 7, Outsourced Activities, came into operation on 31 January 2013 and was revised specifically in view of ICH Q10 to provide guidance on outsourced GMP-regulated activities beyond contract manufacture and analysis. It is therefore the correct instrument for a software service rather than only for a contract manufacturer, which is a point many vendors and some quality units get wrong on first reading.
  • Section 7.5 sets the test that a security attestation cannot pass on its own: prior to outsourcing activities, the Contract Giver is responsible for assessing the legality, suitability and the competence of the Contract Acceptor to carry out successfully the outsourced activities. Three tests, and a SOC 2 report speaks to at most one of them.
  • Section 7.4 places ultimate responsibility with the Contract Giver, whose pharmaceutical quality system should include the control and review of any outsourced activities. Section 7.7 requires ongoing monitoring and review of performance rather than a one-time onboarding check.
  • Section 7.11 is the subcontractor clause with teeth: the Contract Acceptor should not subcontract to a third party any of the work entrusted to him under the Contract without the Contract Giver’s prior evaluation and approval of the arrangements, and information from the third-party suitability assessment must flow through in the same way. For an AI vendor whose model provider is a subcontractor, that is a hard requirement rather than a courtesy notification, and it is materially stricter than the GDPR Article 28(2) notify-and-object pattern.
  • Section 7.13 states that the Contract Acceptor should understand that outsourced activities may be subject to inspection by the competent authorities. A software vendor selling into GMP can be inspected, which is a sentence worth reading twice before answering a questionnaire question about whether you support customer audits.
  • The parent text is ICH Q10, which reached Step 4 on 4 June 2008. Its section 2.7 states that the pharmaceutical company is ultimately responsible to ensure processes are in place to assure the control of outsourced activities, and requires assessing, prior to outsourcing, the suitability and competence of the other party using audits, material evaluations and qualification, a written agreement defining responsibilities and communication, and monitoring and review of performance.
  • ICH Q9(R1), adopted at Step 4 on 18 January 2023, supplies the proportionality rule that governs how much assessment is enough: the evaluation of the risk to quality should be based on scientific knowledge and ultimately link to the protection of the patient, and the level of effort, formality and documentation of the quality risk management process should be commensurate with the level of risk. That is the sentence to quote when a customer proposes an assessment wildly out of proportion to what your product does.
Contract and subcontractor review during a pharmaceutical outsourced activity assessment

