# Vendor and third-party AI due diligence

- **Record type**: Control
- **Kind**: Process
- **Owner**: Procurement or vendor risk lead
- **Frequency**: Once per AI system
- **Duties served**: 6

## What the control achieves

Checks, before an external model, dataset, component or AI service is adopted or resold, that the supplier has met its own duties and that the organisation understands what it is taking on.

## How it is typically implemented

Procurement and onboarding include an AI questionnaire and evidence request tailored to the supplier's role: documentation and test results for a model, provenance for a dataset, conformity evidence and markings for a regulated system, security posture for a hosted service. Reviewers verify the answers against the organisation's minimum requirements, record findings and residual risks and decide whether to proceed, proceed with conditions or decline. Importers and distributors confirm the upstream party's paperwork is complete before the product moves. Supplier entries in the AI register are re-assessed at renewal and when the supplier reports a material change.

## Evidence it produces

- AI supplier due-diligence assessment (supplier_assessment): Completed questionnaire, evidence review and decision for one supplier or component.
- AI supplier and component register (register_entry)
- Supplier onboarding decision (approval_record)

## Legal duties this control serves

- Verify conformity before importing or distributing high-risk AI — EU AI Act, European Union (satisfies): https://aipolicytracker.org/obligations/eu-ai-act-importer-distributor-obligations
- Providers of high-risk AI must have written agreements with suppliers of components, tools and services — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-25-4-written-agreements-with-component-suppliers
- Public authorities must register their use of high-risk AI and must not use unregistered systems — EU AI Act, European Union (supports): https://aipolicytracker.org/obligations/eu-ai-act-art-26-8-public-authority-registration-before-use
- Employers and employment agencies must obtain an independent bias audit before using an automated employment decision tool — NYC Local Law 144 (automated employment decision tools), New York (United States) (supports): https://aipolicytracker.org/obligations/us-new-york-city-local-law-144-bias-audit
- Establish AI governance policies, roles and accountability (Govern) — NIST AI RMF, United States (supports): https://aipolicytracker.org/obligations/us-nist-ai-rmf-govern
- Prioritise, respond to and monitor AI risks (Manage) — NIST AI RMF, United States (supports): https://aipolicytracker.org/obligations/us-nist-ai-rmf-manage

## Standards clauses it corresponds to (clause numbers only)

- ISO/IEC 42001:2023: Annex A.10.2, A.10.3
- NIST AI RMF 1.0: GOVERN 6.1, 6.2; MAP 4.1, 4.2; MANAGE 3.1
- ISO/IEC 27001:2022: Annex A 5.19 to 5.22 Supplier relationships
- OWASP Top 10 for LLM Applications: LLM03 Supply Chain

## MIT AI Risk Repository subdomains addressed

6.5, 2.2, 7.3

## Provenance

- **Record page**: https://aipolicytracker.org/controls/third-party-ai-due-diligence
- **Official source**: none recorded — this record is incomplete, see https://aipolicytracker.org/gaps
- **Review status**: pending review
- **Confidence**: high
- **Facts last confirmed**: never confirmed against the official source
- **Retrieved**: 2026-09-24
- **Licence**: https://creativecommons.org/licenses/by/4.0/

> This record is a structured summary with a link to the official text. It is not legal advice. Open the official source before relying on any date or duty. How current each record type must be is published at https://aipolicytracker.org/verification; what a record must carry at all is published at https://aipolicytracker.org/coverage.
