AI supplier due diligence
One questionnaire is a transaction. A programme is a repeatable way of deciding how much diligence a supplier warrants, what evidence closes the gap, and what happens between renewals, which is where most programmes fail.
Tier by exposure, not by spend
| Tier | Trigger | What to require |
|---|---|---|
| Tier 1 highest | AI in an Annex III domain, or making/materially informing decisions about people | Classification assessment, Annex IV inputs, declared metrics, oversight design, log terms, independent assurance, incident timing, right to audit |
| Tier 2 elevated | AI processing personal data, or generating output shown to your customers | Intended purpose, Art. 50 position, accuracy claim, incident timing, log access |
| Tier 3 standard | AI with no personal data and no customer-facing output | Register it; confirm intended purpose; standard security review |
Spend is a poor proxy. A cheap CV-screening tool sits in Tier 1; an expensive infrastructure optimiser may sit in Tier 3.
Where this usually goes next
Three situations account for most people reading this page. Each has a different answer.
A deal is blocked on an AI questionnaire
Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.
You need ISO/IEC 42001 documentation
23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.
You are not sure what reaches you
Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.
This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →
Where independent assurance fits
Questionnaire answers are self-reported. At Tier 1 that is usually not enough, and the practical options are a certification, an independent assessment, or a right to audit that you will realistically never exercise.
ISO/IEC 42001 is emerging as the reference point. Microsoft’s SSPA names it as an assurance route for AI supplier requirements and requires it for AI-sensitive cases: the clearest published example of a large buyer specifying it. Detail →
What a certificate does and does not tell you
Does: a management system exists, has been audited by an accredited body, and covers a defined scope. Does not: that any specific system is safe, accurate or lawful, or that the scope covers the service you are buying. Always read the scope statement on the certificate. A certificate scoped to a supplier’s internal IT tells you nothing about the product you are purchasing.
The renewal gap
Most programmes assess at onboarding and again at renewal, which leaves twelve to thirty-six months where nothing is checked. In AI that is several model generations.
Practical recommendation. Three lightweight triggers between renewals: the supplier notifies a material change to the AI system or its intended purpose; the supplier notifies a serious incident; and an annual one-page attestation that the previous answers still hold. All three are contract terms, not process, which is why they belong in the agreement rather than in a playbook.
Status labels on this page
Verified fact: Article references and dates cited above, checked against the consolidated Regulation.
Expert analysis: The tables, tiering and assessments on this page are our practice, not a standard.
Unsettled: Procurement practice is not codified and varies by buyer. Verify specific programme requirements against the buyer's own published materials.
Diligence is easier when you have done it yourself
The organisations that run this well are usually the ones that built their own inventory and management system first: they know which questions have expensive answers.
Not sure where you sit?
The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.
Frequently asked
How do you tier AI suppliers for due diligence?
By exposure rather than spend. The highest tier covers suppliers whose AI operates in an Annex III domain or makes or materially informs decisions about people, and warrants a classification assessment, Annex IV inputs, declared metrics, oversight design, log terms, independent assurance and incident timing. A middle tier covers AI processing personal data or generating customer-facing output. A standard tier covers AI with neither, where registering the system and confirming intended purpose alongside a normal security review is proportionate.
Does an ISO 42001 certificate prove a supplier's AI is safe?
No. It shows that an AI management system exists, has been audited by an accredited certification body, and covers a defined scope. It does not establish that any specific system is safe, accurate or lawful. The scope statement on the certificate matters: a certificate scoped to a supplier's internal IT says nothing about the product you are buying.