AIPolicyTracker
Process Owner: Procurement or vendor risk lead Once per AI system

Vendor and third-party AI due diligence

Checks, before an external model, dataset, component or AI service is adopted or resold, that the supplier has met its own duties and that the organisation understands what it is taking on.

Duties satisfied
1
done properly, does the work
Duties supported
5
contributes; the duty needs more
Jurisdictions
3
Evidence items
3

How is it implemented?

Procurement and onboarding include an AI questionnaire and evidence request tailored to the supplier's role: documentation and test results for a model, provenance for a dataset, conformity evidence and markings for a regulated system, security posture for a hosted service. Reviewers verify the answers against the organisation's minimum requirements, record findings and residual risks and decide whether to proceed, proceed with conditions or decline. Importers and distributors confirm the upstream party's paperwork is complete before the product moves. Supplier entries in the AI register are re-assessed at renewal and when the supplier reports a material change.

Which legal duties does it serve?

Satisfies means the control, operated properly, does the work the duty asks for. Supports means it contributes but the duty needs more. The official text decides; open it before relying on either.

European Union 3 duties

New York (United States) 1 duty

United States 2 duties

What evidence shows it is operating?

Evidence this control produces
EvidenceTypeWhat it shows
AI supplier due-diligence assessmentSupplier assessmentCompleted questionnaire, evidence review and decision for one supplier or component.
AI supplier and component registerRegister entry
Supplier onboarding decisionApproval or sign-off record

Owner: Procurement or vendor risk lead. Frequency: once per ai system.

Which risks does it address?

Subdomains of the MIT AI Risk Repository, with the incidents the AI Incident Database has recorded under each. Counts are live; they say how often a risk has materialised, not how well this control prevents it.

Which standards clauses does it correspond to?

Clause numbers only. A reference means the standard asks for overlapping work, so evidence may be reusable; it never means the standard discharges a legal duty.

Framework references
FrameworkReferenceNoteConfidence
ISO/IEC 42001Annex A.10.2, A.10.3high
NIST AI RMFGOVERN 6.1, 6.2; MAP 4.1, 4.2; MANAGE 3.1high
ISO/IEC 27001Annex A 5.19 to 5.22 Supplier relationshipsmedium
OWASP LLM Top 10LLM03 Supply Chainhigh

Cite this record

AIPolicyTracker (2026). “Vendor and third-party AI due diligence”. https://aipolicytracker.org/controls/third-party-ai-due-diligence (accessed 24 September 2026). Data licensed CC BY 4.0.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Which legal duties does "Vendor and third-party AI due diligence" satisfy?
It is recorded as satisfying 1 and supporting 5 duties across European Union, New York (United States) and United States. A mapping means the control, operated properly, does the work the duty asks for; the official text decides whether it is enough.
What evidence shows this control is operating?
AI supplier due-diligence assessment, AI supplier and component register and Supplier onboarding decision. Owner: Procurement or vendor risk lead. Frequency: once per ai system.