Originally published at https://charz.ai/blog/vendor-ai-compliance-procurement-checklist by Char-Z AI.
Buy AI the Way You Buy Software, Then Add the AI Layer
Procurement is where third-party AI risk is either controlled or created. A standard software RFI covers security and pricing, but AI tools add dimensions — model behavior, training data, autonomy, and governance — that a traditional RFP misses. This checklist turns the evaluation workflow from our third-party AI risk guide into a concrete, repeatable artifact.
Use it in two passes. First, a short screening questionnaire to shortlist vendors. Second, a deep-dive evidence review for the finalists handling sensitive data or high-autonomy workloads.
Screening Questionnaire (Shortlist)
Score each question pass / concern / fail.
Data handling
[ ] Does the vendor state whether it trains on customer data?
[ ] Can you opt out of training on your data, in writing?
[ ] Is a data-processing agreement (DPA) available?
[ ] Is data residency documented and acceptable?
Security
[ ] Does the vendor hold SOC 2 Type II or ISO 27001?
[ ] Is encryption (in transit + at rest) documented?
[ ] Is there a documented breach-notification process?
Model and behavior
[ ] Are model cards / technical documentation published?
[ ] Are evaluation or benchmark results available?
[ ] Are limitations and known failure modes disclosed?
Governance
[ ] Does the vendor have its own AI risk-management program?
[ ] Is it mapped to a recognized framework (e.g., NIST AI RMF, ISO 42001)?
[ ] Is there an AI incident-response plan?
Sub-processing
[ ] Is the subprocessor list published?
[ ] Do subprocessor obligations flow down to you?
Deep-Dive Evidence Review (Finalists)
For finalists, go beyond the questionnaire and collect artifacts:
Read the DPA and privacy policy in full. Check training-data clauses, retention, deletion, and third-country transfers (European Commission, 2016).
Review the model card against your specific use case. Does the intended-use boundary cover what you plan to do?
Check certifications on the issuing bodies' registries — do not take a logo on a website as proof.
Review the security disclosures — pen-test summaries, vulnerability policy, and incident history.
Interview the vendor's AI governance owner where data sensitivity or autonomy is high. Ask how they decide when an AI feature ships.
Contract Clauses to Secure
No training on your data (unless accepted) — protects confidentiality + IP.
Right to audit — enables verification over time.
Transparency on material change — you re-assess when the model changes.
Data deletion on termination — meets GDPR erasure + retention needs.
Subprocessor flow-down — keeps obligations complete down the chain.
Incident notification window — meets breach-notification timing needs.
Indemnity for IP / output — mitigates output-related claims.
Recurring Review, Not One-Time Check
Procurement is the start, not the end. Schedule a review of each AI vendor at least annually, and trigger a re-review when the vendor announces a material change — a new model, a new training-data policy, or a new subprocessor. Continuous vendor oversight distinguishes stronger governance programs.
Sources
European Commission. (2016). Regulation (EU) 2016/679 — General Data Protection Regulation. *Official Journal of the European Union*.
NIST. (2023). *Artificial Intelligence Risk Management Framework (AI RMF 1.0)*. National Institute of Standards and Technology. https://doi.org/10.6028/NIST.AI.100-1
Top comments (0)