· 5 min read·en

    EU AI Act Vendor Due Diligence Checklist

    Checklist for SMBs to assess AI vendors under the EU AI Act—contracts, data handling, conformity, red flags and a practical scorecard.

    EU AI Act Vendor Due Diligence Checklist

    TL;DR: Use this practical checklist to evaluate AI vendors against the EU AI Act and GDPR. The checklist covers conformity evidence, data handling, transparency, contracts and a simple scoring template to rank vendors quickly.

    Why vendor due diligence matters under the EU AI Act

    SMBs that buy or use third-party AI systems become part of the compliance chain under the EU AI Act: providers, importers and users each carry obligations. That means vendor shortcomings—missing technical documentation, no conformity assessment, or poor logging—can create fines, operational outages, and reputational harm for your company.

    The AI Act requires a risk-based approach and forces conformity assessments and technical documentation for high-risk AI systems. Providers must keep logs and traceability artifacts SMBs should request during procurement.

    Takeaway: Vendor failures transfer legal and financial risk to your business—due diligence is not optional.

    Quick comparison: EU AI Act vs GDPR for third-party AI

    Both frameworks intersect but have different scopes and enforcement triggers:

    TopicGDPREU AI Act
    Core focusPersonal data protection and lawful processingSafety, fundamental rights, and risk classification of AI systems
    Key obligations for vendorsData minimisation, DPIAs, lawful basis, processors' obligationsConformity assessments for high-risk systems, technical documentation, transparency requirements
    Evidence SMBs should requestData processing agreements, DPIAs, security measuresRisk classification, conformity assessment reports, technical documentation and logs

    Where they overlap: transparency, data minimisation and record-keeping. Where they differ: the AI Act adds conformity assessments, explicit high-risk classifications, and system-level documentation beyond personal data.

    What to check when procuring: ask for both DPIAs and AI Act technical documentation; ensure contractual commitments cover both regimes.

    Takeaway: Satisfy GDPR and the AI Act by requesting both DPIAs and AI Act conformity/technical artefacts.

    Which AI suppliers need deeper scrutiny (high-risk signals)

    Common high-risk use cases for SMBs include:

    • Hiring and HR automation (screening, ranking candidates).

    • Credit or eligibility decisions (loan approvals, insurance pricing).

    • Safety-critical automation (industrial control or automated vehicles).

    • Biometric identification used for security or access control.

    Red flags to watch for:

    • Opaque models with no explainability or model cards.

    • Unclear data lineage or undisclosed training datasets.

    • AI embedded in essential business functions without fallback.

    Opaque models and missing lineage are the most common signs that an AI supplier will cost you more in risk than they save in price.

    Takeaway: Treat vendors powering decisions that affect rights, safety or money as high priority for deep due diligence.

    10-step due diligence checklist for assessing AI vendors

    1. Confirm vendor's risk classification and conformity assessment — request written evidence whether the system is high-risk under the AI Act and any conformity reports.

    2. Review technical documentation — model specs, intended use, limitations, performance metrics, and testing results.

    3. Evaluate data handling — retention periods, purpose limitation, cross-border transfers, and encryption in transit and at rest.

    4. Ask for DPIAs or equivalent risk assessments — verify mitigation measures and residual risks.

    5. Check transparency and contestability — explainability mechanisms, user notices, and processes to contest automated outcomes.

    6. Verify monitoring and update policies — how models are patched, retrained, and how updates are communicated.

    7. Require logging and auditability — decision logs, access logs, and tamper-evident records.

    8. Assess subcontractors and supply chain — who else processes data or provides model components?

    9. Clarify incident response and liability — breach notification timelines, remediation commitments and insurance coverage.

    10. Negotiate contractual clauses — warranties, audit rights, SLAs, termination triggers, and indemnities.

    Takeaway: Use this 10-step list as a minimum procurement checklist—treat missing items as negotiation points or deal breakers.

    Practical contract clauses and questions to request

    Ask for clear, enforceable language. Examples to request or adapt:

    • Audit rights: "Customer may audit vendor's compliance with data processing and AI Act obligations with 30 days' notice, at customer expense unless non-compliance is found."

    • Data processing limits: "Vendor will only process customer personal data for the documented purposes and will not re-use training data for other clients without explicit consent."

    • Model update & change notification: "Vendor will notify customers of material model changes 15 business days before deployment and provide rollback options."

    • Portability and deletion: "Upon contract termination, vendor will export and securely delete customer data within 30 days."

    • Liability & caps: Tie liability caps to breach types; do not accept a blanket low cap for regulatory fines or data breaches.

    Takeaway: Insist on contractual audit rights, notification windows for changes, and clear liability for regulatory breaches.

    Scoring template: how to rank vendors quickly

    Use a weighted scorecard to compare vendors on core categories:

    Suggested weights: Compliance 30%, Data practices 25%, Transparency 20%, Resilience and SLA 15%, Supply chain visibility 10%.

    Scoring method: score each category 0–5, multiply by weight, sum to a total out of 5. Set a minimum pass threshold (e.g., 3.5/5) for procurement.

    Takeaway: A simple weighted scorecard reduces subjective decisions and surfaces hidden risks.

    Common vendor responses and how to interpret them

    What genuine evidence looks like vs marketing claims:

    • Genuine evidence: technical documentation, audit reports, DPIAs, model performance test results, and references from similar customers.

    • Marketing claims to challenge: "proprietary black box" without model cards, vague statements about "anonymised data" without lineage proof, or refusal to name subcontractors.

    How to probe vague answers:

    • Ask for sample model cards or redacted training data inventories.

    • Request specifics on synthetic data sources and whether original personal data was used.

    If a vendor refuses to provide any documentation or audit access, treat that as an immediate red flag.

    Takeaway: Insist on documentary proof; mistrust unsupported marketing language.

    Implementation roadmap for SMBs (30/60/90 days)

    30 days: implement the 10-step checklist for active procurement and enforce immediate stop conditions on unknown, high-risk vendors.

    60 days: update standard contracts, implement a vendor questionnaire and a scoring sheet for procurement.

    90 days: integrate continuous monitoring, logging review and periodic vendor re-assessments into security and compliance workflows.

    Takeaway: Execute quick wins in 30 days, formalise processes in 60, and build continuous oversight by 90 days.

    Immediate stop conditions:

    • No documentation provided.

    • Refusal to allow audits.

    • Unclear or undisclosed data usage and subcontractors.

    Pause deployment and involve legal or an external AI auditor when regulatory exposure is likely (high-risk classification, personal data combined with automated decision making, or complex supply chains).

    Takeaway: Escalate early on clear documentation gaps or audit refusals.

    Resources, templates and next steps

    Downloadable vendor questionnaire and scoring sheet are available—start by adapting the 10-step checklist into your procurement flow. Review related service offerings and real-world examples in our services and case studies.

    Takeaway: Use templates and real-world examples to speed up safe procurement.

    Ready to reduce procurement risk? If a vendor won’t produce documentation or allow audits, treat the deal as unfinished business.

    CTA: Plan a free intro call or "Plan een vrijblijvende kennismaking" — contact us to review a vendor response or get a customised vendor questionnaire: Contact us.

    Klaar voor jouw AI-traject?

    Plan een vrijblijvende kennismaking - in 30 minuten weten we waar AI voor jouw bedrijf de moeite waard is.

    Plan een kennismaking