Third-Party AI Vendor Due Diligence: The Questionnaire Every Enterprise Needs

Share:
Learn how AI vendor due diligence helps assess data security, model transparency, compliance, and third-party risk before approving enterprise AI tools.

AI vendor due diligence is the process of evaluating a third-party AI provider’s data handling, model behavior, security architecture, and compliance posture before granting it access to organizational data or decision-making workflows. It extends traditional third-party risk management by adding questions specific to how a model was trained, how it evolves after deployment, and how accountable the vendor is for the outputs it produces.

Why Standard Vendor Questionnaires Miss AI-Specific Risk

Every enterprise security team already has a vendor risk questionnaire on file. Most were built for software vendors that store data, process transactions, or host infrastructure. AI vendors behave differently. They train models on your data, generate outputs that influence business decisions, and often depend on subprocessors and foundation model providers sitting several layers removed from the contract you signed.

That gap shows up in the breach data. IBM’s 2025 Cost of a Data Breach Report found that organizations with a high level of shadow AI, meaning employees using unapproved AI tools without security sign-off, paid an average of $670,000 more per breach than organizations with low or no shadow AI exposure. The same report found that 97% of organizations that suffered an AI-related security incident lacked basic AI access controls, and 63% had no AI governance policy at all.

A Realistic Shadow AI Scenario

Picture a common pattern security teams are seeing right now. A finance analyst uploads a spreadsheet of vendor contracts into a free-tier generative AI tool to summarize payment terms faster. The tool is not on the approved vendor list, was never reviewed by security, and retains uploaded content to improve its model by default. Months later, a competitor’s pricing strategy looks suspiciously close to your negotiated vendor rates. Tracing the leak back to that one upload takes weeks, because the tool never appeared in any asset inventory or vendor register in the first place.

This is shadow AI vendor risk in practice: exposure that never passed through procurement, never touched a questionnaire, and never triggered a security review until the damage was already done. It is also why due diligence has to start earlier than contract negotiation. It needs to catch tools the moment someone tries to use them.

AI Vendor Risk Assessment Questionnaire

Below is a working questionnaire you can adapt directly into your intake process. It is organized into eight categories, each targeting a distinct AI TPRM risk area. Score every response on the same scale your risk committee already uses (for example, Low, Medium, High, Critical) and require documentation, not just a yes or no answer, for anything scored above Medium.

1. Questions for Data Governance and Provenance

  • What data sources were used to train the model, and does the vendor hold documented rights, licenses, or consent for that data?
  • Will our organization’s data be used to train, fine-tune, or improve the model, and can we opt out?
  • How is our data segregated from other customers’ data in storage and processing?
  • What is the data retention period for prompts, uploads, and outputs, and how is deletion verified?
  • Does the vendor process personal or regulated data (PII, PHI, financial data), and under what legal basis?

2. Questions for Model Transparency and Documentation

  • How frequently is the model retrained or updated, and how are customers notified of material changes?
  • What explainability methods are available for how the model reaches a given output or decision?
  • Has the model been tested for bias or disparate impact across protected classes, and are results available for review?

3. Questions for Security Architecture

  • What encryption standards apply to data in transit and at rest, including prompts and generated outputs?
  • How are API keys, access tokens, and credentials managed and rotated?
  • What tenant isolation controls prevent data leakage between customers in a multi-tenant environment?
  • Does the vendor undergo independent penetration testing or security audits, and can reports be shared under NDA?

4. Questions for Compliance Alignment

  • Does the vendor align its practices with the NIST AI Risk Management Framework or ISO/IEC 42001?
  • What certifications does the vendor currently hold (SOC 2, ISO 27001, ISO 42001), and can current reports be provided?
  • How does the vendor classify the AI system under applicable regulations, including risk-tier obligations under frameworks like the EU AI Act?

5. Questions for Subprocessor and Fourth-Party Disclosure

  • List every foundation model provider, cloud host, and data processor involved in delivering this service.
  • How does the vendor monitor subprocessor security posture on an ongoing basis?
  • Are contractual security and data protection obligations flowed down to every subprocessor in the chain?

6. Questons for Incident Response and Accountability

  • How does the vendor detect and report model failures, data leakage, or harmful outputs?
  • What are the contractual breach notification timelines, and do they meet our regulatory obligations?
  • Who is contractually accountable when an AI-generated output or decision causes harm?

