AIPolicyTracker
ChecklistFree · no accountEU AI ActISO/IEC 42001NIST AI RMF

AI Vendor Due-Diligence Questionnaire

Questions to put to an AI vendor, grouped by governance, data, model, security, transparency, incidents, and insurance and indemnity, scored automatically.

Formats: XLSX and DOCX · Version v1 · Built from dataset 914895c3103e · CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.

What's inside

  • Questionnaire sheet: seven sections, response dropdowns, evidence requested, weighted score
  • Insurance and indemnity section: cover, AI exclusions, IP indemnity, sub-processor flow-down, audit rights
  • Duties sheet: the vendor-governance duties on record that the questions serve

Preview

The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.

Sheet: Questionnaire · 7 columns · 20 rows from the records
First rows of the Questionnaire sheet
#SectionQuestionEvidence requestedResponse ▾Score ƒVendor notes / our assessment
1GovernanceDo you maintain an AI governance policy with named accountable roles?Policy document; org chart=
2GovernanceIs your AI management system certified or assessed against ISO/IEC 42001 or an equivalent?Certificate or assessment report=
3GovernanceWhich AI laws and regulations do you consider yourself subject to, and in what role?Written statement=
4DataWhat data was used to train, tune and evaluate the model, and what rights do you hold to it?Data provenance summary=
5DataDo you process our data to train or improve models? Can we opt out contractually?Contract terms=
6DataWhere is data stored and processed, and which sub-processors are involved?Sub-processor list=

Total score: sum the Score column; the maximum is twice the number of applicable questions.

Sheet: Vendor-governance duties · 14 columns · 3 rows from the records
First rows of the Vendor-governance duties sheet
DutyCategoryInstrumentJurisdictionWho it bindsNatureSource referenceApplies fromWhat it requiresEvidence a reviewer expectsISO/IEC 42001NIST AI RMFVerificationRecord
Provide contestability, supply-chain transparency and records (guardrails 7 to 9)Vendor and supply-chain governanceAustralian Voluntary AI Safety StandardAustraliaDeployer / user organisation, Provider / developerVoluntaryGuardrails 7, 8 and 9Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, modelAI system register and supplier disclosuresGOVERN 6.xSource-linkedhttps://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records
Verify conformity before importing or distributing high-risk AIVendor and supply-chain governanceEU AI ActEuropean UnionImporter, DistributorLegal requirementArticles 23 and 242026-08-02Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised represeSupplier due-diligence checklistAnnex A controls on third parties and suppliersGOVERN 6.1, GOVERN 6.2Source-linkedhttps://aipolicytracker.org/obligations/eu-ai-act-importer-distributor-obligations
Providers of high-risk AI must have written agreements with suppliers of components, tools and servicesVendor and supply-chain governanceEU AI ActEuropean UnionProvider / developerLegal requirementArticle 25(4)2026-08-02A provider of a high-risk AI system and any third party that supplies AI systems, tools, services, components or processes used in or integrated into it must seSupplier agreement with AI Act information and access clauses; Supplier register with agreement statusAnnex A.10.3GOVERN 6.1Verified against the official source 26 Sep 2026https://aipolicytracker.org/obligations/eu-ai-act-art-25-4-written-agreements-with-component-suppliers

Document outline (DOCX)

  1. How to use this questionnaire
  2. Insurance and indemnity
  3. Duties this questionnaire serves
  4. Provide contestability, supply-chain transparency and records (guardrails 7 to 9)
  5. Verify conformity before importing or distributing high-risk AI
  6. Providers of high-risk AI must have written agreements with suppliers of components, tools and services

Duties this template covers (3)

Each is cited in the file with its source reference and a link back to the record.

Legal basis

Version history

Versions of AI Vendor Due-Diligence Questionnaire
VersionBuiltDatasetWhat changed
v1914895c3103eFirst version, built from dataset 914895c3103e.

Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.

Frequently asked questions

Is the AI Vendor Due-Diligence Questionnaire free?
Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 6 recorded duties are cited in it, drawn from 2 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.

Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.

Frequently asked questions

Is the AI Vendor Due-Diligence Questionnaire free?
Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
What is it generated from?
Version v1 was built on 26 September 2026 from dataset 914895c3103e: 6 recorded duties are cited in it, drawn from 2 instruments. Every row that cites a duty links to the record, and the record links to the official source.
How will I know when it changes?
The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
Does completing it make us compliant?
No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.