Template · Articles 25, 26 and 50 · Supports duties in force since 2 August 2026

AI Vendor Due Diligence Questionnaire (EU AI Act)

An AI vendor due diligence questionnaire is a structured question set you send to every supplier whose product contains AI you deploy, to verify their compliance posture under the EU AI Act (Regulation (EU) 2024/1689) before and during adoption. It matters because deployers carry their own obligations — Article 26 duties, Article 50(3)–(4) transparency and, from 2 December 2027, the Annex III high-risk deployer regime — and cannot outsource them to the supplier, while Article 25 allocates duties along the AI value chain that your contract should capture. The RegShelf questionnaire covers five scored sections plus contract clauses.

Last reviewed: 26 August 2026 · Supports duties in force since 2 August 2026 · Included in the kit as 11_Vendor_AI_DueDiligence_Questionnaire.docx

First page of 11_Vendor_AI_DueDiligence_Questionnaire.docx from the RegShelf EU AI Act Kit
First page of 11_Vendor_AI_DueDiligence_Questionnaire.docx — the document you receive in the kit.

What this document is

Document 11 of the RegShelf kit is a fill-in questionnaire — one copy per vendor per AI system — with five question sections (General; Transparency; Data & GDPR; Robustness & support; AI Act posture), a green/amber/red scoring rubric, a list of seven contract items to request, and a decision record. Its premise is stated on page one: "We are AI Act compliant" is a marketing sentence. The questionnaire asks for the specific artefacts — instructions for use, documentation, test results, a DPA — that let you verify the claim, and treats a vendor who cannot answer as itself an answer about risk.

Who needs it

Any company deploying third-party AI: standalone tools, APIs, and AI features inside broader SaaS products. Your vendor's gaps surface in your product — if a vendor chatbot lacks the built-in AI-interaction disclosure its provider owes under Article 50(1), your customers see the gap, and you separately carry your own deployer duties under Article 50(3)–(4). If a vendor screening tool turns out to be high-risk and undocumented, you are the one using it on real candidates. And if you white-label a vendor system under your own brand, the Act treats you as its provider, with the full provider duty set.

What the law requires — precisely

The questionnaire is careful about who owes what:

  • Article 25 allocates responsibilities along the AI value chain — information, cooperation and notification duties between providers and downstream actors belong in the contract, which is why Section 7 lists clauses rather than hopes.
  • Article 50 attribution: AI-interaction disclosure by design (50(1)) and machine-readable marking (50(2)) are the provider's; informing people about emotion recognition or biometric categorisation (50(3)) and visible deepfake/public-interest-text labels (50(4)) are yours as deployer — question B4 asks what features the vendor provides to support your labelling duty, not theirs.
  • Training-data summaries: the duty to publish one (Article 53(1)(d)) applies to GPAI model providers, not to every AI vendor — question C1 asks accordingly instead of demanding a GPAI artefact from an ordinary system provider.
  • Supervision: for AI systems based on a general-purpose AI model developed by the same provider, the AI Office acts as market surveillance authority (Article 75) — question E7 captures which authority is competent for your vendor.

What's inside the RegShelf template

Over thirty questions across five sections:

  • A — General: legal identity and EU establishment, system and version, intended purpose in plain language, the vendor's own role under the Act, and written confirmation that your intended use is within the intended purpose;
  • B — Transparency (Article 50): disclosure features, machine-readable marking and its survival across transformations, deepfake-labelling support, defaults and configuration;
  • C — Data & GDPR: training-data categories, training on your inputs and the opt-out, data residency, DPA with SCCs, retention and sub-processors;
  • D — Robustness & support: evidenced accuracy claims, known limitations and failure modes, incident process, update notices, human-oversight features, security certifications;
  • E — AI Act posture: the vendor's own classification and reasoning, Annex III preparation status for 2 December 2027, upstream GPAI models, deployer documentation, Article 5 screening including the December 2026 CSAM/NCII safeguards, and regulatory history;

plus seven contract items (compliance warranty, notification duties, cooperation clause, no silent repurposing, training-data/IP indemnity, exit terms), the one-red-blocks-adoption scoring rule, and a decision table with a worked example.

How to use it

Send one questionnaire per vendor per AI system, score each section green, amber or red — and do not average: one red section blocks adoption until resolved. Feed the outcome into your AI system inventory, set written conditions with deadlines for ambers, and re-run the questionnaire on material vendor changes (new model version, changed terms, acquisition). Any answer suggesting an Article 5 prohibited practice means running the prohibited practices screen immediately.

Related reading

Frequently asked

Why do we need AI vendor due diligence if the vendor claims compliance?+

Because deployers carry their own AI Act obligations and cannot outsource them, and because an unevidenced compliance claim protects no one. Due diligence swaps assurances for artefacts: instructions for use, documentation, test results, a DPA, and written answers you can hold the vendor to in contract.

What should an AI vendor questionnaire ask about the EU AI Act?+

The vendor's role and classification under the Act with reasoning, Article 50 transparency features (disclosure, marking, labelling support), data and GDPR terms including training on your inputs, robustness evidence and incident processes, high-risk preparation status for December 2027, and Article 5 screening including CSAM/NCII safeguards due by 2 December 2026.

Is the vendor or our company responsible for AI Act compliance?+

Both, for different duties. The provider owes design-side duties (e.g. Article 50(1) disclosure, 50(2) marking, high-risk documentation); you as deployer owe use-side duties (Article 26, Article 50(3)–(4) labels, and from 2 December 2027 the high-risk deployer regime). White-labelling the vendor's system under your own brand shifts you into the provider role entirely.

What contract clauses should we ask an AI vendor for?+

The RegShelf template lists seven: instructions for use as an exhibit with your use confirmed in scope; a compliance warranty tied to the vendor's role; advance notice of material changes and incidents; a cooperation clause for your own compliance needs; no silent remote repurposing; training-data and IP indemnity plus the training opt-out; and exit terms covering data return and transition.

Primary sources

This template ships in the EU AI Act Kit

24 fill-in documents in Word and Excel — launch price €149, twelve months of updates included.

See the full kit