AI vendor due diligence: ask for artefacts, not assurances.

Describe what you are buying and what it will touch. The tool sets a risk tier, then asks the supplier for 20 to 38 artefacts (model card, AIBOM, eval and red-team reports, incident SLA, training-content summary, copyright policy, sub-processors), each mapped to the crosswalk, plus the contract clauses to check.

Indicative, not legal advice and not a conformity claim. Nothing you enter leaves your browser.

JavaScript is off or has not loaded, so the live result and the exports are not available. The questions, the criteria and the guide below still work as a worksheet you can read and fill in by hand.

Built from 15. Governing deployment of the Body of Knowledge. Runs entirely in this page: no account and no upload.

Supplier and product

These names appear in the request, the file names and the link you copy.

What are you buying?

The route decides what you can test and what you must collect.

What does the use decide?

The use, not the product, sets the obligations.

The most sensitive data the supplier will see

Prompts, files, logs and anything a connector can read.

Autonomy and tool access

What the product or its agent can do in your systems.

Where it will be used, and your sector

Tick every jurisdiction of use; the sector flags add the questions their regimes make relevant.

If any of these is true

How the request is built

When you do not own the model, the due-diligence gate is what replaces the red team you cannot run [1]. The less of the model you own, the more of your control budget moves from testing it to bounding it and evidencing the supplier [2]. So every request asks for an artefact you can file against the registry entry, and whatever the supplier cannot provide is recorded as unverified and compensated by bounding the integration: least-privilege scopes, boundary evals and tighter observation of the traffic you control.

The tier rule

The tier is the highest reading across four dimensions: what the use decides, the most sensitive data the supplier will see, the autonomy and tool access it gets, and the regulatory context. Two or more high readings make it critical. This rule is the tool's own and illustrative; write your own thresholds into your third-party AI policy.

What each answer reads as
Dimension Answer Reads
Use Internal productivity; no decisions about people low
Use Customer-facing: people outside the organisation read or use its output medium
Use It decides, or recommends a decision, about people (hiring, credit, benefits, access to services) high
Use Safety component of a regulated product, or critical infrastructure operation critical
Data Public information only low
Data Internal, non-personal information low
Data Confidential business information or trade secrets medium
Data Personal data medium
Data Special-category or otherwise regulated data (health, biometrics, financial) high
Autonomy and tool access Answers only: no access to your systems low
Autonomy and tool access Reads your systems or data through tools or connectors medium
Autonomy and tool access Writes to your systems of record (creates, changes or deletes) high
Autonomy and tool access Acts outside: sends messages, makes payments, publishes high
Regulatory context A financial entity under DORA, or an essential or important entity under NIS2 medium

The question bank

38 requests in this site's own words. Each one is cross-referenced to topics of the crosswalk [4] and to CSA AICM control ids [5] only, so a supplier can answer from the control evidence it already keeps. The tool asks all of them, or the subset the tier and the facts call for; without JavaScript, use the list as a worksheet and skip what clearly does not apply.

Role and scope

  • VDD-01. State your role for this product under the EU AI Act (provider, GPAI model provider, component supplier or reseller), and send the document in which you record that decision.

    Artefact: Role statement per product.

    Crosswalk: Governance and accountability ; Supply chain and third parties · CSA AICM: GRC-06 Governance Responsibility Model

  • VDD-02. Send your own risk classification of the product under the EU AI Act, with the intended purposes it covers and the reasoning behind it.

    Artefact: Classification record.

    Crosswalk: Risk management ; Conformity assessment and certification · CSA AICM: GRC-02 Risk Management Program

  • VDD-03. List every model inside the product (name, version, provider), upstream foundation models included, and explain how you tell us when one of them changes.

    Artefact: Model inventory for the product.

    Crosswalk: Supply chain and third parties ; Inventory and registration · CSA AICM: STA-08 Supply Chain Inventory; STA-10 Supply Chain Risk Management

Documentation

  • VDD-04. Send the model or system card for the version we will use: intended use, known limitations and failure modes, and evaluation results.

    Artefact: Model or system card.

    Crosswalk: Documentation and transparency · CSA AICM: MDS-03 Model Documentation; MDS-04 Model Documentation Requirements

  • VDD-05. Send the instructions for use: the human-oversight measures, the input data the system expects, and the metrics and thresholds a deployer should monitor.

