AI procurement due diligence

Generate a proportionate AI vendor risk questionnaire

Translate your use case, data profile and operational exposure into a tailored set of supplier questions, evidence requests, scoring guidance and contract-focused actions.

Transparent and non-legal.
Results are deterministic and depend on the information you provide. No external API is used.
AI supplier due diligence illustrationA shield, checklist, evidence folder and connected vendor systems.

How it works

Complete the context fields, review the generated risk profile, then use the question set during sourcing, contracting, onboarding and periodic reassessment.

1. Describe the engagement

Capture procurement stage, use case, criticality, data, hosting and who may be affected.

2. Apply deterministic logic

The tool weights material risk factors and assigns questionnaire priorities without hidden data.

3. Export and assess

Collect supplier responses, compare evidence, identify red flags and retain an auditable record.

AI vendor context

Fields marked required must be completed. The generated questionnaire is guidance and should be adapted to your legal, regulatory and contractual context.

Organisation and procurement context
Example: “Summarise customer-support conversations and recommend next actions to trained agents; no automated customer decisions.”
Risk and operating profile
Additional risk triggers

Methodology, limitations and use

The tool applies a transparent weighting model to contextual risk factors, then raises the priority of question areas that are commonly material for the selected operating profile.

Methodology

Weighted points represent potential governance intensity, not legal classification. Question priority changes when inputs indicate sensitive data, material impacts, autonomous integration, continuous learning or complex dependencies.

Limitations

The result does not replace legal advice, security testing, privacy assessment, financial due diligence, sector-specific review or direct verification of supplier evidence.

How to use the result

Use it to structure market engagement, RFPs, contract schedules, onboarding gates and recurring reviews. Record accepted exceptions, compensating controls, owners and deadlines.

Frequently asked questions

What is an AI vendor risk questionnaire?

It is a structured set of questions used to assess a supplier’s governance, data practices, security, privacy, model controls, resilience, subcontractors, assurance and contractual readiness for a defined AI use case.

Does a higher score mean the supplier is unsafe?

No. The score measures the intensity of due diligence suggested by your context. Supplier quality can only be evaluated after reviewing responses, evidence, testing and contract terms.

How should supplier answers be scored?

A practical scale is 0 for no evidence, 1 for partial evidence, 2 for adequate evidence and 3 for strong, current and independently assured evidence. Apply documented judgment and record exceptions.

Which evidence should be requested first?

Prioritise current service-specific evidence for security, privacy, data provenance, model testing, incident response, subprocessors, change control, audit assurance and exit arrangements.

Can this tool support an RFP?

Yes. Export the question set to CSV, add commercial and technical requirements, define mandatory evidence and explain how responses will be evaluated.

How often should an AI supplier be reassessed?

Use a risk-based cadence and reassess after material model, hosting, subprocessor, data-use, regulatory or intended-use changes. Higher-risk services often justify at least annual review with interim monitoring.

What is a red flag?

A red flag is a response or absence of evidence that may indicate unacceptable uncertainty, weak control design, limited transparency or contractual imbalance requiring escalation or compensating controls.

Should foundation-model providers be assessed separately?

Where material, assess both the direct supplier and underlying model or infrastructure providers. Confirm responsibility allocation, evidence coverage, incident flow-down and change notification.

Does the questionnaire determine regulatory compliance?

No. It supports structured due diligence but does not determine legal status, regulatory classification or compliance. Obtain qualified advice for applicable jurisdictions and sectors.

How should accepted risks be documented?

Record the risk statement, evidence considered, rationale, compensating controls, accountable approver, review date, trigger events and any contractual protections.

Can sensitive information be entered safely?

Avoid entering confidential personal or security-sensitive details. This page states that calculations are local, but users should follow their organisation’s information-handling rules and verify the wider site’s implementation.

What should happen before production use?

Complete evidence review, use-case testing, security and privacy checks, contract controls, human oversight design, incident procedures, monitoring thresholds, rollback planning and accountable approval.