The 2025 drafts, and why they matter before they are final

On 7 July 2025 the European Commission opened a joint stakeholder consultation on three EudraLex Volume 4 documents: a revised Chapter 4 on documentation, a revised Annex 11 on computerised systems, and a brand-new Annex 22 on artificial intelligence. The consultation closed on 7 October 2025. As of 27 August 2026 no final text has been published, so everything in this section is draft, and any page that presents it as in force is wrong.
  • Draft Annex 11 grows to seventeen sections and its section 7 is now titled Supplier and Service Management. Section 7.1 states that when a regulated user is relying on a vendor’s qualification of a system used in GMP activities, this does not change the requirements, and the regulated user remains fully responsible based on the risk they constitute on product quality, patient safety and data integrity. That responsibility is not transferable, which is why no assessment performed by us or by anyone else substitutes for the customer’s own supplier qualification decision.
  • Draft section 7.2 says the regulated user should, according to risk and system criticality, conduct an audit or a thorough assessment to determine the adequacy of the vendor’s implemented procedures and the documentation associated with the deliverables, and the potential to leverage these rather than repeating the activities. Section 7.3 expects ongoing oversight against defined service level agreements and key performance indicators.
  • Draft section 7.4 is the clause no SOC 2 report satisfies: documentation is to be accessible and can be explained from their facility. Your customer must be able to explain your controls, in their own building, to an inspector. A report they may only read under NDA does not achieve that, and neither does a trust portal behind a login.
  • Draft section 7.5 sets a nine-point contract minimum: activities and documentation to be provided; company procedures and regulatory requirements to be met; regular, ad hoc and incident reporting with service levels, key performance indicators, answer and resolution times; conditions for supplier audits; support during regulatory inspections if requested; issue resolution; requirements and processes for communication of quality and security related issues; an exit strategy by which the regulated user may retain control of system data; and the process for release of new system versions and the regulated user’s possibility to test these prior to release. That last item is the one that breaks continuously deployed SaaS and silently updated models.
  • Draft Annex 22 is six pages of additional guidance to Annex 11 for computerised systems in which AI models are embedded, and its scope statement is blunt. It applies to static models: the use of dynamic models which continuously and automatically learn and adapt performance during use is not covered and should not be used in critical GMP applications. It applies to deterministic models: probabilistic models that might not provide identical outputs are likewise not covered and should not be used in critical GMP applications. It follows that the document does not apply to Generative AI and Large Language Models, and such models should not be used in critical GMP applications. In non-critical applications, personnel with adequate qualification and training should always be responsible for ensuring outputs are suitable for the intended use, that is, a human in the loop.
  • Do not overstate this. It is a draft, it is scoped to the manufacture of medicinal products and active substances, and critical GMP applications means direct impact on patient safety, product quality or data integrity. It does not ban language models from pharmaceutical companies. It is, however, the clearest regulatory signal currently on record, and its section 2.2 adds that documentation for the activities it describes should be available and reviewed by the regulated user irrespective of whether a model is trained, validated and tested in-house or provided by a supplier.
  • Two adjacent documents complete the picture. EMA’s reflection paper on the use of artificial intelligence in the medicinal product lifecycle, EMA/CHMP/CVMP/83833/2023, adopted by the CHMP on 9 September 2024, places responsibility with the sponsor, applicant, marketing authorisation holder or manufacturer to ensure algorithms, models, datasets and pipelines are fit for purpose and in line with legal, ethical, technical, scientific and regulatory standards, noting these may in some respects be stricter than what is considered standard practice in the field of data science, and expects a methodology qualification process for a third-party AI model used with high regulatory impact or high patient risk. And FDA issued a draft guidance in January 2025 on the use of artificial intelligence to support regulatory decision-making for drug and biological products, which as reported by Goodwin proposes a risk-based credibility assessment framework anchored on the context of use; we cite that via Goodwin rather than the primary text because fda.gov was not directly retrievable during our research.
Laboratory and manufacturing data workflows subject to draft EU GMP computerised systems guidance

Do you actually need a certificate yet?

This is the section most consultancies leave out, because the honest answer costs them revenue. A certification is a demand-driven artefact. Bought speculatively it converts a sales problem into a permanent operating cost, and it frequently fails to answer the question the buyer was obliged to ask. What follows is the case for not certifying, argued from the same primary sources as everything else on this page, followed by what to do instead and what the alternative actually costs.

The decision

Four situations where certification is the wrong purchase

None of these is an argument that certification is worthless. Each is a situation where the money buys less than something else would, and where the recurring cost outlasts the reason it was incurred. If none of the four applies to you, certify.

The first is the simplest: no customer has asked, and no deal is gated on it. Both SOC 2 and ISO 27001 are demand-driven artefacts, and buying one speculatively converts a sales problem into a fixed annual cost. Surveillance audits, recertification, bridge letters and the internal time to keep evidence flowing do not stop when the deal that motivated them closes or fails.

The second is scope mismatch. The scope you would certify is not the scope the buyer cares about. An ISO 27001 certificate covering the corporate IT function does not answer a question about the product, and a SOC 2 covering only the security category does not answer a question about availability. Money spent certifying the wrong boundary buys an artefact you cannot use in the conversation that mattered.

The third is capacity. Below roughly ten people, with no dedicated security owner, both instruments become difficult in a specific way: they require evidence generated continuously over a period. Without an owner, the observation window produces gaps, and gaps become exceptions in section 4 of the report. It is entirely possible to spend the full budget and receive a document that reads worse than nothing.

The fourth is the one this page exists to make: your buyer is a GMP manufacturer. A SOC 2 report does not satisfy draft Annex 11 section 7.4, because the documentation must be accessible and explainable from the customer’s own facility. It does not satisfy the nine-point contract minimum in draft section 7.5, which includes audit conditions, inspection support, an exit strategy returning control of system data, and the customer’s right to test new versions before release. It does not satisfy Chapter 7 section 7.11, which requires prior evaluation and approval of subcontractors, nor section 7.13, which makes you potentially subject to inspection. Spending the certification budget instead on a validation support package, an audit-ready quality manual and a GxP-competent contract answers the question that is actually being asked.

A certificate answers a question. Check first whether it is the question your buyer is obliged to ask.

