The Short Answer
The delay between choosing a research platform and actually using it is almost never the vendor's fault — it is sequencing. Most teams run the approval gates one after another: security review, then legal, then privacy, then procurement. Run serially, that is 12 to 20 weeks. Run in parallel, with every document requested on day one, the same gates close in 4 to 6 weeks.
Three things compress the timeline more than anything else: request the full document pack before your first demo, start the privacy review in parallel with security instead of after it, and check whether the tool has a self-serve tier you can pilot on a company card while the enterprise contract moves. That last one matters more than teams expect — a platform like Koji, which starts at €29/month on self-serve, lets you run real studies during the procurement window instead of waiting it out.
Why Research Tools Stall Longer Than Other Software
A customer research platform trips more review wires than a typical SaaS purchase, because it does two things security teams treat as high-scrutiny at once:
- It collects first-party personal data. Interview transcripts contain names, employer details, opinions about your product, and — when people talk freely — health, financial, and family context nobody put in a form field.
- It processes that data with AI. The moment transcription and analysis run through model providers, your reviewer has a sub-processor chain to vet, a training-data question to answer, and, as of 2026, an AI-specific regulatory checklist.
Most SaaS tools trigger one review track. Research platforms trigger both, and the two tracks are usually owned by different people who do not talk to each other. That handoff is where the weeks disappear.
The Five Gates, and What Each Actually Costs You
Benchmarks from 2026 enterprise sales data give a realistic picture of each stage:
| Gate | Typical duration | Who owns it | Can it run in parallel? |
|---|---|---|---|
| Security review | Median 28 days; top quartile under 21 | InfoSec / IT | Yes — start first |
| Privacy / DPIA review | 2–4 weeks | Legal / DPO | Yes — run alongside security |
| Legal redlines (MSA, DPA) | 2–8 weeks | Legal / Counsel | Partially — needs security sign-off to finalize |
| Procurement approval | 2–6 weeks | Procurement / Finance | Yes — start vendor onboarding early |
| Budget sign-off | 1–4 weeks | Budget owner | Yes — do this before anything else |
The headline numbers are worth sitting with. The median enterprise security review runs 28 days, and the top quartile of deals hold it under 21. Legal redlines and procurement approval together are the number one cause of delayed closes, and negotiation-to-close consumes 35–40% of total enterprise cycle time. In the worst observed cases, 20 weeks pass between a verbal yes and a signature.
Run serially, those medians stack to roughly 14–18 weeks. Run in parallel, the critical path is whichever single gate is slowest — usually legal redlines — and you land at 4–6 weeks.
The Day-One Document Pack
The single highest-leverage move is to ask the vendor for everything before your first real demo, not after each reviewer asks for the next item. One request, one package, no round-trips.
Ask for:
- SOC 2 Type II report or ISO 27001 certificate (under NDA if needed), plus a dated roadmap if they do not have one yet
- A completed SIG Lite or CAIQ — SIG Lite runs about 130 questions, SIG Core about 800, and CAIQ has 261 yes/no/NA items mapped to the Cloud Controls Matrix. A vendor with a pre-filled copy saves your team a month.
- Data Processing Agreement (DPA), pre-signed or ready to countersign
- Full sub-processor list with purpose, data categories, and hosting region for each
- Data residency statement — where compute runs and where data rests, named regions
- Standard Contractual Clauses (SCCs) for any international transfer
- Penetration test summary and incident response policy
- Model-layer answers: is customer data used to train models, what is prompt retention, can retention be zeroed
If a vendor cannot produce most of that within a week, that is your timeline signal. Our buyer's evaluation guide to AI interview data privacy breaks down what good answers look like on each point, and the enterprise security guide covers the controls checklist your InfoSec team will work from.
The AI Gate That Is New in 2026
Standard security questionnaires were not written for AI vendors, and reviewers know it. Two developments changed the 2026 review:
The CSA AI Controls Matrix (AICM v1.0) and its companion AI-CAIQ landed in July 2025 as the canonical AI vendor questionnaire — 243 control objectives across 18 domains, with published mappings to NIST AI 600-1, ISO/IEC 42001, and the EU AI Act. If your security team has adopted it, expect the AI-specific section to add one to two weeks.
