AI Governance Institute
All governance templates →How do we ensure third-party AI vendors meet our standards?

Implementation Kit

AI Vendor Due Diligence Questionnaire and Checklist

A repeatable due diligence pass for any material AI vendor: a questionnaire across four domains, a contract clause checklist, a weighted scorecard, and a model card request. The output is a documented DD record per vendor with gaps and contractual protections tracked.

Who this is for: The procurement, vendor risk, or third-party risk manager assessing a new AI vendor or a renewal, working with Legal on the contract.

Download the kit (Markdown) ↓4 artifacts. Every table also copies as CSV.

1. AI vendor due diligence questionnaire

Spreadsheet

What you send the vendor. Grouped into four domains so a specialist can review each part. Record the answer, the evidence, and your own assessor note per row.

Template

#DomainQuestionVendor responseEvidence providedAssessor noteFlag
1Model and dataWhich models power the service, and are they first-party or sub-processed?
2Model and dataIs customer data used to train or improve your models? Is opt-out the default?
3Model and dataWhat data were the models trained on, and how do you handle IP and licensing in training data?
4Model and dataWhat evaluations do you run for accuracy, safety, and bias, and how often?
5Model and dataWhat are the documented limitations and known failure modes?
6Model and dataDo you provide a model or system card?
7Security and privacyWhat certifications do you hold (SOC 2 Type II, ISO 27001, ISO 42001)?
8Security and privacyWhere is data processed and stored, and can we pin a region?
9Security and privacyHow is our data isolated from other customers and from your training pipeline?
10Security and privacyWhat is your data retention and deletion policy for prompts and outputs?
11Security and privacyHow do you test for prompt injection and data exfiltration?
12Security and privacyWhat was the outcome of your last penetration test?
13Governance and complianceDo you have a named AI governance owner and an AI risk process?
14Governance and complianceHow do you assess and disclose regulatory applicability (EU AI Act role, sector rules)?
15Governance and complianceWill you notify us before material changes to models or safety posture?
16Governance and complianceDo you support audit rights, and in what form (report, questionnaire, on-site)?
17Governance and complianceHave you had an AI-related incident, regulatory inquiry, or litigation?
18Operational resilienceWhat is your uptime commitment and historical performance?
19Operational resilienceWhat is your incident notification window for security and AI-behaviour incidents?
20Operational resilienceWhat is your sub-processor list, and how do you notify changes?
21Operational resilienceWhat happens to our data and our access on termination?
22Operational resilienceWhat is your financial position, and who funds you?

Worked example

#DomainQuestionVendor responseEvidenceAssessor noteFlag
2Model and dataCustomer data used for training? Opt-out default?"Not used for training. No opt-out needed."DPA section 6.2Confirmed in contract languageNo
4Model and dataEvaluations for accuracy, safety, bias, and cadence"Internal evals each release; third-party red team annually"Summary memo, no methodologyAsk for methodology and last red-team dateYes
8Security and privacyData location, can we pin a region?"EU or US; region pinning on Enterprise plan"Trust centre pageRequires the plan tier we are buying, acceptableNo
15Governance and complianceAdvance notice of material model changes?"Changelog published; no advance notice"Public changelogGap. Needs a contractual notice windowYes
19Operational resilienceIncident notification window"72 hours for security incidents"MSA draft clause 11Want 24h for anything touching our data; negotiateYes
Summary3 flags: eval transparency, change notice, incident window

Acceptance criteria

  • Every question has a vendor response and a link or attachment to supporting evidence, or an explicit note that none was provided.
  • Each domain has been reviewed by someone competent in that domain (security reviews the security rows, Legal reviews governance rows).
  • Every flagged row is carried into the scorecard and, where it needs a contract fix, into the clause checklist.

2. AI contract clause checklist

Spreadsheet

The AI-specific terms to get into the contract. For each, whether it is present, and your fallback if the vendor pushes back.

Template

ClauseWhy it mattersPresent?Fallback position
Training data useStops your data improving the vendor's models by defaultY / NContractual opt-out plus deletion on request
Change notificationGives you time to re-test before a model changes under youY / N30 days notice for material model or safety changes
Incident notificationSets a clock on being told about a breach or harmful behaviourY / N24 hours for anything involving your data
Audit rightsLets you verify claims rather than take them on trustY / NAnnual questionnaire plus right to a third-party report
Sub-processor controlControls who else touches your dataY / NList plus notice and objection right for changes
Liability and indemnity for AI outputsAllocates risk for IP claims and harmful outputsY / NCarve-out from the general liability cap for IP infringement
Data return and deletion on exitPrevents lock-in and lingering copiesY / NReturn in a usable format within 30 days, certified deletion
Regulatory cooperationVendor helps you meet your own obligationsY / NReasonable assistance with FRIA, DPIA, and regulator requests

