# AI Vendor Due Diligence Questionnaire and Checklist

A repeatable due diligence pass for any material AI vendor: a questionnaire across four domains, a contract clause checklist, a weighted scorecard, and a model card request. The output is a documented DD record per vendor with gaps and contractual protections tracked.

**Who this is for:** The procurement, vendor risk, or third-party risk manager assessing a new AI vendor or a renewal, working with Legal on the contract.

Source playbook: https://aigovernance.com/playbook/third-party-ai-vendor-due-diligence

---

## AI vendor due diligence questionnaire

_What you send the vendor. Grouped into four domains so a specialist can review each part. Record the answer, the evidence, and your own assessor note per row._

### Template

| # | Domain | Question | Vendor response | Evidence provided | Assessor note | Flag |
|---|---|---|---|---|---|---|
| 1 | Model and data | Which models power the service, and are they first-party or sub-processed? | | | | |
| 2 | Model and data | Is customer data used to train or improve your models? Is opt-out the default? | | | | |
| 3 | Model and data | What data were the models trained on, and how do you handle IP and licensing in training data? | | | | |
| 4 | Model and data | What evaluations do you run for accuracy, safety, and bias, and how often? | | | | |
| 5 | Model and data | What are the documented limitations and known failure modes? | | | | |
| 6 | Model and data | Do you provide a model or system card? | | | | |
| 7 | Security and privacy | What certifications do you hold (SOC 2 Type II, ISO 27001, ISO 42001)? | | | | |
| 8 | Security and privacy | Where is data processed and stored, and can we pin a region? | | | | |
| 9 | Security and privacy | How is our data isolated from other customers and from your training pipeline? | | | | |
| 10 | Security and privacy | What is your data retention and deletion policy for prompts and outputs? | | | | |
| 11 | Security and privacy | How do you test for prompt injection and data exfiltration? | | | | |
| 12 | Security and privacy | What was the outcome of your last penetration test? | | | | |
| 13 | Governance and compliance | Do you have a named AI governance owner and an AI risk process? | | | | |
| 14 | Governance and compliance | How do you assess and disclose regulatory applicability (EU AI Act role, sector rules)? | | | | |
| 15 | Governance and compliance | Will you notify us before material changes to models or safety posture? | | | | |
| 16 | Governance and compliance | Do you support audit rights, and in what form (report, questionnaire, on-site)? | | | | |
| 17 | Governance and compliance | Have you had an AI-related incident, regulatory inquiry, or litigation? | | | | |
| 18 | Operational resilience | What is your uptime commitment and historical performance? | | | | |
| 19 | Operational resilience | What is your incident notification window for security and AI-behaviour incidents? | | | | |
| 20 | Operational resilience | What is your sub-processor list, and how do you notify changes? | | | | |
| 21 | Operational resilience | What happens to our data and our access on termination? | | | | |
| 22 | Operational resilience | What is your financial position, and who funds you? | | | | |

### Worked example

| # | Domain | Question | Vendor response | Evidence | Assessor note | Flag |
|---|---|---|---|---|---|---|
| 2 | Model and data | Customer data used for training? Opt-out default? | "Not used for training. No opt-out needed." | DPA section 6.2 | Confirmed in contract language | No |
| 4 | Model and data | Evaluations for accuracy, safety, bias, and cadence | "Internal evals each release; third-party red team annually" | Summary memo, no methodology | Ask for methodology and last red-team date | Yes |
| 8 | Security and privacy | Data location, can we pin a region? | "EU or US; region pinning on Enterprise plan" | Trust centre page | Requires the plan tier we are buying, acceptable | No |
| 15 | Governance and compliance | Advance notice of material model changes? | "Changelog published; no advance notice" | Public changelog | Gap. Needs a contractual notice window | Yes |
| 19 | Operational resilience | Incident notification window | "72 hours for security incidents" | MSA draft clause 11 | Want 24h for anything touching our data; negotiate | Yes |
| **Summary** | | | | | 3 flags: eval transparency, change notice, incident window | |

### Acceptance criteria

- Every question has a vendor response and a link or attachment to supporting evidence, or an explicit note that none was provided.
- Each domain has been reviewed by someone competent in that domain (security reviews the security rows, Legal reviews governance rows).
- Every flagged row is carried into the scorecard and, where it needs a contract fix, into the clause checklist.

---

## AI contract clause checklist

_The AI-specific terms to get into the contract. For each, whether it is present, and your fallback if the vendor pushes back._

### Template

| Clause | Why it matters | Present? | Fallback position |
|---|---|---|---|
| Training data use | Stops your data improving the vendor's models by default | Y / N | Contractual opt-out plus deletion on request |
| Change notification | Gives you time to re-test before a model changes under you | Y / N | 30 days notice for material model or safety changes |
| Incident notification | Sets a clock on being told about a breach or harmful behaviour | Y / N | 24 hours for anything involving your data |
| Audit rights | Lets you verify claims rather than take them on trust | Y / N | Annual questionnaire plus right to a third-party report |
| Sub-processor control | Controls who else touches your data | Y / N | List plus notice and objection right for changes |
| Liability and indemnity for AI outputs | Allocates risk for IP claims and harmful outputs | Y / N | Carve-out from the general liability cap for IP infringement |
| Data return and deletion on exit | Prevents lock-in and lingering copies | Y / N | Return in a usable format within 30 days, certified deletion |
| Regulatory cooperation | Vendor helps you meet your own obligations | Y / N | Reasonable assistance with FRIA, DPIA, and regulator requests |