7. Human Oversight and Override

  • Does the platform support human review before high-impact decisions are finalized?
  • How quickly can we disable the tool or roll back to a prior model version if it starts behaving unexpectedly?
  • What audit trail exists for human overrides of AI-generated recommendations?

8. Shadow AI and Adoption Controls

  • Does the vendor offer enterprise-tier controls (SSO, admin visibility, data opt-out) that differ from its free or self-serve tier?
  • Can the vendor confirm whether employees at our organization are already using an unmanaged version of this tool?
  • What telemetry does the vendor provide to help us detect unauthorized or unmanaged usage internally?

Use this table as an AI vendor risk assessment template you can drop directly into procurement workflows, and route every AI tool request through it, regardless of which department is asking.

Risk-Scoring Tier Matrix

Turning questionnaire answers into a decision requires a consistent scoring model. The matrix below is a starting point governance teams can calibrate to their own risk appetite.

TierCriteriaTypical Controls Required
CriticalModel influences high-impact decisions (credit, employment, healthcare); processes regulated data; unclear training data rights or subprocessor chainFull security review, legal sign-off, contractual liability terms, continuous monitoring, quarterly reassessment
HighAccess to sensitive but non-regulated business data; retrains on customer inputs by default; limited documentation availableData opt-out required, restricted data scope, semi-annual reassessment
MediumAccess to internal but low-sensitivity data; established vendor with SOC 2 or ISO certification; clear data handling policyStandard contract terms, annual reassessment
LowNo access to sensitive data; used for general productivity (drafting, summarizing public information)Lightweight intake review, added to vendor inventory

Vendors that cannot answer basic questions in categories 1, 4, or 5 should default to Critical regardless of their stated use case, since undocumented data provenance and subprocessor chains are the two risk factors most likely to surface in an incident after the fact.

Making Due Diligence Continuous, Not a One-Time Gate

A questionnaire answered once at contract signing tells you little about risk six months later. AI models update frequently, vendors add new subprocessors, and regulatory expectations shift. Static, point-in-time assessments have always struggled to keep pace with vendor ecosystems, and AI accelerates that gap further, since a model that passed review in January can behave differently by June without any contract amendment.

Leading governance teams are shifting from an annual questionnaire cycle to continuous, automated monitoring: tracking vendor certifications, subprocessor changes, and public disclosures on an ongoing basis instead of waiting for the next renewal date. Ampcus Cyber’s modern TPRM approach reflects this shift, and tools built for continuous vendor visibility, such as Wizard within the ComplyX suite, exist precisely because manual, once-a-year reviews cannot keep pace with how often AI vendors change their models, data practices, and subprocessor relationships. The technical requirement drives the tooling, not the other way around.

Embedding AI Vendor Review Into Your GRC Program

Due diligence questionnaires work best as part of a broader governance, risk, and compliance program, not as a standalone exercise. That means:

  • Routing every AI tool request, regardless of department, through a formal intake and review process
  • Assigning risk tiers based on data sensitivity and decision impact using a matrix like the one above
  • Mapping vendor findings to internal control frameworks so audit teams can trace accountability
  • Reviewing AI vendor relationships on a defined cadence tied to their assigned risk tier, not only at renewal

Enterprises that build this into existing third-party risk management workflows avoid duplicating effort and gain a single system of record for both traditional and AI-specific vendor risk.

Turning the Questionnaire Into a Decision

The most common failure in vendor due diligence is treating the questionnaire as paperwork rather than a decision-making tool. Answers should feed directly into a scoring model that determines whether a vendor is approved outright, approved with conditions such as restricted data access, or rejected. Security and procurement teams that skip this step end up with a stack of completed questionnaires and no clear record of why a vendor was approved in the first place.

If your organization is bringing AI vendors into procurement faster than your risk process can evaluate them, it may be time to formalize the questionnaire, the scoring model, and the monitoring behind it.

Talk to Ampcus Cyber about building an AI-ready third-party risk program that keeps pace with how fast your vendor ecosystem is growing.

Enjoyed reading this blog? Stay updated with our latest exclusive content by following us on Twitter and LinkedIn.

×

7th August 2026

New Delhi, India

Know more
Ampcus Cyber
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Talk to an expert