    Artefact: Instructions for use.

    Crosswalk: Documentation and transparency ; Human oversight · CSA AICM: MDS-04 Model Documentation Requirements; GRC-15 Human supervision

  • VDD-06. Send an AI bill of materials (for example a CycloneDX ML-BOM or an SPDX AI profile) naming the models, datasets and libraries in the product and their licences, or say that none exists.

    Artefact: AIBOM.

    Crosswalk: Supply chain and third parties ; Inventory and registration · CSA AICM: STA-09 Service Bill of Material (BOM)

  • VDD-07. Send the documentation you give downstream providers about the model: capabilities, limitations and what an integrator needs to know.

    Artefact: Downstream-provider documentation.

    Crosswalk: GPAI and foundation models ; Documentation and transparency · CSA AICM: MDS-03 Model Documentation

Data

  • VDD-08. Confirm in writing whether our inputs, outputs, files or logs train or improve any model, what the default setting is, and how we can read that setting back.

    Artefact: Written no-training commitment and the setting.

    Crosswalk: Privacy and data protection ; Data governance · CSA AICM: DSP-08 Data Privacy by Design and Default

  • VDD-09. State the retention period for prompts, outputs, files and logs, per data type and including any abuse-monitoring copies, and send a sample deletion confirmation.

    Artefact: Retention schedule and deletion confirmation.

    Crosswalk: Privacy and data protection · CSA AICM: DSP-02 Secure Disposal

  • VDD-10. Send the current list of sub-processors (hosting, model providers, labelling, support), where it is published, and how you notify changes to it.

    Artefact: Dated sub-processor list.

    Crosswalk: Supply chain and third parties ; Privacy and data protection · CSA AICM: STA-10 Supply Chain Risk Management

  • VDD-11. State where inference, storage and support access take place, and the transfer mechanism for any personal data that leaves the region.

    Artefact: Processing locations and transfer mechanism.

    Crosswalk: Privacy and data protection · CSA AICM: DSP-08 Data Privacy by Design and Default

  • VDD-12. Send the public summary of the content used to train the model.

    Artefact: Training-content summary.

    Crosswalk: GPAI and foundation models ; Data governance ; IP and copyright · CSA AICM: DSP-20 Data Provenance and Transparency

  • VDD-13. Send your copyright policy for the model, including how you identify and respect rights reservations over the content you train on.

    Artefact: Copyright policy.

    Crosswalk: IP and copyright ; GPAI and foundation models · CSA AICM: DSP-20 Data Provenance and Transparency

  • VDD-14. Send the data card or datasheet for the training and evaluation data you can disclose: sources, licences, collection period, known gaps, and the checks for poisoned or unlawful content.

    Artefact: Data card.

    Crosswalk: Data governance · CSA AICM: DSP-20 Data Provenance and Transparency; DSP-21 Data Poisoning Prevention & Detection

Evaluation and security

  • VDD-15. Send the evaluation reports for tasks like ours: method, datasets, metrics, results, date and the model version tested.

    Artefact: Evaluation reports.

    Crosswalk: Robustness, security and evaluations · CSA AICM: AIS-05 Application Security Testing

  • VDD-16. Send a summary of the latest red-team or adversarial testing: scope, who ran it and how independent they were, findings by severity, and what was fixed.

    Artefact: Red-team summary.

    Crosswalk: Robustness, security and evaluations · CSA AICM: MDS-06 Adversarial Attack Analysis; MDS-07 Robustness against Adversarial Attack / Model Hardening

  • VDD-17. Send the bias and fairness testing you have run for uses like ours: groups, metrics, results, and your commitment to remediate what testing finds.

    Artefact: Bias testing report.

    Crosswalk: Fairness and non-discrimination · CSA AICM: GRC-11 Bias and Fairness Assessment

  • VDD-18. Send your security certificates with their scope statements, showing whether the AI service is in scope, and the date of the last independent penetration test.

    Artefact: Certificates with scope; test date.

    Crosswalk: Conformity assessment and certification ; Robustness, security and evaluations · CSA AICM: A&A-02 Independent Assessments

  • VDD-19. Describe the input and output controls in the service (prompt-injection defences, output filtering), which of them we can configure, and the events they log.

