ChecklistFree · no accountEU AI ActISO/IEC 42001NIST AI RMF
AI Vendor Due-Diligence Questionnaire
Questions to put to an AI vendor, grouped by governance, data, model, security, transparency, incidents, and insurance and indemnity, scored automatically.
What's inside
- Questionnaire sheet: seven sections, response dropdowns, evidence requested, weighted score
- Insurance and indemnity section: cover, AI exclusions, IP indemnity, sub-processor flow-down, audit rights
- Duties sheet: the vendor-governance duties on record that the questions serve
Preview
The sheets and sections of version v1, as built. Columns marked ▾ have a dropdown; ƒ is a formula.
Sheet: Questionnaire
| # | Section | Question | Evidence requested | Response ▾ | Score ƒ | Vendor notes / our assessment |
|---|---|---|---|---|---|---|
| 1 | Governance | Do you maintain an AI governance policy with named accountable roles? | Policy document; org chart | = | ||
| 2 | Governance | Is your AI management system certified or assessed against ISO/IEC 42001 or an equivalent? | Certificate or assessment report | = | ||
| 3 | Governance | Which AI laws and regulations do you consider yourself subject to, and in what role? | Written statement | = | ||
| 4 | Data | What data was used to train, tune and evaluate the model, and what rights do you hold to it? | Data provenance summary | = | ||
| 5 | Data | Do you process our data to train or improve models? Can we opt out contractually? | Contract terms | = | ||
| 6 | Data | Where is data stored and processed, and which sub-processors are involved? | Sub-processor list | = |
Total score: sum the Score column; the maximum is twice the number of applicable questions.
Sheet: Vendor-governance duties
| Duty | Category | Instrument | Jurisdiction | Who it binds | Nature | Source reference | Applies from | What it requires | Evidence a reviewer expects | ISO/IEC 42001 | NIST AI RMF | Verification | Record |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Provide contestability, supply-chain transparency and records (guardrails 7 to 9) | Vendor and supply-chain governance | Australian Voluntary AI Safety Standard | Australia | Deployer / user organisation, Provider / developer | Voluntary | Guardrails 7, 8 and 9 | Establish processes for people impacted by AI to challenge use or outcomes; be transparent with other organisations across the AI supply chain about data, model | AI system register and supplier disclosures | GOVERN 6.x | Source-linked | https://aipolicytracker.org/obligations/australia-vaiss-contestability-supply-chain-records | ||
| Verify conformity before importing or distributing high-risk AI | Vendor and supply-chain governance | EU AI Act | European Union | Importer, Distributor | Legal requirement | Articles 23 and 24 | 2026-08-02 | Importers must verify that the provider completed conformity assessment, drew up technical documentation, affixed CE marking and appointed an authorised represe | Supplier due-diligence checklist | Annex A controls on third parties and suppliers | GOVERN 6.1, GOVERN 6.2 | Source-linked | https://aipolicytracker.org/obligations/eu-ai-act-importer-distributor-obligations |
| Providers of high-risk AI must have written agreements with suppliers of components, tools and services | Vendor and supply-chain governance | EU AI Act | European Union | Provider / developer | Legal requirement | Article 25(4) | 2026-08-02 | A provider of a high-risk AI system and any third party that supplies AI systems, tools, services, components or processes used in or integrated into it must se | Supplier agreement with AI Act information and access clauses; Supplier register with agreement status | Annex A.10.3 | GOVERN 6.1 | Verified against the official source 26 Sep 2026 | https://aipolicytracker.org/obligations/eu-ai-act-art-25-4-written-agreements-with-component-suppliers |
Document outline (DOCX)
- How to use this questionnaire
- Insurance and indemnity
- Duties this questionnaire serves
- Provide contestability, supply-chain transparency and records (guardrails 7 to 9)
- Verify conformity before importing or distributing high-risk AI
- Providers of high-risk AI must have written agreements with suppliers of components, tools and services
Duties this template covers (3)
Each is cited in the file with its source reference and a link back to the record.
Legal basis
Version history
| Version | Built | Dataset | What changed |
|---|---|---|---|
| v1 | 914895c3103e | First version, built from dataset 914895c3103e. |
Only the latest version is served. A rebuild that changes the content adds a version; a rebuild that does not is skipped.
Frequently asked questions
- Is the AI Vendor Due-Diligence Questionnaire free?
- Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 6 recorded duties are cited in it, drawn from 2 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.
Informational only, not legal advice. Verify every claim against the linked official sources and consult qualified counsel before acting.
Frequently asked questions
- Is the AI Vendor Due-Diligence Questionnaire free?
- Yes. Download the XLSX and DOCX without an account, under CC BY 4.0. You may use, adapt and share this template, including commercially, with attribution to aipolicytracker.org.
- What is it generated from?
- Version v1 was built on 26 September 2026 from dataset 914895c3103e: 6 recorded duties are cited in it, drawn from 2 instruments. Every row that cites a duty links to the record, and the record links to the official source.
- How will I know when it changes?
- The library is rebuilt daily. When a change to the records reaches this template it gets the next version, a changelog in the version history below, an entry in the AI policy updates hub and the templates feed, and a line in the weekly digest for subscribers of the templates topic.
- Does completing it make us compliant?
- No. It is an informational resource, not legal advice; it helps produce the evidence a regulator, customer or auditor asks for. Whether a duty applies to you is a judgement the template cannot make.