AI for business · Vendor questionnaire

Questions to ask an AI vendor before you buy

Most AI risk comes from suppliers. Pick the areas that apply, send the questions, mark the answers — the tool shows red flags. Answers stay in your browser.

Which areas apply?

Basics (every AI tool)
  1. Which AI models does the product use, and from which model provider?

    Good answer: A named model and provider, with information on changes.

  2. What is your role under the AI Act (provider, distributor) and how do you classify this system’s risk? critical

    Good answer: A clear role and a documented risk classification.

  3. What documentation and instructions for use do we get as the deployer?

    Good answer: Instructions, known limitations, intended purpose.

  4. Do you help us with AI literacy (training materials for our users)?

    Good answer: Training or materials included.

  5. Who owns the outputs, and do you indemnify us against copyright claims?

    Good answer: We own the outputs; an IP indemnity for business plans.

Personal and confidential data
  1. Do you sign a data processing agreement (GDPR Art. 28)? critical

    Good answer: Yes, standard DPA available.

  2. Are our inputs and outputs used to train or improve your models? critical

    Good answer: No, contractually excluded.

  3. Where is data stored and processed? Is EU data residency possible?

    Good answer: EU region, or transfers under the EU–US Data Privacy Framework / SCCs.

  4. How long do you keep prompts, files and logs, and can we delete them?

    Good answer: Short, configurable retention; deletion on request.

  5. Which sub-processors do you use (list, countries)?

    Good answer: A published list with notification of changes.

  6. Do you support our DPIA with information (data flows, risks, measures)?

    Good answer: A DPIA support pack.

Assessment: 0/11

11 questions still unanswered.

Red flags

No red flags among the answered questions.

Which questions are most important?

Whether you get a data processing agreement, whether your data is used for training, where data is stored, and — for high-risk uses — how the vendor supports human oversight and bias testing.

What if the vendor does not answer?

Treat unclear answers to critical questions as a red flag: use the tool without personal data, choose another vendor or negotiate contract terms.

Is this enough for NIS2 or DORA?

It is a good start for supplier assessment; regulated entities need their own documented procedure and contract clauses.

General information, not legal advice — consult a lawyer for borderline cases. Regulations reviewed on 29 Sep 2026.