AI Procurement Knowledge Base

A practical knowledge base for organisations buying AI: Plan → Specify → Evaluate → Contract → Deploy → Monitor.

Direct answer

What is AI procurement? AI procurement is the process of planning, specifying, evaluating, contracting, deploying and monitoring AI-enabled services while accounting for data, model dependencies, security, human oversight, evidence quality and change over time. It extends normal technology procurement because the model, provider, data use and system behaviour can materially change after award.

AI procurement is not ordinary software procurement with an extra questionnaire. Buyers need to understand the intended use, the data involved, model and supplier dependencies, security, human oversight, legal obligations, evidence quality, change management and what happens after deployment.

This knowledge base turns primary-source guidance into a practical procurement workflow. It does not replace legal advice, a contracting authority's procurement rules, or sector-specific obligations. It helps buyers ask better questions, request better evidence and create an auditable decision trail.

Not sure where to start?

Use the AI Procurement Route Finder. It asks a short adaptive set of questions about where you are in the buying process and the factors that may change the workstream.

The free result gives you:

  • the recommended procurement route;
  • an indicative complexity level;
  • framework and specialist checks to consider; and
  • an information checklist showing what to assemble next.

The route finder is intentionally a triage tool. Tailored procurement packs, evidence matrices, supplier assessments, contract schedules, go-live assurance and monitoring frameworks are produced as professional work rather than given away as generic templates.

The six-stage procurement model

1. Plan

Define the problem before selecting a model or supplier. Establish the intended outcome, affected users, data sensitivity, risk ownership, human oversight and whether AI is actually appropriate.

Read: Plan an AI procurement

Attach specialist planning guidance to this stage:

2. Specify

Convert risks and outcomes into procurement requirements. Specify transparency, data handling, security, testing, performance, accessibility, auditability, model changes, incident reporting and exit requirements.

Read: Specify an AI procurement

Attach specialist specification guidance to this stage:

3. Evaluate

Assess supplier claims using evidence rather than marketing statements. Compare architecture, model provenance, data practices, testing, security, governance, contractual commitments, customer evidence and operational capability.

Read: Evaluate AI suppliers

Attach specialist evaluation guidance to this stage:

4. Contract

Translate the evaluation into enforceable obligations. Cover permitted use, data, security, model and subprocessor changes, incidents, audit rights, performance, intellectual property, liability, termination and transition.

Read: Contract for AI services

Attach specialist contracting guidance to this stage:

5. Deploy

Validate the service in the buyer's own operating environment. Confirm access controls, human oversight, logging, user guidance, data boundaries, integrations, incident routes and go-live criteria.

Read: Deploy purchased AI safely

Attach specialist deployment guidance to this stage:

6. Monitor

AI systems and their dependencies change. Monitor performance, incidents, model/provider changes, data use, drift, security findings, complaints, regulatory developments and contract compliance.

Read: Monitor AI suppliers after award

Attach specialist monitoring guidance to this stage:

Core evidence areas

A proportionate AI procurement should consider evidence across these areas:

  • supplier identity, ownership and accountability;
  • intended purpose, users and limitations;
  • model and system architecture;
  • training, fine-tuning, retrieval and operational data where relevant;
  • privacy and data-protection controls;
  • cyber security and AI-specific threat controls;
  • testing, evaluation and known failure modes;
  • human oversight and escalation;
  • accessibility and user impact;
  • model, API, subprocessor and material-change controls;
  • incident response and business continuity;
  • monitoring, logging and auditability;
  • intellectual-property and content rights;
  • exit, portability and deletion;
  • independently verifiable customer or deployment evidence.

Primary sources

This knowledge base is designed to sit above, not replace, authoritative guidance. Key sources include:

Use the AI Procurement Framework Crosswalks hub for NCSC, ICO, EU AI Act and ISO/IEC 42001 mappings.

How AI TrustMark fits

AI TrustMark is an independent verification and assurance layer. The knowledge base explains what buyers should ask for. The directory and assurance system can then show what supplier, product, customer and operational evidence has actually been verified.

A listing, paid service or assessment does not buy a directory position, review score, Assurance score or predetermined certificate outcome.

Start with the right next step

If you already know what you need, use the AI supplier due-diligence checklist, PPN 017 guide, or 2026 UK AI Risk Management Toolkit guide.

If you are not sure which path fits your situation, find your AI procurement route.