Related evidence and next steps

The alternative

Six steps that answer more questions for less money

This is the sequence we run when certification is not yet warranted. It is ordered deliberately: the first step is free and public, the last step is the expensive one and it only happens when a named deal requires it. Most companies complete steps one through five and find that the questionnaire pressure substantially subsides.

Step one is to publish a CAIQ to the CSA STAR Registry. A Level 1 submission is a self-assessment, it costs nothing, and the registry is a publicly accessible listing of the security and privacy controls provided by cloud offerings. It is machine-findable, which matters more each year as procurement research increasingly begins with an assistant rather than an email. For an AI product, submit an AI-CAIQ alongside it using the CSA AI Controls Matrix and its STAR for AI Level 1 submission guide.

Step two is to write the control narrative and build the answer bank keyed to CAIQ. This is the artefact everything else maps back to, and it is what converts the next questionnaire from a week of archaeology into an afternoon of translation.

Step three is to get a real penetration test with a remediation record. A current test with findings closed is more persuasive to a technical reviewer than a Type 1 report, because it is concrete, it is recent, and it demonstrates that the organisation fixes what it finds. It is also the single most commonly requested evidence artefact in the questionnaires we see. Testing is only performed under a signed authorization letter scoping exactly what may be touched, against systems the client owns or is explicitly authorised to test.

Step four is the contract layer, which is where questionnaire answers become binding commitments and where an unprepared company either concedes something it should not or delays the deal arguing. A DPA with genuine Article 28(3)(h) audit rights rather than a clause that quietly converts a statutory audit right into permission to read a SOC 2 report. A named sub-processor list with a notification mechanism. A BAA template where PHI is in scope. And for GxP buyers, audit and inspection support, an exit strategy with a defined data return format, and a pre-release testing window for new versions.

Step five is to publish a trust page that states plainly what you have and what you do not. Being findable without a sales call removes an entire category of friction, and the explicit statement of absences is what makes the stated presences credible.

Step six is the certification itself, and only when a named deal requires it: run a SOC 2 Type 1 to establish design, and start the Type 2 observation window immediately, because that window is the part that cannot be compressed.

1. Publish a CAIQ on STAR

Free, public and machine-findable. The highest-leverage single move available to a small vendor.

2. Control narrative and answer bank

Keyed to CAIQ, so every later instrument becomes translation rather than rediscovery.

3. A real penetration test

With findings closed. More persuasive to a technical reviewer than a point-in-time report.

4. Fix the contract layer

Real audit rights, sub-processor list, BAA template, and GxP exit and pre-release testing clauses.

5. Publish a trust page

Findable without a sales call, and explicit about what you do not have.

6. Certify when a deal requires it

Type 1 for design, then start the Type 2 window immediately. It cannot be shortened later.

Related evidence and next steps

Cost and time

What the named vendors publish, presented as ranges

Certification pricing varies enormously by scope, headcount, system complexity and firm, and any single number quoted with confidence should be treated as a sales figure. What follows is attributed to the sources that publish it, so you can read their assumptions rather than ours. The structural point matters more than any individual figure: the audit fee is usually a minority of the total, and readiness, remediation, penetration testing, tooling and internal time dominate.

For SOC 2, Drata publishes Type 1 at $7,500 to $15,000 for small to midsize companies and $20,000 to $60,000 for large organisations; Type 2 at $12,000 to $20,000 for small to midsize companies and $30,000 to over $100,000 for enterprises; a readiness or gap assessment at $5,000 to $25,000; penetration testing at $5,000 to $15,000; and an all-in first year of $25,000 for a small startup to over $200,000 for a large enterprise. A-LIGN, an audit firm rather than a tooling vendor, publishes an overall range of $20,000 to $150,000 or more depending on company size, system complexity and audit scope.

On timing, A-LIGN describes Type 1 fieldwork as usually taking two to four weeks and a Type 2 programme as normally spanning six to twelve months. The phases are readiness and gap assessment, remediation, the observation window, fieldwork, and the report. Two consequences are consistently missed. A Type 2 cannot be compressed below its observation window, so a promise of SOC 2 in thirty days is describing either a Type 1 or something that will not survive review. And evidence generated after the window closes does not count, which is why the boring work of making evidence accumulate automatically is worth doing before the window opens rather than during it.

