Vendor and third-party AI due diligence
Checks, before an external model, dataset, component or AI service is adopted or resold, that the supplier has met its own duties and that the organisation understands what it is taking on.
- Duties satisfied
- 1
- done properly, does the work
- Duties supported
- 5
- contributes; the duty needs more
- Jurisdictions
- 3
- Evidence items
- 3
How is it implemented?
Procurement and onboarding include an AI questionnaire and evidence request tailored to the supplier's role: documentation and test results for a model, provenance for a dataset, conformity evidence and markings for a regulated system, security posture for a hosted service. Reviewers verify the answers against the organisation's minimum requirements, record findings and residual risks and decide whether to proceed, proceed with conditions or decline. Importers and distributors confirm the upstream party's paperwork is complete before the product moves. Supplier entries in the AI register are re-assessed at renewal and when the supplier reports a material change.
Which legal duties does it serve?
Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.
European Union 3 duties
-
satisfies Legal requirement confidence highVerify conformity before importing or distributing high-risk AI
EU AI Act · Articles 23 and 24 · applies from 2 Aug 2026
Onboarding verifies the provider's conformity assessment, documentation, marking and representative.
-
supports Legal requirementProviders of high-risk AI must have written agreements with suppliers of components, tools and services
EU AI Act · Article 25(4) · applies from 2 Aug 2026
Identifies which suppliers fall within Article 25(4).
-
supports Legal requirementPublic authorities must register their use of high-risk AI and must not use unregistered systems
EU AI Act · Article 26(8); Article 49(3) and 49(4) · applies from 2 Aug 2026
Verifies the provider's registration before purchase.
New York (United States) 1 duty
-
supports Legal requirementEmployers and employment agencies must obtain an independent bias audit before using an automated employment decision tool
NYC Local Law 144 (automated employment decision tools) · NYC Administrative Code Section 20-871(a)(1); 6 RCNY Section 5-301 · applies from 5 Jul 2023
Vendor supplies data and audit access for the tool.
United States 2 duties
-
supports Voluntary confidence highEstablish AI governance policies, roles and accountability (Govern)
NIST AI RMF · GOVERN function
Third-party risk management outcomes.
-
supports VoluntaryPrioritise, respond to and monitor AI risks (Manage)
NIST AI RMF · MANAGE function
Third-party risk management outcomes.
What evidence shows it is operating?
| Evidence | Type | What it shows |
|---|---|---|
| AI supplier due-diligence assessment | Supplier assessment | Completed questionnaire, evidence review and decision for one supplier or component. |
| AI supplier and component register | Register entry | |
| Supplier onboarding decision | Approval or sign-off record |
Owner: Procurement or vendor risk lead. Frequency: once per ai system.
Which risks does it address?
Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.
- 6.5 Governance failure Socioeconomic & Environmental3 incidents · 61 risk entries
- 2.2 AI system security vulnerabilities and attacks Privacy & Security24 incidents · 112 risk entries
- 7.3 Lack of capability or robustness AI system safety, failures, & limitations305 incidents · 126 risk entries
Which standards clauses does it correspond to?
Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.
| Framework | Reference | Note | Confidence |
|---|---|---|---|
| ISO/IEC 42001 | Annex A.10.2, A.10.3 | high | |
| NIST AI RMF | GOVERN 6.1, 6.2; MAP 4.1, 4.2; MANAGE 3.1 | high | |
| ISO/IEC 27001 | Annex A 5.19 to 5.22 Supplier relationships | medium | |
| OWASP LLM Top 10 | LLM03 Supply Chain | high |
Cite this record
AIPolicyTracker (2026). “Vendor and third-party AI due diligence”. https://aipolicytracker.org/controls/third-party-ai-due-diligence (accessed 24 September 2026). Data licensed CC BY 4.0.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Which legal duties does "Vendor and third-party AI due diligence" satisfy?
- It is recorded as satisfying 1 and supporting 5 duties across European Union, New York (United States) and United States. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
- What evidence shows this control is operating?
- AI supplier due-diligence assessment, AI supplier and component register and Supplier onboarding decision. Owner: Procurement or vendor risk lead. Frequency: once per ai system.