Same discipline. Different room.
Life sciences built serious governance for the clinical side. The commercial side answers a buyer's security questionnaire with no source, no owner, no record.
A controlled document announces itself before it says anything. If you work anywhere near the clinical side of a life-sciences company, you’ve seen that header so many times you’ve stopped seeing it.
Now picture the commercial side of the same company, 6:40 on a Tuesday. A buyer’s security team has sent back forty questions with a Friday deadline.
- Document number
- Version
- Effective date
- Approved by, with a name and a date beside it
- The version it replaced is archived, not deleted
- No version
- No effective date
- No approver
- No expiry
- Three tabs: last quarter’s questionnaire, a shared drive, a chat thread from March
Same company. Same regulatory culture. Two completely different standards.
The asymmetry nobody actually decided on
Regulators have been converging on AI accountability in clinical settings — the FDA published draft guidance on AI supporting regulatory decision-making in January 2025, and the EMA and FDA issued joint guiding principles in January 2026. The clinical side responded the way that side of the house always responds — with a policy, a named owner, and a record.
The two halves of each of those rows never sit in the same meeting, which is most of why the gap persists. Each side is coherent on its own terms. Nobody is holding both at once. The last row lands hardest with anyone who has ever sat through an audit.
Same discipline. Different room.
It’s an absence, not a failure
The natural read is that somebody dropped the ball on the commercial side. That’s wrong, and it matters that it’s wrong, because it points at the wrong fix.
Nobody dropped anything. There was never anything to drop. The clinical standard exists because a regulator, an auditor, or a very expensive lesson forced someone to decide that the work deserved a standard — and then someone built one, staffed it, and enforced it. That decision has a date on it. Somebody made it.
No one has ever made that decision about the commercial answers. Not because the answers matter less. A response to a vendor-risk questionnaire is a representation your company has to stand behind, sitting in a buyer’s file, quotable back at you in a renewal conversation two years from now. It matters plenty. It’s just that no one ever put it on an agenda, so it inherited the default: whoever’s free, whatever’s handy, whenever it’s due.
Absence is harder to see than failure.
A failure produces an incident. An absence produces a Tuesday that looks like every other Tuesday.
Swap the nouns and it’s your company too
I lead with life sciences because that’s where the contrast is most vivid — the clinical side of that industry has the most mature controls of any commercial-adjacent function I’ve worked around. But the asymmetry isn’t a life-sciences problem. It’s a shape, and once you know the shape you find it nearly everywhere.
A B2B software company has change management on production deploys, peer review on every merge, and an audit trail on every release. Then it answers a buyer’s security questionnaire — the document that describes all of that control — from memory, under deadline, with no review.
A health system runs credentialing, privacy training, and access controls with real teeth. Its vendor-facing and payer-facing commercial answers run on a folder.
B2B software is where I have watched this most closely, and it is the sharpest version of the irony: the questionnaire is literally asking you to describe controls you demonstrably have. Your engineering organisation could evidence every one of them from its own systems. The document describing them is assembled from memory under deadline.
The same shape shows up wherever a regulated or audited function sits near a commercial one — insurance, financial services, health systems. Supervised, archived and reviewed on one side of the house. Improvised on the other.
The pattern: a regulated or audited function with genuine controls, sitting three doors down from a commercial function with none — and the commercial function is the one talking to the customer.
Here’s what that absence costs, at its simplest. The following is a composite, not anyone’s deal — but every seller who has been through two evaluations in one quarter will recognize it.
Two buyers ask the same security question six weeks apart. Where is data at rest encrypted, and who holds the keys? Two different people answer, drawing from two different documents, both current as far as either of them knew. Both answers go out. Both are now on the record with two different customers.
Neither person lied. Neither was careless. Nobody flagged it, because nobody was watching, because watching wasn’t anyone’s job.
That’s an orphaned answer: a sentence your company is bound to that no human owns. It costs you nothing on the day you send it. It costs you on the day someone reads both.
Where my work stops
Let me be exact about the boundary, because this argument runs alongside a discipline I hold no credential in.
I govern the answer, not the model. Not GxP. Not computer-system validation. Not model-performance testing, not regulatory strategy, not your quality system. I’m not auditing the clinical side and I’m not offering to improve it. I point at it because you already respect it, and because it proves the standard is achievable inside your own walls by your own people.
What I work on is narrower. RFP and RFI responses. Security and vendor-risk questionnaires. The sales content that carries claims about your company into someone else’s evaluation. Not contracts, not redlines, not terms — that’s a lawyer’s job and I won’t pretend otherwise.
That’s the surface. It’s the one I’ve spent my career on: in B2B SaaS and life sciences since 2011, running Deal Desk and Sales Operations since 2018. I built a 2,000+ Q&A response library and a Deal Desk from scratch that governed a $25M+ pipeline, and I’ve built and audited over 5,000 responses for buyers in clinical research, health systems, insurance and financial services.
What the commercial version of that discipline looks like
It looks like the clinical version, minus the regulatory weight and most of the cost. That’s the good news buried in the asymmetry — you’re not inventing a practice. You’re copying one that already works, from a team down the hall.
Five questions. If you can answer them about your last twenty outbound answers, you have Commercial AI Governance whether or not you call it that. If you can’t, you have a browser tab.
Which source may this be drawn from?
One current, owned version of every recurring answer. Not five copies in five drives, and — if a model is doing the drafting — a stated boundary on what it’s allowed to pull from.
Who approves it before a buyer sees it?
A named person for each answer domain. Security answers don’t get approved by whoever’s online.
Where’s the record?
Approved by whom, on what date, against what version. This is the whole ballgame, and it’s the one nobody has.
Is it still true?
A recency rule per domain, because a security answer and an office-location answer decay at wildly different speeds. Answers expire. Almost nobody dates them.
Does it contradict what we already said?
A check across what’s already gone out. The two-buyers problem is invisible without one.
None of that requires software you don’t have. It requires a decision, an owner, and a cadence — which is exactly the recipe the clinical side used.
The clinical side didn’t get its discipline because those people were more careful than your commercial team. It got it because somebody decided the work deserved a standard, and then built one. That decision has never been made about the answers your company sends to buyers. That’s all that’s actually missing.
Go find the last security questionnaire your company sent. Who approved it — and how long would it take you to find out?