    Artefact: Guardrail description and event log sample.

    Crosswalk: Runtime guardrails · CSA AICM: TVM-13 Guardrails; AIS-09 Input Validation; AIS-10 Output Validation

  • VDD-20. Confirm that we may run our own boundary evaluations and agreed red-team windows against the service, and under what conditions.

    Artefact: Testing permission in writing.

    Crosswalk: Robustness, security and evaluations · CSA AICM: AIS-05 Application Security Testing

  • VDD-21. Send the independent audit or assurance reports you share with customers, and how often they are renewed.

    Artefact: Audit reports and cadence.

    Crosswalk: Conformity assessment and certification · CSA AICM: A&A-02 Independent Assessments; A&A-04 Requirements Compliance

Incidents and change

  • VDD-22. State, in hours, the window within which you notify us of security incidents, personal-data breaches and serious model failures, the channel you use, and send a sample notice.

    Artefact: Incident-notice SLA in hours.

    Crosswalk: Incident response and monitoring · CSA AICM: SEF-07 Incident Management and Response; SEF-08 Security Breach Notification

  • VDD-23. Explain how you support our own reporting clocks: which facts you give us about an incident, how fast, and a named contact for regulator enquiries.

    Artefact: Incident cooperation procedure.

    Crosswalk: Incident response and monitoring · CSA AICM: SEF-07 Incident Management and Response

  • VDD-24. State the notice, in days, you give before a material change (model version updates and deprecations included), and whether we can pin a version.

    Artefact: Change and deprecation terms.

    Crosswalk: Deployment, change and decommissioning · CSA AICM: CCC-01 Change Management Policy and Procedures

  • VDD-25. State which logs we receive or can export (inputs, outputs, tool calls, timestamps, model version), in what format, and for how long.

    Artefact: Log export description and sample.

    Crosswalk: Logging and traceability · CSA AICM: LOG-09 Log Records; LOG-12 Transaction/Activity Logging

  • VDD-26. Describe the features that let our staff review, override or stop an output or an action of the system.

    Artefact: Oversight features.

    Crosswalk: Human oversight · CSA AICM: GRC-15 Human supervision

  • VDD-27. Describe what explanation of an individual output or decision the service can produce, and in what form.

    Artefact: Explanation capability.

    Crosswalk: Explainability and right to explanation · CSA AICM: GRC-13 Explainability Requirement; GRC-14 Explainability Evaluation

  • VDD-28. Send the version of your acceptable-use policy that will bind us, how you notify changes to it, and confirm that our intended use is permitted.

    Artefact: Acceptable-use policy version.

    Crosswalk: Prohibited practices · CSA AICM: GRC-09 Acceptable Use of the AI Service

  • VDD-29. Send the service levels: availability, latency, rate limits, and what happens on an outage or a forced deprecation.

    Artefact: SLA.

    Crosswalk: Deployment, change and decommissioning

  • VDD-30. Describe how we leave: return of our data (days, format), of fine-tunes, adapters and embeddings, and a deletion certificate afterwards.

    Artefact: Exit terms.

    Crosswalk: Deployment, change and decommissioning · CSA AICM: DSP-02 Secure Disposal

Agents and tool access

  • VDD-31. List the identities, permissions and scopes the product's agent or integration needs in our systems, their lifetime, and whether it acts under its own identity or under a user's delegated token.

    Artefact: Identity and scope list.

    Crosswalk: Agent identity and autonomy · CSA AICM: IAM-18 Agent Access Restriction; IAM-12 Unique Identities; AIS-11 Agents Security Boundaries

  • VDD-32. List the tools and MCP servers the agent can call, with publisher, version and a hash of each tool's definition, and how you notify a change to a definition.

    Artefact: Tool and MCP server manifest.

    Crosswalk: Agent identity and autonomy ; Supply chain and third parties · CSA AICM: AIS-11 Agents Security Boundaries; STA-09 Service Bill of Material (BOM)

  • VDD-33. Describe how our staff approve irreversible actions, how we suspend the agent or stop sending it traffic, and how long a stop takes.

    Artefact: Approval and suspension procedure.