For ISO 27001, High Table publishes a total range of £5,000 to £50,000 and a 2026 baseline of £1,500 per auditor day, with roughly five audit days at £6,250 for one to ten employees rising to about 28 days at £36,875 for organisations above 8,500 people. Stage 1, the documentation review, is approximately 20 to 30 percent of certification fees and Stage 2, the implementation audit, approximately 70 to 80 percent. Annual surveillance is around a third of the initial fee with a full recertification in year three. Implementation routes range from a £500 do-it-yourself toolkit to £5,000 to £40,000 for a consultant.

Read those surveillance and recertification numbers carefully, because they are the part that changes the decision. A certificate is not a purchase, it is a subscription with an audit attached. For a company where the certificate is genuinely opening deals that is straightforwardly good economics. For a company that bought one because a competitor had one, it is a line item that will still be there in year four.

Drata, SOC 2

Type 1 at $7,500 to $15,000 for SMBs; Type 2 at $12,000 to $20,000; first year all-in from $25,000.

A-LIGN, SOC 2

$20,000 to $150,000 or more overall. Type 1 fieldwork two to four weeks; Type 2 six to twelve months.

High Table, ISO 27001

£5,000 to £50,000 total, on a 2026 baseline of £1,500 per auditor day, five to 28 audit days by size.

The recurring part

Surveillance at roughly a third of the initial fee annually, plus recertification in year three.

Related evidence and next steps

Sequencing

A thirty, sixty and ninety day shape

The calendar depends on how much already exists, how quickly internal owners can be assembled, and whether a deal is already in motion. The shape below is what we typically run when nothing is on fire, and it deliberately front-loads the artefacts that reduce the cost of every subsequent request.

In the first thirty days the objective is a single source of truth. We inventory what exists, interview the people who actually operate the controls, write the control narrative, and produce the system description with data flows and named sub-processors. The gap list is drafted here, with owners and dates attached, and it is reviewed honestly rather than optimistically, because a gap discovered now is cheap and the same gap discovered by a reviewer is not.

In the second thirty days the objective is reusability and publication. The answer bank is built against CAIQ v4, the policy set is versioned and approved, the evidence index is assembled and each artefact is dated, and the CAIQ is submitted to the STAR Registry. Where the product involves a model, the AI section of the pack is written: provider named, retention and training terms cited by clause, deployment type and residency stated, tenant isolation and fine-tuning separation described, and a model change-control commitment agreed internally before it is offered to a customer.

In the third thirty days the objective is the layer that separates a life-science vendor from a generic one. The GxP pack is built: supplier quality documentation, a validation support package for the customer’s own qualification, a Part 11 and Annex 11 traceability view, an audit trail specification with its export format, and the contract clauses covering audit and inspection support, exit strategy and pre-release testing. Where certification is warranted, this is also when the audit firm or certification body is selected, by you, independently of us.

Throughout, the working assumption is that your team learns to operate this rather than renting it indefinitely. The measure of a successful readiness engagement is that the third questionnaire is answered without us.

Related evidence and next steps

What we build, and who builds it

Readiness work produces artefacts, not opinions. Each item below is a deliverable your team owns afterwards and can maintain without us. Where technical security depth is required, the work is led by a named independent security architect on our expert bank rather than by generalists, and full attestation work is referred to an audit firm.

Control narrative

A written statement per control area of what you do, why, and who owns it. The single source of truth every instrument maps back to, in both the security and the quality register.

See the practice

Canonical answer bank

Answers keyed to CAIQ v4, so SIG, HECVAT and bespoke questionnaires become translation rather than rediscovery. Includes the published STAR Level 1 submission where appropriate.

The mirror-image service

Evidence index

Policies, penetration test results, access reviews, restore tests, tabletop records and training records, versioned, dated and findable. Assembly cost is what usually breaks a deadline.

Where test evidence comes from

GxP supplier pack

Supplier quality documentation, a validation support package, an audit trail specification with export format, and the contract clauses on audit, inspection, exit and pre-release testing.

Validation services

AI disclosure pack

Model provider named, training and retention terms cited by clause, deployment type and residency, tenant isolation, fine-tuning separation, human oversight design and model change control.

AI policy and governance

Honest gap register

Every place the correct answer today is no, with an owner and a date. Published internally, and drawn on when a customer asks something we would otherwise be tempted to soften.

