Vendor Due Diligence Questions for AI Tools
Deliberate Academy Editorial Team
Reviewed for accuracy and professional relevance
You're 6 lessons in — don't lose your progress.
Sign up free to save where you are and earn a verified certificate when you pass.
- Identify the core categories a vendor AI due-diligence process must cover, and the specific question within each category that most often gets skipped
- Explain why a vendor's own compliance assurance does not transfer or discharge your organization's own regulatory obligations
- Recognize model-change notification as the single most commonly missing clause in AI vendor contracts, and explain why it matters
- Apply a proportionate approach to due-diligence depth based on the risk the vendor relationship actually carries
Most AI systems a compliance professional will actually review were not built in-house — they arrive embedded in a vendor's software, delivered through an API, or bundled into a platform the organization already licenses. This creates a common and risky assumption: that because the AI capability came from a vendor, the vendor carries the compliance risk. It does not, or at least not all of it — and the portion your organization retains is frequently the exact portion a regulator or an affected individual will ask your organization to answer for, not the vendor.
What a Vendor AI Due-Diligence Process Should Cover
Data handling. What data does the tool process, and is that data used to train or improve the vendor's models beyond your own organization's instance? This question — whether your data quietly trains a shared model used by other customers — is one of the most consequential and most frequently unasked questions in AI vendor onboarding.
Data residency. Where is data hosted and processed, and what jurisdictional implications does that carry for your organization's own regulatory obligations?
Certifications and audit rights. What relevant certifications does the vendor hold — information security standards, increasingly ISO/IEC 42001 for AI management — and what audit evidence will they actually provide? A vendor's own compliance assurance is a starting point for your review, not a substitute for it — your organization typically retains its own obligations regardless of what the vendor's contract promises.
Model change notification. Will the vendor notify you of a material change to the underlying model before it takes effect, and what does "material" mean in the contract? This is the single most commonly missing clause in AI vendor contracts, and one of the most consequential — a vendor's routine model update can shift a tool's real-world behavior with no code change on your side and no visibility unless a notification clause exists or you run your own independent monitoring.
Do not accept "our vendor is responsible for AI compliance" as a complete answer from a business unit onboarding a new AI-powered tool. It is frequently wrong. Even where a vendor genuinely carries significant provider-side obligations for the system itself, your organization almost always retains its own obligations as the deployer — obligations that a vendor contract cannot discharge on your behalf, regardless of what the contract says about who pays if something goes wrong.
A company's legal team confirms a new AI vendor's contract includes a strong indemnification clause, stating the vendor is liable for any regulatory penalty arising from the tool's operation. Does this indemnification clause mean the company's own deployer-level obligations — such as monitoring the tool's real-world performance in its own context — can be treated as satisfied?
Select one answer.
Sizing Due Diligence to the Risk
Not every AI vendor relationship warrants the same depth of review. A vendor providing an AI tool that screens job candidates or scores credit risk warrants the full due-diligence process, contractual model-change notification, and frequent reassessment. A vendor providing an AI-powered internal meeting-notes summarization tool, with no bearing on any consequential decision about an individual, warrants a lighter review focused primarily on data handling and confidentiality. Applying the same exhaustive process to both wastes limited compliance capacity on the lower-risk relationship at the expense of the higher-risk one.
A Missed Model-Change Notification — Consumer Products Company
Context
A company used a third-party AI recruitment platform to rank job applications, processing several thousand applications per quarter. The vendor contract did not include a clause requiring advance notice of material model updates.
Action
The vendor updated its underlying scoring model mid-quarter, described in release notes only as a general 'ranking quality improvement,' with no detail on what had actually changed. The company's own internal monitoring — comparing the demographic composition of shortlisted candidates against the applicant pool each quarter — flagged a statistically significant shift partway through the quarter, coinciding with the undisclosed update.
Outcome
The company paused reliance on the automated shortlist for two weeks while assessing whether the new model version introduced a concerning pattern, and confirmed with the vendor afterward that the update had occurred. The AI governance team added a mandatory model-change notification clause to the next contract renewal and, recognizing that no such clause existed for several other vendor relationships, extended independent monitoring frequency for every AI-powered vendor tool without a notification clause already in place.
Why does this lesson identify model-change notification as the single most commonly missing clause in AI vendor contracts, and why does that matter?
Select one answer.
Exercise
Your Task
Draft a six-question AI vendor due-diligence checklist covering the four categories from this lesson: data handling, data residency, certifications and audit rights, and model-change notification. For each question, write what a concerning answer would look like, so the checklist is usable by a colleague who did not write it.
Success looks like
- At least one question specifically addresses whether the vendor uses your data to train or improve models beyond your own instance
- The model-change notification question specifies what "material change" should mean, rather than leaving it undefined
Watch out for
- Omitting the model-change notification question, which this lesson identifies as the most commonly missing and most consequential gap
- Accepting vague vendor marketing language such as "we take compliance seriously" as a passing answer to any specific question
- A vendor AI due-diligence process should cover data handling, data residency, certifications and audit rights, and model-change notification.
- A vendor contract can allocate commercial liability through indemnification, but it cannot transfer your organization's own deployer-level regulatory obligations, such as contextual monitoring.
- Model-change notification is the single most commonly missing clause in AI vendor contracts — a routine vendor update can shift a tool's behavior with no visibility on your side without it.
- Due-diligence depth should be proportionate to the risk the vendor relationship actually carries — full scrutiny for consequential decision-making tools, a lighter review for low-stakes internal tools.
- "Our vendor handles compliance" is rarely a complete answer — your organization typically retains its own obligations regardless of what the vendor contract promises.