Editorial
Guides
Independent explainers organised around the AI procurement buyer journey: Plan → Specify → Evaluate → Contract → Deploy → Monitor. These pages do not change scores, rankings, or TrustMark outcomes.
AI procurement buyer journey
Start at the AI Procurement Knowledge Base, then follow the stage that matches the work in hand.
All published guides
- AI TrustMark and ISO 42001
Bronze/Silver/Gold are assessment depths. ISO/IEC 42001 is a management-system standard. They answer different questions.
- How to verify an AI vendor
Practical steps for buyers to verify an AI supplier without treating logos or unpaid claims as proof.
- What is an AI TrustMark?
A plain explanation of what an AI TrustMark is, what it is not, and how it relates to reviews, ranking and assurance.
- AI Security Due Diligence
A buyer-focused security due-diligence guide for AI-enabled services.
- NIST AI RMF for Procurement
A procurement-focused guide to using NIST AI RMF without treating it as certification or a substitute for UK requirements.
- UK Government AI Playbook for Procurement
A procurement-focused crosswalk to the UK Government AI Playbook.
- Procuring Agentic and Autonomous AI
A buyer guide to the additional controls needed when AI systems can plan, call tools or take actions.
- Human Oversight in AI Procurement
A practical guide to specifying, evidencing and testing meaningful human oversight in AI procurement.
- AI Model, API and Provider Dependencies
A practical procurement guide to understanding and controlling AI model, API and provider dependencies.
- AI Procurement Framework Crosswalks
A structured hub for mapping AI procurement evidence across government guidance, security, privacy, risk management, regulation and management-system assurance.
- ISO/IEC 42001 Evidence in AI Procurement
A practical guide to using ISO/IEC 42001 evidence in supplier due diligence without treating management-system certification as proof of product performance or suitability.
- EU AI Act Procurement Evidence Guide
How procurement teams can turn EU AI Act applicability and role questions into practical supplier evidence requests without treating procurement as legal certification.
- ICO AI and Data Protection for Procurement
A buyer-focused guide to turning ICO AI and data-protection requirements into proportionate supplier questions and evidence requests.
- NCSC Secure AI Guidance for Procurement
A procurement-focused interpretation of the NCSC Guidelines for secure AI system development, with evidence areas buyers can test before and after award.
- Using the UK AI Risk Management Toolkit in Procurement
A practical procurement interpretation of the 2026 DSIT AI Risk Management Toolkit.
- PPN 017 Explained for AI Procurement
A practical explanation of PPN 017 and how to use its AI-transparency questions in procurement.
- AI Supplier Due-Diligence Checklist
A compact evidence checklist for buyers evaluating AI products and suppliers.
- Monitor AI Suppliers After Award
A practical post-award monitoring framework for AI-enabled services.
- Deploy Purchased AI Safely
A practical go-live framework for purchased AI systems after contract award.
- Contract for AI Services
Translate AI procurement findings into enforceable supplier obligations and change controls.
- Evaluate AI Suppliers
How to distinguish supplier claims from independently supportable evidence when evaluating AI services.
- Specify an AI Procurement
How to write proportionate, testable procurement requirements for AI-enabled services.
- Plan an AI Procurement
A practical planning framework for AI procurement before supplier selection begins.
- AI Procurement Knowledge Base
A practical knowledge base for organisations buying AI: Plan → Specify → Evaluate → Contract → Deploy → Monitor.
- How an AI TrustMark assessment works
A clear end-to-end explanation of AI TrustMark's evidence-based assurance process.
- How ranking eligibility works on AI TrustMark
- What Independent AI Supplier Verification Should Cover
Independent AI supplier verification is a check of named evidence, not a badge for sale. Buyers should record the legal entity, product scope, controls, dependencies and customer evidence that were actually inspected, the date they were checked, and any gap that remains. A listing, paid assessment or certificate logo is not a substitute for that record.
- AI Vendor Due Diligence Process and Evidence Areas
AI vendor due diligence is a process for testing supplier claims against evidence before award and after material change. It should start with intended use and data, then collect proportionate evidence on identity, architecture, privacy, security, oversight and dependencies. A completed bespoke questionnaire or scoring matrix is professional work; this page explains the process and evidence categories buyers should insist on.