A practical AI vendor risk checklist covering purpose, data, security, model limitations, documentation, changes, contracts and human oversight.
Supplier assurance starts with your intended use
A vendor questionnaire only works when the buyer has defined how the system will be used. Evidence that is proportionate for an internal productivity assistant may be insufficient for a system influencing important decisions about customers or employees.
Questions worth asking
- What is the system's intended purpose and what uses does the provider restrict?
- What customer data is processed, where, for how long and for what purposes?
- Is customer content used to train or improve models, and what controls are available?
- What documentation exists on accuracy, limitations, testing, bias and human oversight?
- How does the provider handle security incidents and material model or feature changes?
- Which AI Act role does the provider consider it occupies and what supporting documentation will it supply?
- Can the contract support audit, notification, deletion and exit needs appropriate to the risk?
Do not outsource the risk decision
A supplier can explain its system, but your organisation still owns the decision to use it for your chosen purpose. Marketing claims such as 'compliant AI' do not replace an assessment of your configuration, data, users and consequences.
Plan for change
AI services can change quickly. Define which model, feature, data or contractual changes require re-review. A procurement decision made against one system configuration may not remain valid indefinitely.
Blanche perspective
Match due diligence depth to impact. Standardise a short baseline for ordinary AI suppliers, then require stronger evidence and specialist review where decisions, sensitive data or regulatory classification make the consequences greater.
Sources
Primary and authoritative sources used for this Insight.