AI Governance · Vendor Risk
AI Vendor Assessment Checklist
Five questions before you sign, aligned to ISO/IEC 42001 and the NIST AI RMF — and what the EU AI Act actually requires, with the corrected 2 December 2027 deadline.
Before an AI vendor contract is signed, someone in the organisation has to be able to answer what the system does with data, and who is accountable if it gets something wrong. This checklist is the structured version of that conversation — the same five questions used in the Responsible AI Studio AI Vendor Assessment tool, usable with or without it.
The 5-question checklist
- Where does the data live?Which country, which subprocessors, retained for how long — not a general security statement.
- Can the vendor explain a decision to the person it affects?Not the model in general — the specific reason for a specific decision.
- Who's accountable when it's wrong?In the contract, not implied in a sales conversation.
- What's the human-review point?Before the output affects someone's job, credit, or insurance.
- ISO 42001 or NIST AI RMF — which, and what did it cover?"We're compliant" is not an answer; the framework and scope are.
How the scoring works
A formal assessment scores the vendor across six weighted categories — including data protection and transparency — against a structured question set, landing in one of three bands: Pass , Conditional , or Reject . Conditional isn't a rejection — it identifies exactly what evidence closes the gap.
Try the checklist on a real vendor — free sample, no cost, just your email.
Email me the free sampleOr go straight to the full assessment — $29, one-time, no subscription.
Frequently asked
- What is an AI vendor assessment?
- An AI vendor assessment is a structured review of a third-party AI system before you sign a contract with it, covering what data it processes, whether its decisions are explainable, who is accountable when it's wrong, and whether it aligns to a recognised framework such as ISO/IEC 42001 or the NIST AI Risk Management Framework.
- Is my AI vendor high-risk under the EU AI Act?
- Under EU AI Act Regulation 2024/1689, Annex III, an AI system is high-risk if it is used to screen or filter job candidates, evaluate creditworthiness (with an exception for AI used solely to detect financial fraud), or assess risk and set pricing for life or health insurance. High-risk obligations for these standalone Annex III systems become enforceable on 2 December 2027, following adoption of the Digital Omnibus on 29 June 2026.
- Does ISO 42001 or NIST AI RMF apply to vendor assessments?
- Both can apply. ISO/IEC 42001 is a certifiable AI management system standard; the NIST AI Risk Management Framework is a voluntary US framework for identifying and managing AI risk. Vendor assessments are commonly scored against one or both, depending on the organisation's jurisdiction and existing compliance programme.
- What is the EU AI Act deadline for high-risk AI vendors?
- Standalone Annex III high-risk obligations — covering recruitment, credit scoring, and life/health insurance pricing — become enforceable on 2 December 2027. This date was corrected after the Digital Omnibus was adopted on 29 June 2026; it was previously 2 August 2026. Note that 2 August 2026 still applies separately to Article 50 transparency obligations and GPAI enforcement powers, which are unaffected by this change.
This page and the linked tool produce first-draft, AI-generated documents — not legal advice. Qualified review is required before you rely on any output.
Sources: Regulation (EU) 2024/1689 (EU AI Act), Annex III · Council of the EU, final adoption of the Digital Omnibus, 29 June 2026 · 12 CFR § 1002.9 (Regulation B) · Responsible AI Studio .