Direct answerAI supplier due diligence is the evidence-led assessment of a vendor, AI system and contract before purchase and throughout use. Buying the product does not remove the buyer’s responsibility for its chosen use, data, oversight or downstream impact.

The evidence to request

System identityProduct, model and version; intended purpose; known limitations; deployment and update model.
Roles and riskSupplier’s supported EU AI Act role, risk classification and reasoning for the intended use.
Data and testingData provenance and governance, evaluation design, results, failure modes and bias testing relevant to use.
ControlsHuman oversight, transparency, access, logging, monitoring, incident and change-management design.
Supply chainModel providers, subprocessors, hosting locations, material dependencies and notification commitments.
AssuranceRelevant independent reports and certificates, their scope, validity and any exclusions.
ContractAudit rights, evidence updates, incident deadlines, change notice, exit support and responsibility allocation.

What strong and weak answers look like

Weak: “Our AI is compliant and unbiased.”

Stronger: “Version 4.2 was tested against these representative user groups and failure modes on 18 July; results and limits are attached; this control owner reviews drift monthly; the following exceptions remain open.”

The stronger answer is bounded, dated, attributable and verifiable. Procurement can turn it into a decision record and contractual obligation.

Red flags that should pause a purchase

  • The vendor cannot identify the model, material subprocessors or where customer data flows.
  • Testing claims are not connected to the buyer’s intended users, context or failure impact.
  • Role and risk claims are assertions without system-level reasoning.
  • The contract permits material model changes without notice or reassessment.
  • Incident notification, audit access, data return and exit assistance are unclear.
  • A certificate is presented without its scope, expiry date or issuing body.

A proportionate scoring process

  1. Screen the intended use, affected people and business impact before issuing the questionnaire.
  2. Request evidence in proportion to that risk; do not demand the same pack for every tool.
  3. Score both the answer and the supporting evidence, recording gaps and compensating controls.
  4. Route material legal, security, data-protection and fundamental-rights issues to the right specialists.
  5. Convert accepted assumptions into contract terms, owners and reassessment triggers.

Use the AI vendor DDQ and the new procurement evidence-pack guide.

Frequently asked questions

What is AI supplier due diligence?

It is the evidence-led assessment of an AI supplier, system and contract before purchase and throughout use.

What evidence should a vendor provide?

Evidence should cover system identity, roles and risk, data and limitations, testing, oversight, transparency, security, incidents, suppliers, changes and contract commitments.

Is an ISO certificate enough?

No. It can support assurance, but the actual product, use, scope and unresolved risks still require assessment.

When should a supplier be reassessed?

At least annually and whenever the model, purpose, data, risk, supplier chain or incident history changes materially.

Use a repeatable evidence pack

Download the procurement checklist or book a focused review of the evidence your buyers or suppliers currently exchange.

Related guidance

Sources

Last reviewed 14 August 2026. General information, not legal advice.