AI Vendor Due Diligence Process and Evidence Areas

AI vendor due diligence is a process for testing supplier claims against evidence before award and after material change. It should start with intended use and data, then collect proportionate evidence on identity, architecture, privacy, security, oversight and dependencies. A completed bespoke questionnaire or scoring matrix is professional work; this page explains the process and evidence categories buyers should insist on.

How should the process start?

Define the buying problem before sending a vendor pack:

  • intended outcome and users;
  • data classes and locations;
  • whether the decision is consequential;
  • whether the service is a tool, a model API, an agent or a managed outcome;
  • who will own residual risk.

Then use the AI Procurement Route Finder if the workstream is still unclear.

What evidence areas should the process cover?

Walk through identity, purpose, architecture, training and retrieval data where relevant, privacy, security, testing, human oversight, accessibility, model/provider change, incidents, monitoring, IP and exit. The checklist lists the compact set. This process page is about order and discipline, not a scored matrix.

How should buyers treat supplier answers?

For each material statement, distinguish:

  • claim only;
  • documented;
  • demonstrated in operation;
  • independently verified.

Do not give a marketing PDF the same weight as a dated, scoped, independently checked control.

When is deeper work needed?

Increase depth where personal data, consequential decisions, privileged tools, public-sector duties, EU AI Act exposure, safety-critical use or weak supplier transparency are present. See human oversight and agentic AI procurement.

What should stay with the buyer?

Eligibility, evaluation scores, legal advice, framework admission, contract award and risk acceptance. Independent verification can shorten baseline due diligence; it cannot take those decisions.

How AI TrustMark fits

AI TrustMark is an independent verification layer. This public guide explains what good looks like, what questions to ask and which evidence categories matter. It is guidance, not a legal opinion, government endorsement, UKAS accreditation or ISO certification.

Fact: primary-source frameworks set expectations for buyers and suppliers. Guidance: the questions and evidence categories below help a buyer apply those frameworks. AI TrustMark methodology: published TrustMark records state what was independently checked, the depth of investigation and when. They do not replace the buyer's award decision.

Free public tools include the AI Procurement Route Finder, this knowledge base and the published methodology. Tailored RFI/RFP/ITT documents, evaluation matrices, organisation-specific crosswalks, completed evidence packs, contract schedules, supplier assessments, deployment assurance and monitoring frameworks remain professional services.

Related guidance

FAQ

Is this a free evaluation matrix?

No. It explains the process and evidence categories. A tailored scoring matrix, RFI or completed evidence pack is professional work.

Can one due-diligence pack cover every tender?

Only where the product, scope and evidence remain current. Contract-specific requirements, higher-risk uses and expired evidence still need a fresh look.