As it turns out, all of my current engagements are for AI companies. Basically SaaS companies that utilize AI for very specific business service delivery. One of these companies targets major global enterprises so I'm getting a first hand view of how these enterprises are looking at their risks.
Suggestions: get your basic SOC2/ISO27x stuff in order. It answers a lot right out of the gate.
Be prepared to explain, in detail how the clients data will be exposed to the LLM. Have a rock-solid one-two pager on that. Helps focus discussions.
This is new stuff for some of these big enterprises so there is not a lot of similarity between their questions/tools yet. Everyone is learning about how AI is implemented in business tools. Expect lots of questions from lots of parties; IT, Cyber, legal, IP. Expect lots of duplicate questions.
Keep you own tooling up to date with client questions/questionnaires about AI controls and your answers for repeatability.
One client has asked about ISO42001, and we have it backlogged and I'm starting to cost out the program. We are pretty sure having it will help speed procurement with other large prospects.
Happy to answer any specific questions.