Playbook ┬╖ 6 minute read
How to Respond to an AI Regulator Inquiry
A regulatory inquiry about an AI system is answered from evidence that already exists. The sequence is to preserve everything, understand exactly what is being asked, assemble what exists, and coordinate a single accurate response rather than several partial ones.
Regulatory inquiries about AI systems are answered from evidence that already exists. The response is largely a retrieval exercise for organisations that built evidence as they went, and a project for those that did not. This playbook covers handling one, drawing on FISTA Solutions' AI enablement work. This article is general guidance, not legal advice.
When is this worth doing?
On receipt of any formal inquiry, information request, or examination notice concerning an AI system.
The preparation, however, happens long before: an organisation that maintains an inventory, assessments, evaluation evidence, and decision records experiences an inquiry very differently from one that does not.
What does the sequence look like?
| Step | Purpose |
|---|---|
| 1. Preserve everything | Before anything else |
| 2. Engage counsel | Early, not after the first response |
| 3. Understand the request | Precisely, with clarification |
| 4. Assemble what exists | From where it already lives |
| 5. Coordinate one response | Single voice, consistent |
| 6. Fix what the gaps revealed | Regardless of the outcome |
Step 1 тАФ Preserve evidence immediately
Suspend routine deletion and log rotation for anything potentially relevant: system logs, trajectories, evaluation results, version records, approvals, and internal communications.
This is the first action because it is time-sensitive. Logs rotate on schedules, and evidence lost to a routine process during an inquiry is considerably worse than evidence that never existed, because the loss itself requires explaining.
Record what was preserved, when, and by whom.
Step 2 тАФ Engage counsel early
Before the first substantive response rather than after it.
The framing of early responses shapes the rest of the inquiry, and communications made without counsel can be difficult to unwind. Organisations that respond helpfully and quickly to establish good faith sometimes create problems the response was meant to avoid.
That is not a reason to be slow or obstructive. It is a reason to have the right people involved before the first document goes out.
Step 3 тАФ Understand exactly what is being asked
Read the request precisely. What systems, what period, what documents, what decisions.
Ambiguity is common and asking for clarification is normal and expected. Guessing produces either over-disclosure, which generates further questions, or under-disclosure, which looks evasive.
Map the request to what you hold before responding, so the response describes what exists rather than what was requested.
Step 4 тАФ Assemble from where the evidence lives
Pull the inventory entries, risk assessments, evaluation results with dates and versions, approval records, decision records, and incident history for the systems in scope.
Organisations with these as by-products of how they work complete this in days. Organisations without them are now doing the assessment work under a deadline, which is the expensive way to do it.
Do not edit historical documents. Supplement them with a covering explanation if context is needed, and leave the originals as they are. See AI compliance audit cost.
Step 5 тАФ Coordinate a single response
One point of contact, one review process, one version of the response.
Multiple people responding separately produces inconsistencies, and inconsistencies in a regulatory response are themselves a finding тАФ frequently a more serious one than whatever prompted the inquiry.
Brief anyone who might be contacted directly about where to route enquiries, including people who no longer work on the system.
Step 6 тАФ Fix what the gaps revealed
Whatever you could not produce quickly is what your programme is missing.
That list is more valuable than the inquiry's outcome. An organisation that could not produce evaluation evidence, or could not say which model version was in use when, has learned something specific and actionable.
Act on it visibly. Remediation started before the inquiry concludes is both better practice and materially better received.
What should you not do?
Create documents that look reconstructed. An assessment written last week describing a decision from two years ago is transparent to anyone reading carefully, and it converts a documentation gap into a credibility problem.
Equally, do not volunteer material outside the scope of the request. Helpfulness is good; expanding the inquiry's surface is not, and the distinction is one counsel can help with.
How do you prepare before an inquiry arrives?
By building evidence as a by-product of engineering rather than as a compliance activity.
An inventory with owners, assessments tied to specific use, evaluation results with dates and versions, decision records, and incident history. Organisations with those answer inquiries by retrieval.
The test is simple: pick three systems and try to produce all of that without a special exercise. Whatever you cannot produce is what an inquiry will ask for. See what is an ai inventory.
Who needs to be involved?
A coordinator, counsel, the technical owners of the systems in scope, and someone senior enough to approve the response.
The technical owners are needed for accuracy and should not be the point of contact. Responses drafted by engineers under regulatory pressure tend to include more detail than is helpful.
How long does it take?
Days to weeks depending on the request and the state of the evidence. Organisations with evidence already assembled respond in days; those without spend weeks producing it.
What are the common failure modes?
Losing evidence to routine rotation. Responding before engaging counsel. Guessing at an ambiguous request. Several people responding separately. Reconstructing documents. And treating the outcome as the end of the matter.
How do you know it worked?
A response that is accurate, consistent, and delivered on time, with a clear record of what was provided, and a remediation plan for what the gaps revealed.
What does it cost?
Mostly people's time rather than tooling. The expensive version is the one that stalls halfway and leaves the organisation with neither the old state nor the new one, which is why a narrow first pass beats a comprehensive plan nobody finishes.
Budget the work as an operated change rather than a project with an end date, because most of these need a maintenance tail. See AI total cost of ownership.
What should you do first?
Suspend deletion on anything potentially relevant. That takes minutes and it is the action that cannot be taken later.
How FISTA Solutions helps
FISTA Solutions runs this work alongside client teams rather than around them: evidence produced as a by-product of engineering so inquiries are answered by retrieval, gaps identified and remediated rather than papered over, evidence produced as the work proceeds, and handover that leaves your people able to continue without us. Delivery runs through AI agents, AI enablement, and forward deployed engineers. The record is 150+ projects for 50+ companies across 12+ countries, with 47% average efficiency gains where measured.
To run this with support, message FISTA on WhatsApp, or read AI compliance audit cost.
Share-ready article cover
Download the generated social format.
Clear answers
Questions raised by this field note.
Straightforward guidance for evaluating scope, fit, and the next step.
01What is the first thing to do?
Preserve evidence: logs, versions, evaluation results, approvals, and communications. Routine deletion and log rotation continue while you prepare, and losing evidence during an inquiry is considerably worse than not having had it.
02How should the request be interpreted?
Precisely and narrowly, with clarification sought where it is ambiguous. Over-answering provides material that generates further questions; under-answering looks evasive. Ask what is meant rather than guessing.
03Who should respond?
One coordinated team with a single point of contact. Multiple people responding separately produces inconsistencies, and inconsistencies in a regulatory response are themselves a finding.
04What if the evidence does not exist?
Say so plainly, explain what does exist, and describe what is being done about it. Reconstructing documents to fill a gap is transparent to anyone reading carefully and turns a gap into a credibility problem.
05What happens afterwards?
Use the inquiry as a map of what your programme is missing. Whatever you could not produce quickly is what to fix, regardless of how the inquiry itself is resolved.
Continue exploring
Related capabilities
Start with the hard problem
Need the outcome owned, not merely analyzed?
Tell us where delivery is constrained. WeтАЩll map the fastest credible path from intent to verified production.