Back to Blog
Vendor Management
Vendor Due Diligence for AI Systems: What to Ask
Your AI vendors need to support your compliance. Here's a comprehensive due diligence questionnaire for AI vendors.
Dr. Anna MüllerJanuary 5, 20259 min read
Vendor Due Diligence for AI Systems: What to Ask
When you deploy AI systems from third-party vendors, you inherit compliance responsibilities. Your vendors need to support—not hinder—your EU AI Act compliance.
The Vendor Compliance Questions
AI System Documentation
- Can you provide technical documentation of your AI system?
- What is the intended purpose and scope of use?
- What are the known limitations of the system?
- Do you provide instructions for use?
Risk Classification
- Have you classified your AI system under the EU AI Act?
- What is the classification result?
- Can you share your classification reasoning?
- Do you have prohibited practices screening results?
High-Risk Obligations (if applicable)
- Is the system registered in the EU database?
- Do you have a conformity assessment?
- What quality management system is in place?
- Can you provide the CE marking documentation?
Data and Privacy
- What data does the AI system process?
- Where is data stored and processed?
- What data retention policies apply?
- Do you have a DPA that covers AI processing?
Transparency
- What transparency notices should we provide to users?
- Are outputs marked as AI-generated (if applicable)?
- What information should we disclose to affected persons?
Logging and Monitoring
- What logs does the system generate?
- How long are logs retained?
- Can we export logs on demand?
- What monitoring capabilities are available?
Incident Response
- What is your incident response process?
- How will you notify us of issues?
- What is your SLA for critical issues?
- How do we report concerns to you?
Ongoing Compliance
- How do you stay current with EU AI Act requirements?
- Will you provide compliance updates?
- What happens if the system needs modification for compliance?
Get the Full Questionnaire
Download our Vendor Due Diligence Questionnaire to use in your procurement process.
Get More Insights
Subscribe to receive the latest EU AI Act updates and compliance tips.