Skip to content
Amended. Regulation (EU) 2026/1744 entered into force 27 July 2026. See what moved →
EU AI Act ChecklistIndependent reference
Procurement · programme design

AI supplier due diligence

One questionnaire is a transaction. A programme is a repeatable way of deciding how much diligence a supplier warrants, what evidence closes the gap, and what happens between renewals, which is where most programmes fail.

Arts. 23–26ISO/IEC 42001 Annex A third-party controls

Tier by exposure, not by spend

TierTriggerWhat to require
Tier 1
highest
AI in an Annex III domain, or making/materially informing decisions about peopleClassification assessment, Annex IV inputs, declared metrics, oversight design, log terms, independent assurance, incident timing, right to audit
Tier 2
elevated
AI processing personal data, or generating output shown to your customersIntended purpose, Art. 50 position, accuracy claim, incident timing, log access
Tier 3
standard
AI with no personal data and no customer-facing outputRegister it; confirm intended purpose; standard security review

Spend is a poor proxy. A cheap CV-screening tool sits in Tier 1; an expensive infrastructure optimiser may sit in Tier 3.

Where this usually goes next

Three situations account for most people reading this page. Each has a different answer.

A deal is blocked on an AI questionnaire

Legal will not sign until you can evidence how AI is governed. HumanAudit’s AI Trust Package is a fixed $3,500 over five business days: a public trust page, a pre-filled SIG Lite / CAIQ / SSPA Section K questionnaire bank, and your AI inventory and classification.

How this works for AI companies →

You need ISO/IEC 42001 documentation

23 clause-mapped AIMS documents with all 38 Annex A controls pre-populated, editable and yours to keep, from $199. Or score your gaps first: 18 questions, free, no signup to begin.

Free gap assessment →
See the three tiers →

You are not sure what reaches you

Twenty minutes with the founder. No prep, no deck, straight to the person accountable for the work. If none of this applies to you, you get told that on the call.

Book a free 20-minute call →

This reference is published by HumanAudit Inc. Not a law firm, not an accredited certification body, not a registered auditor. We build documentation, your counsel interprets it, and an accredited body of your choosing certifies you. How this is funded →

Where independent assurance fits

Questionnaire answers are self-reported. At Tier 1 that is usually not enough, and the practical options are a certification, an independent assessment, or a right to audit that you will realistically never exercise.

ISO/IEC 42001 is emerging as the reference point. Microsoft’s SSPA names it as an assurance route for AI supplier requirements and requires it for AI-sensitive cases: the clearest published example of a large buyer specifying it. Detail →

What a certificate does and does not tell you

Does: a management system exists, has been audited by an accredited body, and covers a defined scope. Does not: that any specific system is safe, accurate or lawful, or that the scope covers the service you are buying. Always read the scope statement on the certificate. A certificate scoped to a supplier’s internal IT tells you nothing about the product you are purchasing.

The renewal gap

Most programmes assess at onboarding and again at renewal, which leaves twelve to thirty-six months where nothing is checked. In AI that is several model generations.

Practical recommendation. Three lightweight triggers between renewals: the supplier notifies a material change to the AI system or its intended purpose; the supplier notifies a serious incident; and an annual one-page attestation that the previous answers still hold. All three are contract terms, not process, which is why they belong in the agreement rather than in a playbook.

Status labels on this page

Verified fact: Article references and dates cited above, checked against the consolidated Regulation.

Expert analysis: The tables, tiering and assessments on this page are our practice, not a standard.

Unsettled: Procurement practice is not codified and varies by buyer. Verify specific programme requirements against the buyer's own published materials.

Next step

Diligence is easier when you have done it yourself

The organisations that run this well are usually the ones that built their own inventory and management system first: they know which questions have expensive answers.

Not sure where you sit?

The classifier maps your system against Articles 5, 6, 50 and Annex III. Twelve questions, no email.

Run the classifier →

Frequently asked

How do you tier AI suppliers for due diligence?

By exposure rather than spend. The highest tier covers suppliers whose AI operates in an Annex III domain or makes or materially informs decisions about people, and warrants a classification assessment, Annex IV inputs, declared metrics, oversight design, log terms, independent assurance and incident timing. A middle tier covers AI processing personal data or generating customer-facing output. A standard tier covers AI with neither, where registering the system and confirming intended purpose alongside a normal security review is proportionate.

Does an ISO 42001 certificate prove a supplier's AI is safe?

No. It shows that an AI management system exists, has been audited by an accredited certification body, and covers a defined scope. It does not establish that any specific system is safe, accurate or lawful. The scope statement on the certificate matters: a certificate scoped to a supplier's internal IT says nothing about the product you are buying.