How to verify an AI vendor

Practical steps for buyers to verify an AI supplier without treating logos or unpaid claims as proof.

Verifying an AI vendor means checking who you are buying from, what product and deployment you are actually getting, and which evidence supports the claims that matter for your use case. A logo, case-study quote or unpaid directory listing is not verification.

This guide is a procurement aid, not legal advice.

1. Confirm the legal supplier

Record the legal entity name, company number where available, registered address and contracting party. Check that the entity on the order form matches the entity named on security, privacy and assurance documents.

If the trading brand differs from the contracting company, treat that as a material fact to resolve before award.

2. Pin the product and intended use

Name the exact product, edition and material dependencies (models, APIs, subprocessors, hosting regions). Write down the intended users and permitted use cases.

Without a fixed product scope, later model or hosting changes can invalidate the evidence you collected.

3. Separate claim types

Ask the supplier to label each claim as one of:

  • self-attestation;
  • customer reference;
  • third-party audit or certificate;
  • product test result;
  • contractual commitment.

Do not let a marketing page collapse those into a single “trusted AI” statement.

4. Check security, privacy and operational evidence

For the proposed architecture, request evidence appropriate to your risk:

  • data flows and processing locations;
  • access control and logging;
  • incident and resilience practice;
  • subprocessors and change notification;
  • human oversight for the intended use.

Use structured checklists such as the AI Supplier Due-Diligence Checklist and, where relevant, AI Security Due Diligence.

5. Verify independent certificates yourself

If the supplier presents an AI TrustMark or another certificate:

  • look it up on the issuer's verify page;
  • confirm the legal entity and product named;
  • note validity dates and scope;
  • treat expired or mismatched certificates as not current evidence.

AI TrustMark certificates can be checked at Verify. Do not invent or assume a TrustMark that has not been issued.

6. Treat customer reviews as evidence of use, not of safety

Verified customer reviews can support deployment and satisfaction questions. They do not replace security, privacy, performance or legal evidence. On AI TrustMark, stars affect directory order only after ranking eligibility is unlocked, and payment never buys stars or list position.

7. Control change after award

Define which model, hosting, subprocessor or intended-use changes require notification, evidence refresh or re-evaluation. See Monitor AI suppliers after award.

How AI TrustMark fits

AI TrustMark can help by publishing verified directory evidence, inviting and verifying customer reviews, and running independent assurance assessments. It does not replace your procurement decision, invent reviews, or sell directory position.

Return to the AI Procurement Knowledge Base or use the AI Procurement Route Finder.