AI vendor due diligence means establishing, in writing, what each AI supplier has committed to: their role under the EU AI Act, the system’s intended purpose, how it handles your data, and the instructions for use you are expected to follow. As a deployer, your own compliance is built on those answers — Article 26 requires you to use high-risk systems in line with the provider’s instructions, which you cannot do if you have never asked for them.
Why your compliance depends on their answers
The AI Act splits responsibility along the supply chain. The provider carries the product-side duties; you, as deployer, carry the operational ones — and several of yours are defined by reference to theirs. You must use the system within its intended purpose and instructions, retain logs where they are under your control, and monitor operation as the provider directs. Each duty presupposes the vendor has told you the purpose, where the logs live, and what monitoring is expected. Due diligence is how you get that on the record.
The questionnaire: what to ask every AI supplier
- Role: Do you confirm you are the provider of this system under the EU AI Act? Who is the provider if not you?
- Intended purpose: What is the system’s documented intended purpose? Is our planned use within it?
- Classification: Have you assessed the system against Article 5, Annex III and Article 50? What was the conclusion, and will you share the reasoning?
- Instructions for use: Provide the instructions Article 26 expects us to follow, including any human-oversight requirements.
- Logging: What logs does the system generate, where are they held, for how long, and how do we retrieve them?
- Data handling: What data does the system process, where, and is it used to train models? Is a GDPR Article 28 processing agreement in place?
- Transparency: If the tool interacts with our customers or generates content, what built-in support exists for the Article 50 disclosure and labelling duties arriving on 2 August and 2 December 2026?
- Change control: How will you notify us of substantial changes to the system or its intended purpose — either of which can change its classification and our duties?
- Incidents: What is your process for serious incidents, and how quickly will we be told?
Reading the answers
Strong vendors answer specifically and in writing; weak ones send a marketing page that says “fully EU AI Act compliant” without saying what was assessed or by whom. Watch especially for an intended purpose narrower than your planned use — a “productivity” tool you intend to use for screening job applicants is a classification problem and possibly a role problem, since repurposing a system into a high-risk use can shift provider duties onto you. A vendor who cannot say where logs live is a vendor whose tool you cannot operate compliantly in a high-risk setting.
Make it routine, not a project
- Send the questionnaire before any new AI purchase, and to existing vendors at renewal.
- Include AI features switched on inside software you already own — CRM scoring, ATS matching, meeting transcription.
- File the completed answers against the system in your AI register, dated — that is the evidence layer.
- Diarise a re-check when the vendor announces major changes: new features can mean a new classification.
Due diligence with somewhere to live
AI Register Ireland makes vendor due diligence a standing obligation on every system you record, with the completed questionnaire stored as evidence beside the classification. See how it works.