Using the UK AI Risk Management Toolkit in Procurement

A practical procurement interpretation of the 2026 DSIT AI Risk Management Toolkit.

The Department for Science, Innovation and Technology published the AI Risk Management Toolkit on 8 September 2026. It is intended to support people involved in the design, operation, procurement and delivery of AI-enabled products.

For procurement teams, the important point is that AI risk management should not be bolted on after supplier selection. It should shape the procurement from planning through post-award monitoring.

1. Use risk management before market engagement

Define the intended use, affected people, data, material failure scenarios and risk ownership before writing requirements. This prevents the market from defining the problem on the buyer's behalf.

See: Plan an AI procurement.

2. Turn identified risks into evidence requirements

A risk register is only useful in procurement if it changes what suppliers must prove. For example:

Risk: sensitive data leakage

Procurement evidence might include data-flow documentation, retention controls, access controls, training-use restrictions, subprocessor details and security testing.

Risk: incorrect or misleading output

Evidence might include task-specific evaluations, known limitations, monitoring, human review, user guidance and escalation processes.

Risk: uncontrolled model change

Evidence might include model/version governance, change notification, regression testing and contractual re-evaluation triggers.

Risk: third-party dependency failure

Evidence might include dependency mapping, continuity plans, alternative providers and exit arrangements.

3. Use multidisciplinary evaluation

The toolkit is aimed at multidisciplinary teams. AI procurement decisions may require commercial, operational, security, privacy, legal, data, technical and change-management input. The precise mix should follow the use case and risk.

The goal is not to create a large committee for every purchase. It is to make sure material risks are reviewed by someone qualified to assess them.

4. Record treatment, not just identification

For each material risk record: 1. the risk; 2. likelihood and impact assumptions where appropriate; 3. supplier evidence; 4. buyer controls; 5. contractual controls; 6. residual risk; 7. owner; 8. monitoring or re-evaluation trigger.

This creates a procurement decision trail that can survive personnel changes and later scrutiny.

5. Connect procurement and contract management

AI risk can change after award. Contract obligations should support ongoing risk treatment through incident reporting, model-change notification, audit/evidence rights, performance monitoring and exit controls.

See: Contract for AI services and Monitor AI suppliers after award.

6. Keep evidence proportional

The depth of assurance should follow the impact of the service. A low-impact productivity tool and a high-impact decision-support system should not require identical due diligence.

Factors that usually justify greater depth include:

  • sensitive or high-volume personal data;
  • consequential decisions;
  • limited human oversight;
  • vulnerable users;
  • critical operational dependency;
  • extensive system access or autonomous actions;
  • difficult-to-reverse deployment;
  • complex model or supplier chains.

7. Create re-evaluation triggers

Risk assessment should be refreshed when the facts change. Triggers may include a new model, new data class, new high-impact use, significant incident, material subprocessor change, major architecture change or new regulatory obligation.

How AI TrustMark fits

The toolkit helps buyers structure risk management. AI TrustMark can provide an independent evidence layer against relevant supplier, product and operational claims. It does not replace the buyer's risk decision or create automatic procurement approval.

Start with the AI Supplier Due-Diligence Checklist or return to the AI Procurement Knowledge Base.