Review template

AI vendor due diligence checklist

Use these prompts as a starting structure. Adjust depth and ownership to the proposed use case and your organization’s requirements.

What this due diligence checklist covers

This AI vendor due diligence checklist organizes questions across use-case accountability, data and privacy, model behavior, security and resilience, legal and commercial terms, and human oversight. Teams should select and deepen questions according to the proposed use—not treat every item as a universal requirement.

Intended roles:
Review coordinators, business owners, and participating security, privacy, legal, procurement, compliance, risk, accessibility, finance, or AI-governance reviewers.
Use it when:
Planning a review, assigning questions, recording evidence needs, or checking whether material gaps remain before a decision.
Inputs:
Defined use case, users and affected people, data categories, integrations, vendor responses, internal requirements, contract terms, evidence references, and named owners.
Outputs:
Relevant questions, response owners, evidence references, reviewer findings, open gaps, follow-up actions, and reassessment triggers.
Boundary:
A checked item is not evidence. Completing the list does not approve a vendor, establish compliance or security, or guarantee that the review is complete.

About this resource

AI Vendor Decision publishes static informational resources for structuring an internal vendor review. The site does not receive documents, assess vendors, provide professional advice, or make approval decisions. Check each resource against your current use case, evidence, policies, contracts, and applicable requirements.

01

Use case and accountability

  • What business outcome is proposed?
  • Who will use the system and who may be affected?
  • Who owns the decision and ongoing operation?
  • Which uses are explicitly out of scope?
02

Data and privacy

  • What data enters, leaves, or is generated by the service?
  • Is sensitive, confidential, regulated, or personal data involved?
  • Where is data processed and who can access it?
  • What deletion, retention, and reuse controls apply?
03

Model and output behavior

  • What models or components support the service?
  • How are limitations and failure modes communicated?
  • Can outputs influence consequential decisions?
  • What evaluation is relevant to the intended use?
04

Security and resilience

  • How is access controlled and logged?
  • How are vulnerabilities and incidents handled?
  • What dependencies and subprocessors are material?
  • What continuity, backup, and exit options exist?
05

Legal and commercial terms

  • Do usage rights fit the proposed workflow?
  • How are customer inputs and generated outputs treated?
  • What commitments, exclusions, and change rights matter?
  • Can the organization meet its own obligations?
06

Oversight and lifecycle

  • Where is human review required?
  • How can users report harmful or incorrect behavior?
  • What conditions must be monitored?
  • What changes require reassessment?

How to use this checklist

For each relevant question, record an owner, response, evidence reference, reviewer finding, open gap, and next action. A completed checkbox is not evidence and does not by itself support approval.

Frequently asked questions

How should teams use an AI vendor due diligence checklist?

Start with a defined use case, select the questions that are material to it, assign owners, and record each response with an evidence reference, reviewer finding, open gap, and next action.

Is a completed checklist evidence that a vendor is approved?

No. A completed checkbox is not evidence and does not establish approval, compliance, security, or fitness for a particular use.

Should every AI vendor receive the same review?

No. Review depth and participating functions should reflect the proposed use, data, integrations, decision impact, internal requirements, and material unknowns.