Worked example

AI Vendor Due Diligence File Example

A due diligence file example for buyers collecting security, data, model, and compliance evidence from an AI vendor.

Who this is for

A founder, operations lead, or procurement owner reviewing a third-party AI product before connecting company data.

Signals to check

  • The vendor processes customer or employee data.
  • The tool may produce decisions or recommendations.
  • The vendor has limited public documentation about retention, sub-processors, or evaluation.

Step-by-step workflow

  1. Write down the data categories and business process touched by the vendor.
  2. Generate a vendor questionnaire with evidence requests and red flags.
  3. Create an inventory entry so the AI system is not forgotten after launch.
  4. Schedule a follow-up review whenever the vendor changes its model or terms.

Useful outputs include a saved classification, an owner, an evidence list, a disclosure draft, and a date for the next review. The useful result is not just a score or file; it is a small record that explains what was checked, what changed, and what should be reviewed next.

Before you start

After the output

Known limitation

The tools are self-assessment aids. A higher-stakes launch still needs internal sign-off and, where appropriate, professional legal review. Keep an editable copy and re-run the workflow when the destination requirement or policy changes.

Related examples

Back to examples