AI Procurement Knowledge Base
A practical knowledge base for organisations buying AI: Plan → Specify → Evaluate → Contract → Deploy → Monitor.
Direct answer
What is AI procurement? AI procurement is the process of planning, specifying, evaluating, contracting, deploying and monitoring AI-enabled services while accounting for data, model dependencies, security, human oversight, evidence quality and change over time. It extends normal technology procurement because the model, provider, data use and system behaviour can materially change after award.
AI procurement is not ordinary software procurement with an extra questionnaire. Buyers need to understand the intended use, the data involved, model and supplier dependencies, security, human oversight, legal obligations, evidence quality, change management and what happens after deployment.
This knowledge base turns primary-source guidance into a practical procurement workflow. It does not replace legal advice, a contracting authority's procurement rules, or sector-specific obligations. It helps buyers ask better questions, request better evidence and create an auditable decision trail.
Not sure where to start?
Use the AI Procurement Route Finder. It asks a short adaptive set of questions about where you are in the buying process and the factors that may change the workstream.
The free result gives you:
- the recommended procurement route;
- an indicative complexity level;
- framework and specialist checks to consider; and
- an information checklist showing what to assemble next.
The route finder is intentionally a triage tool. Tailored procurement packs, evidence matrices, supplier assessments, contract schedules, go-live assurance and monitoring frameworks are produced as professional work rather than given away as generic templates.
The six-stage procurement model
1. Plan
Define the problem before selecting a model or supplier. Establish the intended outcome, affected users, data sensitivity, risk ownership, human oversight and whether AI is actually appropriate.
Attach specialist planning guidance to this stage:
- UK Government AI Playbook
- UK AI Risk Management Toolkit
- PPN 017 transparency questions
- AI Procurement Route Finder
2. Specify
Convert risks and outcomes into procurement requirements. Specify transparency, data handling, security, testing, performance, accessibility, auditability, model changes, incident reporting and exit requirements.
Read: Specify an AI procurement
Attach specialist specification guidance to this stage:
- PPN 017 transparency questions
- ICO data protection
- NCSC secure AI procurement
- EU AI Act for procurement
- Human oversight requirements
3. Evaluate
Assess supplier claims using evidence rather than marketing statements. Compare architecture, model provenance, data practices, testing, security, governance, contractual commitments, customer evidence and operational capability.
Attach specialist evaluation guidance to this stage:
- AI supplier due-diligence checklist
- Independent AI supplier verification
- AI vendor due diligence
- Security evidence for AI vendors
- ISO/IEC 42001 for AI procurement
- NIST AI RMF for procurement
- ICO data protection for AI procurement
- NCSC secure AI procurement
- EU AI Act for procurement
- Procuring agentic and autonomous AI
4. Contract
Translate the evaluation into enforceable obligations. Cover permitted use, data, security, model and subprocessor changes, incidents, audit rights, performance, intellectual property, liability, termination and transition.
Read: Contract for AI services
Attach specialist contracting guidance to this stage:
- Model, API and subprocessor dependencies
- Human oversight and consequential decisions
- ICO data protection for AI procurement
5. Deploy
Validate the service in the buyer's own operating environment. Confirm access controls, human oversight, logging, user guidance, data boundaries, integrations, incident routes and go-live criteria.
Read: Deploy purchased AI safely
Attach specialist deployment guidance to this stage:
6. Monitor
AI systems and their dependencies change. Monitor performance, incidents, model/provider changes, data use, drift, security findings, complaints, regulatory developments and contract compliance.
Read: Monitor AI suppliers after award
Attach specialist monitoring guidance to this stage:
- NCSC secure operation
- Oversight that still works in practice
- Data-practice drift
- How TrustMark evidence is refreshed
Core evidence areas
A proportionate AI procurement should consider evidence across these areas:
- supplier identity, ownership and accountability;
- intended purpose, users and limitations;
- model and system architecture;
- training, fine-tuning, retrieval and operational data where relevant;
- privacy and data-protection controls;
- cyber security and AI-specific threat controls;
- testing, evaluation and known failure modes;
- human oversight and escalation;
- accessibility and user impact;
- model, API, subprocessor and material-change controls;
- incident response and business continuity;
- monitoring, logging and auditability;
- intellectual-property and content rights;
- exit, portability and deletion;
- independently verifiable customer or deployment evidence.
Primary sources
This knowledge base is designed to sit above, not replace, authoritative guidance. Key sources include:
- UK Government AI Playbook, which covers safe, effective and secure AI use and how government organisations select, buy and deploy AI. See the Playbook procurement crosswalk.
- DSIT AI Risk Management Toolkit, published 8 September 2026 for teams designing, operating, procuring or delivering AI-enabled products.
- PPN 017: Improving transparency of AI use in procurement, which provides optional questions to identify AI use in procurements and service delivery.
- The Sourcing Playbook, updated 15 June 2026.
- NCSC Guidelines for secure AI system development, including secure design, development, deployment, operation and supply-chain considerations.
- NIST AI Risk Management Framework, a widely used framework for governing and managing AI risk. See the NIST AI RMF procurement crosswalk.
Use the AI Procurement Framework Crosswalks hub for NCSC, ICO, EU AI Act and ISO/IEC 42001 mappings.
How AI TrustMark fits
AI TrustMark is an independent verification and assurance layer. The knowledge base explains what buyers should ask for. The directory and assurance system can then show what supplier, product, customer and operational evidence has actually been verified.
A listing, paid service or assessment does not buy a directory position, review score, Assurance score or predetermined certificate outcome.
Start with the right next step
If you already know what you need, use the AI supplier due-diligence checklist, PPN 017 guide, or 2026 UK AI Risk Management Toolkit guide.
If you are not sure which path fits your situation, find your AI procurement route.