DEV Community

Char-Z AI
Char-Z AI

Posted on

Vendor AI Compliance: A Procurement Checklist

Originally published at https://charz.ai/blog/vendor-ai-compliance-procurement-checklist by Char-Z AI.

Buy AI the Way You Buy Software, Then Add the AI Layer

Procurement is where third-party AI risk is either controlled or created. A standard software RFI covers security and pricing, but AI tools add dimensions — model behavior, training data, autonomy, and governance — that a traditional RFP misses. This checklist turns the evaluation workflow from our third-party AI risk guide into a concrete, repeatable artifact.

Use it in two passes. First, a short screening questionnaire to shortlist vendors. Second, a deep-dive evidence review for the finalists handling sensitive data or high-autonomy workloads.
Screening Questionnaire (Shortlist)

Score each question pass / concern / fail.

Data handling

[ ] Does the vendor state whether it trains on customer data?
[ ] Can you opt out of training on your data, in writing?
[ ] Is a data-processing agreement (DPA) available?
[ ] Is data residency documented and acceptable?
Enter fullscreen mode Exit fullscreen mode

Security

[ ] Does the vendor hold SOC 2 Type II or ISO 27001?
[ ] Is encryption (in transit + at rest) documented?
[ ] Is there a documented breach-notification process?
Enter fullscreen mode Exit fullscreen mode

Model and behavior

[ ] Are model cards / technical documentation published?
[ ] Are evaluation or benchmark results available?
[ ] Are limitations and known failure modes disclosed?
Enter fullscreen mode Exit fullscreen mode

Governance

[ ] Does the vendor have its own AI risk-management program?
[ ] Is it mapped to a recognized framework (e.g., NIST AI RMF, ISO 42001)?
[ ] Is there an AI incident-response plan?
Enter fullscreen mode Exit fullscreen mode

Sub-processing

[ ] Is the subprocessor list published?
[ ] Do subprocessor obligations flow down to you?
Enter fullscreen mode Exit fullscreen mode

Deep-Dive Evidence Review (Finalists)

For finalists, go beyond the questionnaire and collect artifacts:

  • Read the DPA and privacy policy in full. Check training-data clauses, retention, deletion, and third-country transfers (European Commission, 2016).

  • Review the model card against your specific use case. Does the intended-use boundary cover what you plan to do?

  • Check certifications on the issuing bodies' registries — do not take a logo on a website as proof.

  • Review the security disclosures — pen-test summaries, vulnerability policy, and incident history.

  • Interview the vendor's AI governance owner where data sensitivity or autonomy is high. Ask how they decide when an AI feature ships.

Contract Clauses to Secure

  • No training on your data (unless accepted) — protects confidentiality + IP.

  • Right to audit — enables verification over time.

  • Transparency on material change — you re-assess when the model changes.

  • Data deletion on termination — meets GDPR erasure + retention needs.

  • Subprocessor flow-down — keeps obligations complete down the chain.

  • Incident notification window — meets breach-notification timing needs.

  • Indemnity for IP / output — mitigates output-related claims.

Recurring Review, Not One-Time Check

Procurement is the start, not the end. Schedule a review of each AI vendor at least annually, and trigger a re-review when the vendor announces a material change — a new model, a new training-data policy, or a new subprocessor. Continuous vendor oversight distinguishes stronger governance programs.

Sources

European Commission. (2016). Regulation (EU) 2016/679 — General Data Protection Regulation. *Official Journal of the European Union*.
NIST. (2023). *Artificial Intelligence Risk Management Framework (AI RMF 1.0)*. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1
Enter fullscreen mode Exit fullscreen mode

Top comments (0)