Worked example

ClausePresent in draft?Note
Training data useYDPA 6.2, acceptable as written
Change notificationNAdd: 30 days for material changes. Vendor initially offered changelog only
Incident notificationPartialDraft says 72h; redlined to 24h for data-involving incidents
Audit rightsYAnnual questionnaire plus SOC 2 report, acceptable
Sub-processor controlYList provided; added 15-day objection window
Liability for AI outputsNLegal adding IP indemnity carve-out from the cap
Data return and deletionY30 days, certified deletion
Regulatory cooperationNAdd: assistance with FRIA and regulator queries
Status4 of 8 need redlines; sent to vendor counsel 2026-09-03

Acceptance criteria

  • Every clause is marked present, partial, or absent against the actual contract draft, not the vendor's marketing.
  • Absent or partial clauses have a redline in progress with an owner, or a documented, approved decision to accept the gap.
  • The fallback positions are agreed with Legal before negotiation starts, so the reviewer is not improvising.

3. Vendor risk scorecard

Spreadsheet

Rolls the questionnaire into a single rating. Weight the dimensions to your context, score each 1 (poor) to 5 (strong), and read off the total.

Template

DimensionWeightScore (1-5)WeightedNotes
Model and data transparency0.25
Security and privacy posture0.25
Governance and regulatory readiness0.20
Operational resilience0.15
Contractual protections achievable0.15
Total1.00

Rating: 4.0 and above is Low risk. 3.0 to 3.9 is Moderate, proceed with the flagged items tracked. 2.0 to 2.9 is High, needs governance sign-off and a remediation plan. Below 2.0 is Do not proceed.

Worked example

DimensionWeightScoreWeightedNotes
Model and data transparency0.2530.75Eval methodology not shared
Security and privacy posture0.2541.00SOC 2 Type II, ISO 27001, region pinning
Governance and regulatory readiness0.2030.60Named owner, but no advance change notice
Operational resilience0.1540.6099.9% uptime, sub-processor list provided
Contractual protections achievable0.1530.454 redlines outstanding, vendor engaging
Total1.003.40Moderate. Proceed with the 3 flags and 4 redlines tracked to closure

Acceptance criteria

  • The weights are set for your risk context before scoring, not adjusted afterwards to reach a preferred rating.
  • Each score has a one-line justification tied to questionnaire evidence.
  • A Moderate or worse rating has a named approver and a remediation plan with dates before the vendor is onboarded.

4. Model / system card request

Document

What to ask the vendor to provide when they have no published card. Send it as a template so the response is comparable across vendors.

Template

Ask the vendor to complete and return. Chase the gaps.

  • Model name and version:
  • Provider, and any sub-processed models:
  • Intended use and out-of-scope use:
  • Training data: sources, cut-off date, languages, known gaps
  • Evaluation results: benchmarks, safety testing, bias testing, with dates
  • Known limitations and failure modes:
  • Guardrails: content filtering, refusal behaviour, jailbreak resistance testing
  • Update and deprecation policy: cadence, notice, support window
  • Data handling: retention of prompts and outputs, training use, region
  • Contact for security and AI-behaviour issues:

Worked example

  • Model name and version: VendorLM-4, served build 2026-07
  • Provider: first-party; embeddings sub-processed to a named third party
  • Intended use: support and knowledge tasks. Out of scope: legal, medical, or financial advice
  • Training data: licensed and public web to 2026-01; weak coverage of non-European languages
  • Evaluation results: internal accuracy suite each release; annual external red team, last completed 2026-05; bias testing on a standard benchmark, results shared on request
  • Known limitations: cites plausible but wrong sources under ambiguity; degrades on inputs over 50k tokens
  • Guardrails: content filter on by default; jailbreak testing part of the red team
  • Update policy: roughly quarterly; changelog only, no advance notice today
  • Data handling: prompts and outputs retained 30 days for abuse monitoring; not used for training; EU or US region
  • Contact: security@vendor.example, ai-safety@vendor.example

Acceptance criteria

  • The vendor returned the template, and every field is answered or explicitly marked unavailable.
  • Evaluation and testing claims carry dates, so you can tell whether they are current.
  • The completed card is attached to the due diligence record and refreshed at each renewal.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

PRC-001
AI Vendor Due Diligence

The completed questionnaire and scorecard are the due diligence record for the vendor, with a rating and a rationale.

PRC-002
AI Contractual Requirements

The clause checklist evidences which AI-specific contractual protections were sought and secured, and the approved position on any gaps.

PRC-003
Third-Party AI Model Evaluation

The model card request and the model-and-data questionnaire section document the third-party model evaluation.

PRC-004
Vendor AI Incident Notification Requirements

The incident-notification questionnaire rows and clause checklist set and record the vendor incident notification window.

PRC-005
AI Procurement Risk Assessment

The scorecard is the procurement-stage AI risk assessment, weighted and rated before onboarding.

PRC-007
Vendor Governance Change Monitoring

The change-notification question and clause create the hook for ongoing vendor governance-change monitoring after onboarding.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →