Implementation Kit
AI Vendor Due Diligence Questionnaire and Checklist
A repeatable due diligence pass for any material AI vendor: a questionnaire across four domains, a contract clause checklist, a weighted scorecard, and a model card request. The output is a documented DD record per vendor with gaps and contractual protections tracked.
Who this is for: The procurement, vendor risk, or third-party risk manager assessing a new AI vendor or a renewal, working with Legal on the contract.
1. AI vendor due diligence questionnaire
SpreadsheetWhat you send the vendor. Grouped into four domains so a specialist can review each part. Record the answer, the evidence, and your own assessor note per row.
Template
| # | Domain | Question | Vendor response | Evidence provided | Assessor note | Flag |
|---|---|---|---|---|---|---|
| 1 | Model and data | Which models power the service, and are they first-party or sub-processed? | ||||
| 2 | Model and data | Is customer data used to train or improve your models? Is opt-out the default? | ||||
| 3 | Model and data | What data were the models trained on, and how do you handle IP and licensing in training data? | ||||
| 4 | Model and data | What evaluations do you run for accuracy, safety, and bias, and how often? | ||||
| 5 | Model and data | What are the documented limitations and known failure modes? | ||||
| 6 | Model and data | Do you provide a model or system card? | ||||
| 7 | Security and privacy | What certifications do you hold (SOC 2 Type II, ISO 27001, ISO 42001)? | ||||
| 8 | Security and privacy | Where is data processed and stored, and can we pin a region? | ||||
| 9 | Security and privacy | How is our data isolated from other customers and from your training pipeline? | ||||
| 10 | Security and privacy | What is your data retention and deletion policy for prompts and outputs? | ||||
| 11 | Security and privacy | How do you test for prompt injection and data exfiltration? | ||||
| 12 | Security and privacy | What was the outcome of your last penetration test? | ||||
| 13 | Governance and compliance | Do you have a named AI governance owner and an AI risk process? | ||||
| 14 | Governance and compliance | How do you assess and disclose regulatory applicability (EU AI Act role, sector rules)? | ||||
| 15 | Governance and compliance | Will you notify us before material changes to models or safety posture? | ||||
| 16 | Governance and compliance | Do you support audit rights, and in what form (report, questionnaire, on-site)? | ||||
| 17 | Governance and compliance | Have you had an AI-related incident, regulatory inquiry, or litigation? | ||||
| 18 | Operational resilience | What is your uptime commitment and historical performance? | ||||
| 19 | Operational resilience | What is your incident notification window for security and AI-behaviour incidents? | ||||
| 20 | Operational resilience | What is your sub-processor list, and how do you notify changes? | ||||
| 21 | Operational resilience | What happens to our data and our access on termination? | ||||
| 22 | Operational resilience | What is your financial position, and who funds you? |
Worked example
| # | Domain | Question | Vendor response | Evidence | Assessor note | Flag |
|---|---|---|---|---|---|---|
| 2 | Model and data | Customer data used for training? Opt-out default? | "Not used for training. No opt-out needed." | DPA section 6.2 | Confirmed in contract language | No |
| 4 | Model and data | Evaluations for accuracy, safety, bias, and cadence | "Internal evals each release; third-party red team annually" | Summary memo, no methodology | Ask for methodology and last red-team date | Yes |
| 8 | Security and privacy | Data location, can we pin a region? | "EU or US; region pinning on Enterprise plan" | Trust centre page | Requires the plan tier we are buying, acceptable | No |
| 15 | Governance and compliance | Advance notice of material model changes? | "Changelog published; no advance notice" | Public changelog | Gap. Needs a contractual notice window | Yes |
| 19 | Operational resilience | Incident notification window | "72 hours for security incidents" | MSA draft clause 11 | Want 24h for anything touching our data; negotiate | Yes |
| Summary | 3 flags: eval transparency, change notice, incident window |
Acceptance criteria
- ✓Every question has a vendor response and a link or attachment to supporting evidence, or an explicit note that none was provided.
- ✓Each domain has been reviewed by someone competent in that domain (security reviews the security rows, Legal reviews governance rows).
- ✓Every flagged row is carried into the scorecard and, where it needs a contract fix, into the clause checklist.
2. AI contract clause checklist
SpreadsheetThe AI-specific terms to get into the contract. For each, whether it is present, and your fallback if the vendor pushes back.
Template
| Clause | Why it matters | Present? | Fallback position |
|---|---|---|---|
| Training data use | Stops your data improving the vendor's models by default | Y / N | Contractual opt-out plus deletion on request |
| Change notification | Gives you time to re-test before a model changes under you | Y / N | 30 days notice for material model or safety changes |
| Incident notification | Sets a clock on being told about a breach or harmful behaviour | Y / N | 24 hours for anything involving your data |
| Audit rights | Lets you verify claims rather than take them on trust | Y / N | Annual questionnaire plus right to a third-party report |
| Sub-processor control | Controls who else touches your data | Y / N | List plus notice and objection right for changes |
| Liability and indemnity for AI outputs | Allocates risk for IP claims and harmful outputs | Y / N | Carve-out from the general liability cap for IP infringement |
| Data return and deletion on exit | Prevents lock-in and lingering copies | Y / N | Return in a usable format within 30 days, certified deletion |
| Regulatory cooperation | Vendor helps you meet your own obligations | Y / N | Reasonable assistance with FRIA, DPIA, and regulator requests |
Worked example
| Clause | Present in draft? | Note |
|---|---|---|
| Training data use | Y | DPA 6.2, acceptable as written |
| Change notification | N | Add: 30 days for material changes. Vendor initially offered changelog only |
| Incident notification | Partial | Draft says 72h; redlined to 24h for data-involving incidents |
| Audit rights | Y | Annual questionnaire plus SOC 2 report, acceptable |
| Sub-processor control | Y | List provided; added 15-day objection window |
| Liability for AI outputs | N | Legal adding IP indemnity carve-out from the cap |
| Data return and deletion | Y | 30 days, certified deletion |
| Regulatory cooperation | N | Add: assistance with FRIA and regulator queries |
| Status | 4 of 8 need redlines; sent to vendor counsel 2026-09-03 |
Acceptance criteria
- ✓Every clause is marked present, partial, or absent against the actual contract draft, not the vendor's marketing.
- ✓Absent or partial clauses have a redline in progress with an owner, or a documented, approved decision to accept the gap.
- ✓The fallback positions are agreed with Legal before negotiation starts, so the reviewer is not improvising.
3. Vendor risk scorecard
SpreadsheetRolls the questionnaire into a single rating. Weight the dimensions to your context, score each 1 (poor) to 5 (strong), and read off the total.
Template
| Dimension | Weight | Score (1-5) | Weighted | Notes |
|---|---|---|---|---|
| Model and data transparency | 0.25 | |||
| Security and privacy posture | 0.25 | |||
| Governance and regulatory readiness | 0.20 | |||
| Operational resilience | 0.15 | |||
| Contractual protections achievable | 0.15 | |||
| Total | 1.00 |
Rating: 4.0 and above is Low risk. 3.0 to 3.9 is Moderate, proceed with the flagged items tracked. 2.0 to 2.9 is High, needs governance sign-off and a remediation plan. Below 2.0 is Do not proceed.
Worked example
| Dimension | Weight | Score | Weighted | Notes |
|---|---|---|---|---|
| Model and data transparency | 0.25 | 3 | 0.75 | Eval methodology not shared |
| Security and privacy posture | 0.25 | 4 | 1.00 | SOC 2 Type II, ISO 27001, region pinning |
| Governance and regulatory readiness | 0.20 | 3 | 0.60 | Named owner, but no advance change notice |
| Operational resilience | 0.15 | 4 | 0.60 | 99.9% uptime, sub-processor list provided |
| Contractual protections achievable | 0.15 | 3 | 0.45 | 4 redlines outstanding, vendor engaging |
| Total | 1.00 | 3.40 | Moderate. Proceed with the 3 flags and 4 redlines tracked to closure |
Acceptance criteria
- ✓The weights are set for your risk context before scoring, not adjusted afterwards to reach a preferred rating.
- ✓Each score has a one-line justification tied to questionnaire evidence.
- ✓A Moderate or worse rating has a named approver and a remediation plan with dates before the vendor is onboarded.
4. Model / system card request
DocumentWhat to ask the vendor to provide when they have no published card. Send it as a template so the response is comparable across vendors.
Template
Ask the vendor to complete and return. Chase the gaps.
- Model name and version:
- Provider, and any sub-processed models:
- Intended use and out-of-scope use:
- Training data: sources, cut-off date, languages, known gaps
- Evaluation results: benchmarks, safety testing, bias testing, with dates
- Known limitations and failure modes:
- Guardrails: content filtering, refusal behaviour, jailbreak resistance testing
- Update and deprecation policy: cadence, notice, support window
- Data handling: retention of prompts and outputs, training use, region
- Contact for security and AI-behaviour issues:
Worked example
- Model name and version: VendorLM-4, served build 2026-07
- Provider: first-party; embeddings sub-processed to a named third party
- Intended use: support and knowledge tasks. Out of scope: legal, medical, or financial advice
- Training data: licensed and public web to 2026-01; weak coverage of non-European languages
- Evaluation results: internal accuracy suite each release; annual external red team, last completed 2026-05; bias testing on a standard benchmark, results shared on request
- Known limitations: cites plausible but wrong sources under ambiguity; degrades on inputs over 50k tokens
- Guardrails: content filter on by default; jailbreak testing part of the red team
- Update policy: roughly quarterly; changelog only, no advance notice today
- Data handling: prompts and outputs retained 30 days for abuse monitoring; not used for training; EU or US region
- Contact: security@vendor.example, ai-safety@vendor.example
Acceptance criteria
- ✓The vendor returned the template, and every field is answered or explicitly marked unavailable.
- ✓Evaluation and testing claims carry dates, so you can tell whether they are current.
- ✓The completed card is attached to the due diligence record and refreshed at each renewal.
Governance controls this kit produces evidence for
Completing the artifacts above gives you a head start on the evidence requirements for these controls.
The completed questionnaire and scorecard are the due diligence record for the vendor, with a rating and a rationale.
The clause checklist evidences which AI-specific contractual protections were sought and secured, and the approved position on any gaps.
The model card request and the model-and-data questionnaire section document the third-party model evaluation.
The incident-notification questionnaire rows and clause checklist set and record the vendor incident notification window.
The scorecard is the procurement-stage AI risk assessment, weighted and rated before onboarding.
The change-notification question and clause create the hook for ongoing vendor governance-change monitoring after onboarding.
This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.
Decide what to implement next
Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.
Start the AI governance assessment →