← Resource library
FIELD GUIDE

AI vendor due diligence

The goal is not to collect reassuring answers. It is to obtain enough relevant evidence for the client to understand supplier dependency, limitations and the controls it still owns as a deployer or downstream provider.

Core evidence questions

Role & product
Who is the provider of the AI system/model, what is the intended purpose, and which version/service is being supplied?
Upstream dependencies
Which third-party models, APIs or material AI components does the service depend on?
Data provenance
What data was used where relevant, what is its provenance, and what governance/quality controls were applied?
Performance
What metrics and test populations support the claimed performance for the intended use?
Bias & impacts
What groups and failure modes were tested, what limitations remain, and how are residual risks communicated?
Human oversight
What information and controls enable the customer to understand, challenge, override or stop the AI where needed?
Logging
What logs are generated, who can access them, how long are they retained and how can the customer use them for monitoring?
Security
What AI-specific security testing, vulnerability management and incident response are in place?
Transparency
What technical or user-facing features help the customer meet applicable transparency duties?
Changes
How will customers be notified of model, data, functionality, intended-purpose or material performance changes?
Incidents
What is the process and timeframe for notifying customers of serious incidents, material failures or relevant regulatory issues?
Conformity evidence
Where relevant, provide applicable technical documentation, instructions for use, declaration/CE evidence and registration information.

Red flags

Consultant habit

For every important vendor answer, ask: “What evidence supports that, which system/version does it cover, and what remains the customer's responsibility?”

This guide reflects AI Act Ready training and themes in the uploaded Vendor Due Diligence lesson. Live procurement decisions should be checked against current law, contract requirements and appropriate legal, privacy, security and technical review.