EU AI Act Article 50 transparency obligations apply from 2 August 2026. For AI-moderated research this is directly relevant: systems must inform people when they are interacting with an AI rather than a human. A platform that already discloses AI moderation to participants clears this by design; one that blurs the line creates a compliance problem your legal team will have to solve. We cover the specifics in the EU AI Act and user research.
The practical move: ask the AI questions in your very first vendor email. Training data, prompt retention, sub-processor disclosure, and participant AI-disclosure are the four that stall reviews, and they are answerable in a paragraph by any vendor who has thought about it.
The Parallelization Playbook
Week 0 — before you talk to vendors. Confirm the budget owner and the approval threshold. Many companies have a spend level below which procurement is not involved at all; knowing yours changes your entire strategy. Request the document pack from your shortlist.
Week 1 — open every gate at once. Send the security pack to InfoSec, the DPA and sub-processor list to legal and your DPO, and start vendor onboarding paperwork with procurement. Do not wait for security to finish before legal starts — they review different documents.
Weeks 2–4 — work the critical path. Security and privacy usually resolve here. Track blocking questions daily and route them to the vendor same-day; the slowest part of most reviews is a question sitting in someone's inbox.
Weeks 4–6 — legal close. Redlines are the long pole. Accepting the vendor's standard DPA unmodified, where your counsel is comfortable, removes the single biggest source of delay.
Throughout — pilot on self-serve. This is the step most teams miss.
Do Not Wait to Start Researching
Here is the structural problem with the whole process: the research question that justified the tool does not pause for procurement. A pricing decision, a churn investigation, a launch readiness check — those have dates.
This is where the pricing model of the platform matters as much as its features. Enterprise-only AI research platforms force you through the full gauntlet before you can run a single interview. Listen Labs starts around a $20K annual base plus $300–400 per session. Strella runs an enterprise per-study model at roughly $10K–$25K+ per engagement. Both are legitimate products, but neither has a path where a PM validates the tool this week.
Koji is built the other way around. The Insights plan is €29/month (29 credits) and the Interviews plan is €79/month (79 credits), both self-serve. Credits are consumed at 1 per text interview, 3 per voice interview, and 5 per report refresh — and a quality gate means only conversations scoring 3 or higher consume a credit at all, so abandoned or junk sessions do not bill you. That means a team can run a real study on a company card in week 1 while the enterprise contract moves through legal in the background. By the time procurement closes, you are not guessing whether the tool works — you have the output.
Why Koji Clears Security Review Faster
Koji is built and operated in the EU, which removes several of the questions that usually generate round-trips:
- Application and compute run on Vercel in Paris (cdg1); database, accounts, and file uploads on Supabase in Paris (eu-west-3). Product analytics and transactional email are also processed in the EU.
- A DPA is available to every business customer — not gated to an enterprise tier.
- The full sub-processor list is published openly, with the purpose, data categories, and region for each. Reviewers can read it before they ask.
- International transfers to AI and payment providers are governed by Standard Contractual Clauses and each provider's own DPA.
- Signup is gated to verified business email — consumer, disposable, and school domains are blocked.
- For larger deployments, the compliance hub holds the enterprise package: custom MSA, BAA, countersigned DPA, completed security questionnaires, and SOC 2 / ISO status under NDA. EU-resident AI processing is available as an enterprise option, via Google Vertex AI's EU regions and ElevenLabs EU data residency with optional zero-retention voice mode.
On the research side, Koji runs AI-moderated voice and text interviews that probe follow-ups automatically, produces automatic thematic analysis across every transcript, and generates one-click reports — with no moderator in the room to introduce bias. Studies combine open conversation with six structured question types (open_ended, scale, single_choice, multiple_choice, ranking, yes_no), so the same session yields quotable narrative and chartable numbers.
Get Moving While the Paperwork Moves
Procurement is a queueing problem, not a persuasion problem. Open every gate on day one, hand reviewers a complete document pack before they ask, and pick a platform you can pilot without a signature.
Start a Koji study today — €29/month, self-serve, no procurement required. Run the research that justified the purchase while the contract works its way through legal.
If you are still building the internal case, our user research budget template has the line items and ROI language that get budgets approved, and the stakeholder buy-in playbook covers the conversation before the paperwork.