For Heads-of · Practitioner

AI Vendor Due Diligence Questionnaire

An assessor's questionnaire built on what the EU AI Act already obliges a provider to hold, covering Article 25 on the value chain and the Annex XII documentation duty in force since August 2025, instead of a security questionnaire with "AI" added to the headings.

  • third-party risk
  • eu-ai-act
  • due diligence
  • procurement
  • supply chain

Why this tool exists

Answer the two questions that decide whether AI third-party risk work is real. What does the organisation actually depend on, beneath the vendor named on the invoice. And is the organisation a deployer, or has it become a provider without noticing. The questionnaire asks for named regulatory documents rather than general descriptions, because a named request asks for something the provider is already required to hold.

How it's used

Used when assessing a new AI supplier, when re-assessing an existing one after a model change, and when a procurement team needs contract terms that reflect the AI-specific risks. Completed per system rather than per vendor, since the same supplier in two deployments is two assessments.

What you get

Nine sections across 11 pages: system identification, an Article 25 deployer-or-provider determination, a dependency chain map, an Annex XII documentation checklist, data and training questions, change and version management, security and incidents, concentration and exit with ten contract clauses to confirm, and an assessment outcome with a review cadence.

The determination it starts with

Under Article 25, putting your name on a system, modifying it substantially, or changing its intended purpose can make you its provider, taking on the provider's obligations in full. All three are ordinary commercial acts. Section 2 is an internal determination completed before the commercial conversation, because it changes what you are negotiating for.

What you are entitled to ask for

Since 2 August 2025, providers of general-purpose AI models must maintain documentation for downstream providers integrating the model, meeting Annex XII. Section 4 lists all eleven items so you can request them by name. A general question invites a marketing paragraph. A named request asks for a document that should already exist.

The four questions a security questionnaire never asks

What model is underneath this and how will we be told when it changes. What happens to our data in relation to training, at every layer. Can you provide the Annex XII documentation. And if you disappeared in ninety days, what would we do.

On a non-response

A vendor who cannot produce Annex XII documentation, name the model beneath their product, or commit to a change notice period has given you a finding rather than an inconvenience. A documented gap you accepted is a defensible position. An unasked question is not.

Further reading

See the companion article, Third-Party AI Risk, the third-party governance hub, and the third-party risk glossary entry.

Available formats

Downloads route through a short-lived signed link.

DOCX · v1.0 · 18 KB

AI vendor due diligence questionnaire (Word)

Member access

Sign in to download

Framework and clause references

FrameworkClauseTitle
EU AI ActArticle 53Obligations for providers of general-purpose AI models
ISO/IEC 42001:2023Annex A.10Third-party and customer relationships
EU AI ActArticle 25Responsibilities along the AI value chain