How we state our own

Where this sits in the security practice

This page is one service in a cluster. One page assesses the vendors you buy from; this one prepares you to be the vendor being assessed. The others supply the evidence and the design decisions that make the answers true.

The mirror image
AI Vendor Security Assessment
The same questions, asked in the other direction. That page is for when you are evaluating an AI vendor. This one is for when a pharma partner, CRO or acquirer is evaluating you.
Assess a vendor
The evidence
Penetration Testing and Secure Code Review
A current test with findings closed is the artefact questionnaires ask for most often. Performed only under a signed authorization letter scoping exactly what may be touched. Testing is insured.
See testing scope
The design
Classification and Access Model
Access-control answers are only true if the underlying model enforces them. This engagement builds the taxonomy, group structure and platform configuration that the answers describe.
Build the model

Questions about questionnaire and certification readiness

Often not yet, and it is worth asking the question honestly before spending the money. SOC 2 is a demand-driven artefact: it is worth buying when a named customer has gated a named deal on it, and it is an expensive standing cost when nobody has asked. It is also not a certification. It is an attestation examination performed by a licensed CPA firm under AICPA attestation standards, producing a report with an opinion in it. If your buyer is a GMP manufacturer, the report will not answer the question they are contractually obliged to ask, because a security attestation does not address supplier qualification, documentation you can explain from your own facility, subcontractor approval, or inspectability. In that situation the same budget spent on a control narrative, a validation support package and a GxP-competent contract answers more of the questionnaire than a Type 2 does.
No, and that is a feature rather than a limitation. IntuitionLabs is not a CPA firm, not an accredited certification body, and not a notified body. We do not issue SOC 2 reports, ISO certificates, HITRUST certifications or AI Act conformity assessments, and we never will. The professions involved are deliberately structured to prevent the same organisation from building and then blessing a control environment. AICPA independence rules treat designing, implementing or maintaining internal control as a management responsibility so significant that no safeguard can cure it, and ISO/IEC 17021-1 clause 5.2.5 forbids certification bodies from providing management system consultancy at all. That prohibition is precisely what creates a legitimate preparation role, and it only works if the preparer stays on its side of the line.
We build the answer bank, we draft the answers, and we sit with your team while the specific instrument is completed, but the person who signs it must be someone in your company who can stand behind it. A security questionnaire is a representation made by your company to a customer, frequently incorporated into a contract by reference. Someone external asserting facts about controls they do not operate is exactly the pattern that produces the overclaim a reviewer later catches. What we can do is make the honest answer fast: a canonical answer bank keyed to CAIQ, an evidence index, a named owner per control area, and a written record of where the correct answer is currently a documented no with a remediation date attached.
Readiness work and certification work are on different clocks and it is worth separating them. A control narrative, an evidence index and a canonical answer bank for a company of fifty to a few hundred people is a matter of weeks, and it starts paying back on the first questionnaire it answers. Certification is longer and partly outside anyone’s control. A-LIGN describes SOC 2 Type 1 fieldwork as usually two to four weeks and a Type 2 programme as normally spanning six to twelve months, because a Type 2 opinion covers operating effectiveness throughout a period and that period cannot be compressed. ISO 27001 runs on a Stage 1 and Stage 2 audit with a three-year cycle and annual surveillance. Any promise of a certificate in thirty days is either describing a Type 1 or describing something that will not survive review.
Answer the question your buyer is actually asking rather than collecting instruments. HIPAA is not a certification and no one can issue one, so a claim of being HIPAA certified is a category error that a knowledgeable reviewer will notice immediately; what a covered entity needs from you is a signed business associate agreement meeting the content requirements of 45 CFR 164.504(e), including the subcontractor flow-down and the return-or-destroy obligation at termination. HITRUST carries disproportionate weight in US healthcare and payer procurement specifically, and its portfolio is tiered: e1 with 43 controls, i1 with 182, and the tailored r2. SOC 2 is the general-purpose instrument most technology buyers recognise. In EU pharma manufacturing none of these is the operative expectation; Annex 11 and Chapter 7 are.
They are mirror images of the same problem. Our AI vendor security assessment service is for the company doing the assessing: you are about to hand data to an AI vendor and you need to know what to ask and how to read the answers. This page is for the company being assessed: your pharma partner, CRO or acquirer has sent the questionnaire and you have to answer it accurately, consistently and without stalling the deal. Most life-science companies eventually need both, because the same organisation buys AI tooling and sells software or services into a regulated customer. The two engagements share an evidence base, which is why running them together usually costs less than running either twice.
