Vendor / Model Due-Diligence Gate

Vendor / Model Due-Diligence Gate A workflow diagram generated by Archify. 01 / Provider 02 / Deployer 03 / Layer 02 Inventory & Transparency 04 / Layer 05 Assurance & Continuous Compliance EX / Rejected Submit Assess + gate Register + evidence Vendor package · docs, model card, terms · Provider › Submit Vendor package docs, model card, terms Due-diligence checks · docs, evals, contract · Deployer › Assess + gate Due-diligence checks docs, evals, contract Due-diligence gate · approve / reject · Deployer › Assess + gate · or conditions Due-diligence gate approve / reject or conditions Registry entry · with conditions · Layer 02 Inventory & Transparency › Assess + gate Registry entry with conditions Evidence record · assessment filed · Layer 05 Assurance & Continuous Compliance › Register + evidence · provider-attested flagged Evidence record assessment filed provider-attested flagged Rejected · not deployed · Rejected › Register + evidence Rejected not deployed assess reject submit re-open on change file assessment Legend Agent logic Policy Context / trace External system

A gate for what you do not own

  • • When you cannot red-team the weights, the gate replaces the test you cannot run
  • • Assess evals and red-team evidence, documentation and AIBOM, data flows, tool scopes, incident commitments and the right to audit
  • • Structure it on a versioned template, not an ad-hoc questionnaire

Inventoried and bounded

  • • An approved system enters the registry with an owner, a scope and its conditions
  • • Where a control cannot be verified, record that and bound the integration
  • • Re-open the gate on renewal or a material model change

The limits are explicit

  • • The gate is where deployer duties start; keep the checklist versioned
  • • Reliance on provider-supplied evidence is flagged, not hidden