Vendor AI Due Diligence Questionnaire
Build a due-diligence questionnaire and evidence-request checklist for an AI vendor from five inputs: vendor role, sector, data classes, AI use case, and operating jurisdictions. Questions are grouped by governance, data, testing, transparency, incident, and contractual evidence, and each statutory question carries a primary-source citation with a retrieval date.
Last verified: 2026-07-23
The role the vendor plays in the deployment determines which statutory duties sit with the vendor and which stay with the acquiring organization.
Select every jurisdiction where the system will touch consumers, candidates, or employees — not only where the organization is headquartered.
How the questionnaire is assembled
From vendor facts to an auditable evidence file
The generator does not produce a fixed template. Each input narrows or widens the question set, because the duties that attach to an AI deployment are allocated by role, use case, and operating footprint rather than by product category.
1. Scope the vendor
Vendor role decides who carries developer-side documentation duties and who carries deployer-side notice and review duties. A model provider, an application vendor, and an integrator produce materially different question sets.
2. Declare data and use case
Data classes and AI use case drive the sector and statutory questions — biometric capture, training-data transparency, consequential decisions, and generative-content provenance each add their own evidence requests.
3. Select operating jurisdictions
State duties attach where the system touches consumers, candidates, or employees, not where the acquiring organization is incorporated. Selecting the full operating footprint prevents a jurisdiction-shaped gap in the evidence file.
4. Send and record
Each question ships with the artifact to request, so responses can be logged with evidence received and a residual-risk rating. The Markdown export carries response and evidence fields for exactly that purpose.
Run the compliance checker first if the applicable laws have not been established yet, then use the impact assessment generator once a vendor is selected and the deployment needs its own assessment record. For sector context, the insurance AI compliance hub and the financial services hub set out the instruments behind the sector-specific questions.
FAQ
Vendor AI due diligence questions
What is an AI vendor due diligence questionnaire?
It is a structured set of questions an acquiring organization sends to an AI vendor before or during procurement, paired with the documentary evidence each answer should be backed by. Unlike a generic security questionnaire, it covers model provenance, evaluation and bias testing, disclosure duties, incident reporting, and the contractual flow-down that determines whether the acquiring organization can produce evidence to a regulator.
What should an AI vendor assessment cover for insurance or financial services?
Insurance carriers add the NAIC Model Bulletin AI Systems Program expectations, including third-party AI oversight, and — where the carrier is Colorado-licensed — the ECDIS governance and unfair-discrimination testing duties under Colorado Regulation 10-1-1. Financial services adds specific and accurate adverse-action reasons under the Equal Credit Opportunity Act per CFPB Circular 2022-03, and independent model validation consistent with interagency model risk management guidance.
Does the questionnaire replace a security or privacy assessment?
No. It sits alongside them. Security questionnaires cover infrastructure and access control; privacy assessments cover lawful basis and data subject rights. This tool covers the AI-specific layer — model provenance, evaluation evidence, disclosure mechanics, and AI incident handling — that neither of those instruments reaches.
Are the questions tied to primary sources?
Every question that asserts a legal or standards requirement links to the primary source — the bill text, agency guidance, or standard — with the date that source was retrieved. Questions that are operational diligence rather than a legal requirement are labeled as such and carry no citation, so the distinction stays visible in the exported file.
Does this constitute legal advice?
No. The output is an informational procurement artifact. Statutory scope, effective dates, and enforcement posture change — Colorado in particular was restructured by SB 26-189 in 2026 — so each citation should be confirmed against the current primary source and the completed assessment reviewed with qualified counsel.