### Worked example

| Clause | Present in draft? | Note |
|---|---|---|
| Training data use | Y | DPA 6.2, acceptable as written |
| Change notification | N | Add: 30 days for material changes. Vendor initially offered changelog only |
| Incident notification | Partial | Draft says 72h; redlined to 24h for data-involving incidents |
| Audit rights | Y | Annual questionnaire plus SOC 2 report, acceptable |
| Sub-processor control | Y | List provided; added 15-day objection window |
| Liability for AI outputs | N | Legal adding IP indemnity carve-out from the cap |
| Data return and deletion | Y | 30 days, certified deletion |
| Regulatory cooperation | N | Add: assistance with FRIA and regulator queries |
| **Status** | | 4 of 8 need redlines; sent to vendor counsel 2026-09-03 |

### Acceptance criteria

- Every clause is marked present, partial, or absent against the actual contract draft, not the vendor's marketing.
- Absent or partial clauses have a redline in progress with an owner, or a documented, approved decision to accept the gap.
- The fallback positions are agreed with Legal before negotiation starts, so the reviewer is not improvising.

---

## Vendor risk scorecard

_Rolls the questionnaire into a single rating. Weight the dimensions to your context, score each 1 (poor) to 5 (strong), and read off the total._

### Template

| Dimension | Weight | Score (1-5) | Weighted | Notes |
|---|---|---|---|---|
| Model and data transparency | 0.25 | | | |
| Security and privacy posture | 0.25 | | | |
| Governance and regulatory readiness | 0.20 | | | |
| Operational resilience | 0.15 | | | |
| Contractual protections achievable | 0.15 | | | |
| **Total** | 1.00 | | | |

**Rating:** 4.0 and above is Low risk. 3.0 to 3.9 is Moderate, proceed with the flagged items tracked. 2.0 to 2.9 is High, needs governance sign-off and a remediation plan. Below 2.0 is Do not proceed.

### Worked example

| Dimension | Weight | Score | Weighted | Notes |
|---|---|---|---|---|
| Model and data transparency | 0.25 | 3 | 0.75 | Eval methodology not shared |
| Security and privacy posture | 0.25 | 4 | 1.00 | SOC 2 Type II, ISO 27001, region pinning |
| Governance and regulatory readiness | 0.20 | 3 | 0.60 | Named owner, but no advance change notice |
| Operational resilience | 0.15 | 4 | 0.60 | 99.9% uptime, sub-processor list provided |
| Contractual protections achievable | 0.15 | 3 | 0.45 | 4 redlines outstanding, vendor engaging |
| **Total** | 1.00 | | **3.40** | Moderate. Proceed with the 3 flags and 4 redlines tracked to closure |

### Acceptance criteria

- The weights are set for your risk context before scoring, not adjusted afterwards to reach a preferred rating.
- Each score has a one-line justification tied to questionnaire evidence.
- A Moderate or worse rating has a named approver and a remediation plan with dates before the vendor is onboarded.

---

## Model / system card request

_What to ask the vendor to provide when they have no published card. Send it as a template so the response is comparable across vendors._

### Template

> Ask the vendor to complete and return. Chase the gaps.

- **Model name and version:**
- **Provider, and any sub-processed models:**
- **Intended use and out-of-scope use:**
- **Training data:** sources, cut-off date, languages, known gaps
- **Evaluation results:** benchmarks, safety testing, bias testing, with dates
- **Known limitations and failure modes:**
- **Guardrails:** content filtering, refusal behaviour, jailbreak resistance testing
- **Update and deprecation policy:** cadence, notice, support window
- **Data handling:** retention of prompts and outputs, training use, region
- **Contact for security and AI-behaviour issues:**

### Worked example

- **Model name and version:** VendorLM-4, served build 2026-07
- **Provider:** first-party; embeddings sub-processed to a named third party
- **Intended use:** support and knowledge tasks. Out of scope: legal, medical, or financial advice
- **Training data:** licensed and public web to 2026-01; weak coverage of non-European languages
- **Evaluation results:** internal accuracy suite each release; annual external red team, last completed 2026-05; bias testing on a standard benchmark, results shared on request
- **Known limitations:** cites plausible but wrong sources under ambiguity; degrades on inputs over 50k tokens
- **Guardrails:** content filter on by default; jailbreak testing part of the red team
- **Update policy:** roughly quarterly; changelog only, no advance notice today
- **Data handling:** prompts and outputs retained 30 days for abuse monitoring; not used for training; EU or US region
- **Contact:** security@vendor.example, ai-safety@vendor.example

### Acceptance criteria

- The vendor returned the template, and every field is answered or explicitly marked unavailable.
- Evaluation and testing claims carry dates, so you can tell whether they are current.
- The completed card is attached to the due diligence record and refreshed at each renewal.

---

## Governance controls this kit produces evidence for

- **PRC-001**: The completed questionnaire and scorecard are the due diligence record for the vendor, with a rating and a rationale.
- **PRC-002**: The clause checklist evidences which AI-specific contractual protections were sought and secured, and the approved position on any gaps.
- **PRC-003**: The model card request and the model-and-data questionnaire section document the third-party model evaluation.
- **PRC-004**: The incident-notification questionnaire rows and clause checklist set and record the vendor incident notification window.
- **PRC-005**: The scorecard is the procurement-stage AI risk assessment, weighted and rated before onboarding.
- **PRC-007**: The change-notification question and clause create the hook for ongoing vendor governance-change monitoring after onboarding.