In priority order: a one-page security overview and a system description with data flows and named sub-processors; a canonical answer bank keyed to CAIQ v4, because CAIQ maps to the Cloud Controls Matrix and the Cloud Controls Matrix maps to almost everything else; a published CAIQ on the CSA STAR Registry; a versioned policy set with approval dates; evidence artefacts including a current penetration test with remediation status, access review records and backup restore tests; a legal pack with a DPA carrying genuine Article 28(3)(h) audit rights, a sub-processor list and a BAA template where PHI is in scope; an AI-specific pack naming the model provider and citing its retention terms by clause; and, for life-science buyers, a GxP pack the customer can hold and explain from its own facility. A change log matters too, because a stale pack is worse than no pack.
It is the failure mode that does the most quiet damage, because inconsistency reads to a reviewer as either incompetence or concealment and there is no good way to recover from that impression mid-deal. It happens structurally rather than through carelessness: SIG, CAIQ and a customer’s bespoke Word document ask the same underlying question in three different vocabularies, and without a canonical answer bank each one gets answered from scratch by whoever is available that week. The fix is not more discipline, it is a single source of truth that each instrument maps back to, so that the question of whether you encrypt backups has exactly one recorded answer, one owner, and one piece of evidence behind it.
No, and understanding why is the most useful thing on this page. A security attestation tests whether a vendor runs a competent security programme. A GxP supplier assessment tests something the security frameworks never test: whether the regulated user remains able to discharge a legal responsibility it is not permitted to delegate. Draft Annex 11 section 7.4 requires that documentation be accessible and explainable from the regulated user’s own facility, which a report delivered under NDA does not achieve. Draft Annex 11 section 7.5 sets out a nine-point contract minimum including audit conditions, inspection support, an exit strategy returning control of system data, and the customer’s right to test new versions before release. EU GMP Chapter 7 section 7.11 requires prior evaluation and approval of subcontractors, and section 7.13 makes the contract acceptor itself potentially subject to inspection.
It is no longer bolted on. The Shared Assessments SIG 2026 release added a comprehensive mapping to ISO/IEC 42001, so AI governance questions are now part of the standard instrument for every organisation running a SIG-based programme. ISO/IEC 42006:2025, published in July 2025, sets the requirements for bodies certifying AI management systems, which is why 42001 certificates are moving from self-declared to accredited. The Cloud Security Alliance published its AI Controls Matrix in July 2025 with 243 control objectives across 18 domains and a companion AI-CAIQ, which is free and currently the closest thing to a standard AI self-assessment. What a reviewer wants from you is your model provider named, its training and retention terms cited by clause, your deployment type and residency stated precisely, and a model change-control commitment.
Readiness work is done by IntuitionLabs consultants alongside your own owners, because the controls have to be operated by people who work at your company. Where technical security depth is required, the engagement is led by a named security architect on our expert bank: an independent consultant with seventeen years in information security, including a decade on the central security team of a major enterprise infrastructure vendor covering design and architecture review, source code review, penetration testing and vulnerability response, plus earlier client-facing consultancy work. The specialist is named to you in the engagement letter, and is a specialist on the expert bank rather than an employee — the value of which is that a review can be performed by someone who did not build what they are reviewing.
No. IntuitionLabs was founded in 2023 and does not hold SOC 2 or ISO 27001, and we would rather say that plainly on a page about certification than let a reader assume otherwise. Our own security posture is documented on our security page and in our Trust Center, and it is deliberately described in terms of what we actually do rather than what we are accredited for. The argument this page makes is not that certificates are worthless. It is that most life-science companies are asked for evidence long before they are asked for a certificate, and that the honest statement of what you have and do not have is a stronger position than an overclaim that gets discovered during diligence.
Bring the Questionnaire You Are Stuck On

Bring the Questionnaire You Are Stuck On

Send the instrument that arrived, the deal it is attached to, and whatever evidence you already have. We will tell you which answers you can give truthfully today, which need work first, and whether a certificate is actually the thing your buyer is asking for. We prepare; we do not certify.

Book a Meeting

© 2026 IntuitionLabs. All rights reserved.