    Crosswalk: Human oversight ; Agent identity and autonomy · CSA AICM: GRC-15 Human supervision; IAM-18 Agent Access Restriction

  • VDD-34. Send a sample trace of one agent task: the plan, each tool call with its parameters, any approval, and the result.

    Artefact: Sample agent trace.

    Crosswalk: Logging and traceability ; Agent identity and autonomy · CSA AICM: LOG-12 Transaction/Activity Logging

Open weights

  • VDD-35. State the model's licence (family and version), the acceptable-use policy it incorporates, any scale threshold and any attribution or naming duty.

    Artefact: Licence and AUP versions.

    Crosswalk: IP and copyright ; Supply chain and third parties · CSA AICM: STA-10 Supply Chain Risk Management

  • VDD-36. Send the file hashes or signatures of the weight files and name their serialisation format.

    Artefact: Weight hashes or signatures.

    Crosswalk: Supply chain and third parties ; Content provenance and deepfakes · CSA AICM: MDS-09 Model Signing/Ownership Verification

Risk transfer

  • VDD-37. Send the IP indemnity terms with their conditions and exclusions, and the liability cap with its carve-outs.

    Artefact: Indemnity and liability terms.

    Crosswalk: IP and copyright ; Governance and accountability

  • VDD-38. Send certificates of insurance showing cover for AI-related claims, with limits.

    Artefact: Certificates of insurance.

    Crosswalk: Governance and accountability

The contract clauses

The clause checklist comes from the contracts page [3]: the tool lists the clauses the tier and the facts make relevant, each with its red flag, a fallback position and the evidence to keep. A clause that matters at runtime must become a check (the no-training setting read back, the version pin held in the registry); a clause nothing checks is a hope [2].

The response record

Once the answers are in, the tool writes a record for the vendor-due-diligence-response.v1 schema [6]: the supplier's answers, the requests still open, and your decision with its conditions, reviewer and reassessment date. Re-open the gate on renewal and on every material change notice.

What this is not

Not legal advice and not a conformity claim. The questions are this site's, not a copy of any published questionnaire; the crosswalk and AICM mappings are illustrative, not a claim of conformity, and the contract checklist names what to look for, while the legal reading of a contract stays with counsel. The tier rule is the tool's own: write your thresholds into your third-party AI policy.

Terms used here

Sources

  1. [1] Vendor / Model Due-Diligence Gate (pattern: gate procured and API-only AI on a structured assessment; record what you can and cannot verify; re-open on renewal or material change). AI Governance Engineering Body of Knowledge. 2026-09-24. https://aigovernanceengineer.com/patterns/vendor-model-due-diligence-gate (verified: primary)
  2. [2] 15. Governing deployment: "Build, buy or adapt" (three routes, three evidence burdens), "Vendor contracts and licence terms" and "Monitoring third parties while you run". AI Governance Engineering Body of Knowledge. 2026-09-24. https://aigovernanceengineer.com/bok/governing-deployment#vendor-contracts-and-licence-terms (verified: primary)
  3. [3] Contracts and licences: the AI vendor contract clause checklist (red flag, fallback, evidence) and the licence families of open-weight models; an engineering checklist, not legal advice. AI Governance Engineer. 2026-09-24. https://aigovernanceengineer.com/resources/contracts (verified: primary)
  4. [4] Topic crosswalk v2 (25 topics across the EU AI Act, ISO/IEC, NIST AI RMF, CSA AICM and other instruments; the CSA AICM control ids each topic maps to). AI Governance Engineer. 2026-09-24. https://aigovernanceengineer.com/resources/crosswalk (verified: primary)
  5. [5] CSA AI Controls Matrix (AICM) v1.1 (control objectives across 18 domains; cited here by control id and short title only). Cloud Security Alliance. 2026-06-22. https://cloudsecurityalliance.org/artifacts/ai-controls-matrix-v1-1 (verified: secondary)
  6. [6] Vendor due-diligence response, JSON Schema v1 (supplier answers keyed to the obligations they help evidence, plus the buyer's assessment and reassessment date). AI Governance Engineer templates and schemas library. 2026-09-24. https://aigovernanceengineer.com/schemas/vendor-due-diligence-response.v1.json (verified: primary)