Quick answerAI vendor due diligence is the assessment of an AI-enabled supplier – SaaS, consultant, model provider or service provider – against your AI governance standards. It complements standard vendor risk management with AI-specific questions: model provenance, training data, oversight responsibilities, hallucination handling and incident reporting.
Why AI vendors need their own due diligence
Standard vendor risk management covers security, financial stability, business continuity and privacy. AI introduces new dimensions that those reviews rarely surface: where the model came from, what it was trained on, how it behaves under stress, what guardrails apply, how the vendor handles incidents involving AI outputs. Treating an AI vendor as a regular SaaS vendor misses most of the risk.
What to assess
- Use case and intended business purpose – what decisions does this AI inform or make
- Data flowing to and from the vendor – including training, inference and logging
- Model provenance – built in-house, foundation model, fine-tuned, vendor-licensed
- Training data – sources, consent basis, sensitive categories
- Model behaviour – accuracy, bias testing, hallucination handling
- Human-oversight responsibilities – your team’s, the vendor’s, joint
- Vendor controls, certifications and policies (SOC 2, ISO 27001, ISO 42001)
- Incident reporting commitments – what events, what timelines
- Sub-processors – including the underlying model provider (OpenAI, Anthropic, Google, Meta, etc.)
- Data retention and deletion – including model training opt-outs
Where standard vendor due diligence falls short
Model provenance
Standard vendor questionnaires don’t ask where the underlying model came from. For AI vendors this matters: a vendor wrapping GPT-4 has different risk than one wrapping a self-trained model.
Training data lineage
Was the model trained on data the vendor had the right to use? Was personal data involved? Was consent obtained? Standard questionnaires don’t go here.
Behavioural testing
Has the AI been tested for bias, accuracy, robustness? Standard vendor reviews assume software behaves the same way each time. AI does not.
Hallucination handling
How does the vendor handle confident-but-wrong AI outputs? What guardrails apply? What’s the user-facing remediation path?
AI vendor due diligence in practice
Three practical patterns:
- Tier vendors by AI risk – not all AI vendors need the same depth of review
- Reuse common questionnaires (Cloud Security Alliance AI questionnaire, FS-ISAC AI tools assessment) and supplement with use-case-specific questions
- Time-box the review – perfect AI vendor due diligence is unreachable; defensible AI vendor due diligence is achievable in 1-4 weeks per vendor
How PrivIQ supports AI vendor due diligence
PrivIQ ships AI vendor assessment templates that are tailorable by vendor category (model provider, AI-enabled SaaS, AI consultant), AI use case and risk profile. Assessments link back to the AI use-case register so a vendor’s coverage of your specific use cases is visible. Sub-processor traceability is built in for cases where the AI vendor’s own dependencies (the underlying model provider) introduce additional risk.
- AI vendors need AI-specific due diligence – not just standard vendor reviews.
- Model provenance, training data, behavioural testing and hallucination handling are the gaps standard reviews miss.
- Tier vendors by AI risk; not all need the same depth of review.
- Reuse common questionnaires (CSA, FS-ISAC) and supplement with use-case questions.
PrivIQ helps organisations and consultants put this into practice — with policies, controls, evidence, tasks, registers and reporting that survive audit.
More on AI Governance.
Do I need to do AI due diligence on tools like ChatGPT or Copilot?
Yes. Enterprise-tier subscriptions to ChatGPT, Copilot and similar consumer-grade tools still need due diligence – particularly around data retention, training opt-outs, output rights and sub-processor disclosures. The vendor-grade enterprise versions have these answers; the free or consumer-tier versions often do not.
Should I assess the underlying model provider (OpenAI, Anthropic) directly?
Where the AI vendor exposes meaningful choice of underlying model, yes – at least at a high level. Most enterprise AI vendors will already have done this and provide the disclosure as part of their standard due diligence pack.
How is AI vendor due diligence different from AI third-party risk?
They’re closely related. ‘AI vendor due diligence’ is the assessment phase. ‘AI third-party risk’ is the ongoing oversight phase – periodic reassessment, incident monitoring, contract review. Same data, different cycle.
How long does AI vendor due diligence take?
For tier-1 AI vendors (high-stakes use cases, significant data exposure): 2-4 weeks. For tier-2: 1-2 weeks. For tier-3 (low-stakes, limited data): a checklist review of an hour or two.
Can the AI vendor’s SOC 2 substitute for AI-specific due diligence?
No. SOC 2 covers operational and security controls. It does not cover model provenance, training data, behavioural testing or hallucination handling. SOC 2 is necessary but not sufficient.