What Independent AI Supplier Verification Should Cover
Independent AI supplier verification is a check of named evidence, not a badge for sale. Buyers should record the legal entity, product scope, controls, dependencies and customer evidence that were actually inspected, the date they were checked, and any gap that remains. A listing, paid assessment or certificate logo is not a substitute for that record.
What should independent verification cover?
A proportionate verification record should identify:
- the legal supplier entity and trading identity;
- the named product, version and intended use;
- model, API and subprocessor dependencies;
- security, privacy and governance evidence in scope;
- human oversight for consequential decisions;
- customer or deployment evidence, if claimed;
- the date, method and remaining gaps.
If a claim cannot be tied to a source, date and scope, treat it as a claim, not as verified evidence.
How is this different from a directory ranking?
Customer-review stars, where they exist, are a separate evidence stream. An Assurance score is a separate 0–100 product-assessment measure. Independent supplier verification is the evidence record behind procurement and assurance work. Payment can fund collection or investigation depth; it cannot buy stars, directory position or a predetermined outcome.
See Evaluate AI suppliers and How ranking eligibility works.
What questions should buyers ask?
- Which legal entity is contracting, and who is accountable for the AI service?
- What product, model family and deployment mode are in scope?
- What evidence has been inspected versus only asserted?
- What is excluded: other products, regions, subprocessors or unpublished models?
- When was the evidence last current, and what would make it stale?
Which evidence categories usually matter?
Identity, purpose and limitations, architecture, data, privacy, security, testing, oversight, change control, incidents, monitoring, intellectual-property and exit. Use the AI supplier due-diligence checklist as a compact prompt, then deepen with security and model/provider dependency guides where the architecture requires it.
What are common gaps?
- a certificate or policy with no named product in scope;
- model providers omitted from the architecture;
- privacy notices that do not match observed data flows;
- “human in the loop” with no authority, competence or time to intervene;
- customer case studies with no permission or relationship evidence;
- expired, undated or copied-from-another-bid evidence.
How AI TrustMark records verification
AI TrustMark records state what was checked, the investigation depth and when. Bronze uses external evidence; Silver adds operational evidence; Gold adds technical examination where access is granted. That is methodology, not a claim that every control in a framework has been certified.
How AI TrustMark fits
AI TrustMark is an independent verification layer. This public guide explains what good looks like, what questions to ask and which evidence categories matter. It is guidance, not a legal opinion, government endorsement, UKAS accreditation or ISO certification.
Fact: primary-source frameworks set expectations for buyers and suppliers. Guidance: the questions and evidence categories below help a buyer apply those frameworks. AI TrustMark methodology: published TrustMark records state what was independently checked, the depth of investigation and when. They do not replace the buyer's award decision.
Free public tools include the AI Procurement Route Finder, this knowledge base and the published methodology. Tailored RFI/RFP/ITT documents, evaluation matrices, organisation-specific crosswalks, completed evidence packs, contract schedules, supplier assessments, deployment assurance and monitoring frameworks remain professional services.
Related guidance
- AI Procurement Knowledge Base
- Evaluate AI suppliers
- AI Procurement Route Finder
- Procurement evidence packs
- Independent assurance
- Methodology
- AI vendor due diligence
- Due-diligence checklist
FAQ
Is supplier verification the same as a TrustMark certificate?
No. A TrustMark is a verified assessment status for a defined scope. Verification can exist as a dated evidence record without issuing a certificate, and a certificate never means every possible control was checked.
Can a supplier pay to be verified as lower risk?
No. Payment can fund the work of collecting and examining evidence. It cannot buy a more favourable verification grade, score or directory position.