# Vendor due-diligence questions — AI tools (SMB template)

**How to use:** Send to vendors before buying or renewing an AI tool (chatbot, ATS, analytics, copilots). Keep answers with your AI tools register. Prioritise vendors that touch HR, credit, biometrics, or customer chat.

**Disclaimer:** Questionnaire for SMB orientation — **not legal advice**. It does not replace contract review or, where needed, legal counsel. The EU AI Act allocates duties by **role**; vendor marketing claims (“AI Act ready”) are not proof.

**Buyer:** `[ORG NAME]`  
**Vendor:** `[VENDOR NAME]`  
**Product:** `[PRODUCT NAME]`  
**Date sent:** `[YYYY-MM-DD]`  
**Response due:** `[YYYY-MM-DD]`  
**Our contact:** `[NAME, EMAIL]`

---

## A. Role & scope

1. Who is the **provider** of the AI system under Regulation (EU) 2024/1689 — you, a sub-processor, or us if we brand/modify it?  
2. Is the product placed on the **EU market** / supported for EU customers? Where is the legal entity contracting with us?  
3. Does the product include a **general-purpose AI (GPAI) model** you provide, or do you only call third-party APIs (name them)?  

**Vendor answer:** `[ ]`

---

## B. Intended purpose & high-risk

4. What is the documented **intended purpose** of the AI?  
5. Is the product marketed or suitable for **recruitment/HR decisions**, **credit scoring**, **education decisions**, **biometrics**, or **critical infrastructure** safety? If yes, which Annex III / Annex I category do you map to?  
6. Do you claim an **Article 6(3)** “not high-risk” position? If yes, provide the written assessment approach (without relying on us to invent it).  
7. Will full **Annex III** provider duties be met by **2 December 2027** (Omnibus timeline)? Share your roadmap at high level.  

**Vendor answer:** `[ ]`

---

## C. Prohibited practices (Article 5)

8. Confirm the product does **not** provide: workplace/education **emotion recognition** (outside lawful exceptions), **social scoring** of the banned type, **untargeted face scraping**, biometric categorisation on sensitive traits, or tools for non-consensual intimate imagery.  
9. What controls stop customers from enabling banned configurations?  

**Vendor answer:** `[ ]`

---

## D. Transparency (Article 50) — live since 2 Aug 2026

10. If the system interacts with natural persons, how do you support **disclosure that they interact with AI**?  
11. For generative audio/image/video/text, how do you support **machine-readable marking / detectability**? What must we configure as deployer?  
12. Can you provide sample end-user notice text?  

**Vendor answer:** `[ ]`

---

## E. Deployer enablement (especially if high-risk later)

13. Will you provide **instructions for use**, human-oversight guidance, and logging export (≥ 6 months retention capability)?  
14. How are **serious incidents** reported to us and to authorities?  
15. What training / literacy materials do you offer for our staff?  

**Vendor answer:** `[ ]`

---

## F. Data protection & security

16. What **personal data** categories are processed? Sub-processors? Transfer tools (SCCs, etc.)?  
17. Is there a current **DPA** / Article 28 GDPR package?  
18. Security certifications, penetration test summary availability, and data residency options (`[EU-only?]`)?  

**Vendor answer:** `[ ]`

---

## G. Contractual

19. Will you accept flow-down clauses that you remain **provider** where that is the correct role, and cooperate with our audits on AI Act points above?  
20. Liability / indemnity language specific to AI Act fines or forced withdrawal — what is on offer?  

**Vendor answer:** `[ ]`

---

## Internal scoring (buyer only — do not send)

| Area | OK / Gap / Blocker | Notes |
|------|--------------------|-------|
| Role clear | `[ ]` | |
| No Art. 5 features | `[ ]` | |
| Art. 50 support | `[ ]` | |
| Annex III roadmap (if needed) | `[ ]` | |
| GDPR / security | `[ ]` | |
| **Decision** | `[buy / pilot / reject]` | `[date]` |

