AI Vendor Due Diligence Questionnaire Template
Use this AI vendor due diligence questionnaire to assess third-party AI risk.
Date
Author
An AI vendor due diligence questionnaire helps regulated institutions evaluate how third-party vendors use AI, what data their AI systems process, what risks they introduce, and what evidence the vendor can provide. Standard vendor reviews and SOC 2 reports are not enough to govern AI risk because AI features, models, data use, and system behavior can change over time.
Below, we've listed key components of an effective an AI vendor due diligence questionnaire. If you need an extra hand in assess risk of your current vendors, we'd love to help you out with our complimentary AI Vendor Risk assessment.
Why AI vendor due diligence needs to change
Financial institutions have long relied on third-party risk management processes to evaluate vendors. These processes typically review areas such as security, business continuity, privacy, compliance, financial condition, operational resilience, and contractual controls.
Those areas still matter.
But AI introduces new questions that traditional vendor reviews often do not answer.
A vendor may pass a standard security review while still using AI in ways that create governance, privacy, compliance, consumer protection, explainability, or audit exposure. A vendor may provide a SOC 2 report, but that report may not tell you whether the vendor uses AI in customer-facing workflows, trains models on customer data, changes AI features after onboarding, or relies on human oversight for high-impact outputs.
For regulated financial institutions, AI vendor due diligence needs to become more specific, more operational, and more continuous. See our related post on the three AI vendor risks a SOC 2 report will never catch for the specific gaps this questionnaire is built to close.
The accountability question isn’t hypothetical either. Under the EU AI Act, deployers carry accountability for high-risk systems operating in their environment, on top of whatever obligations the vendor building the AI already carries. If a vendor’s AI touches an EU resident’s credit decision, the institution using that vendor carries regulatory exposure regardless of who built the model. A due diligence questionnaire is one of the few tools that gets that accountability question answered up front, while there’s still time to change course. Waiting for an examiner to raise it is a far more expensive way to find out.
What is an AI vendor due diligence questionnaire?
An AI vendor due diligence questionnaire is a structured set of questions used to evaluate a vendor’s AI functionality, data use, model behavior, governance controls, documentation, monitoring practices, and change management process.
It should help teams answer:
Does this vendor use AI?
Where is AI embedded in the product or service?
What data does the AI process?
Is customer, borrower, member, employee, or confidential data involved?
Does the AI affect regulated decisions, communications, or workflows?
How does the vendor test, monitor, and update the AI?
What documentation and evidence can the vendor provide?
What changes will trigger notification or reassessment?
The goal is not to block vendors from using AI. The goal is to understand and govern the risk.
When should financial institutions use an AI vendor questionnaire?
Use an AI vendor due diligence questionnaire when:
Onboarding a new vendor
Reviewing an existing vendor that has added AI features
Evaluating a vendor that processes sensitive or regulated data
Reviewing a vendor that supports customer-facing workflows
Assessing a vendor involved in lending, servicing, underwriting, fraud, marketing, compliance, support, or decisioning workflows
Renewing a contract with a vendor that has changed its product functionality
Preparing for an audit, exam, board review, or customer diligence request
AI vendor review should not be limited to procurement. It should be part of the broader AI governance lifecycle.
AI vendor due diligence questionnaire
Use the questions below as a starting point for vendor review.
Vendor AI use
Does your product, service, or platform use AI, machine learning, generative AI, large language models, or AI agents?
Which product features or workflows use AI?
Is AI core to the product or limited to optional features?
Are AI features enabled by default or configurable by the customer?
Can customers disable AI functionality?
Are any AI features currently in beta, pilot, or experimental release?
Do you use third-party AI models, APIs, or infrastructure providers?
Do you use proprietary models, open-source models, commercial models, or a combination?
Do you provide customers with documentation describing AI functionality?
How often do AI features change?
Business process and customer impact
What business process does the AI support?
Does the AI influence customer, borrower, member, employee, or applicant outcomes?
Does the AI generate recommendations, decisions, summaries, scores, classifications, or communications?
Are AI outputs used in regulated workflows?
Can AI outputs affect access to financial products, pricing, eligibility, servicing, fraud review, collections, or dispute handling?
Is human review required before AI outputs are used?
Can customers configure when human review is required?
Are AI-generated outputs labeled or disclosed?
How do you prevent inappropriate reliance on AI outputs?
How do you document the intended and prohibited uses of the AI?
Data use and privacy
What customer data does the AI process?
Does the AI process personally identifiable information, financial data, credit data, transaction data, health data, biometric data, or other sensitive data?
Is customer data used to train, fine-tune, evaluate, or improve AI models?
Can customers opt out of data use for model training or improvement?
Is customer data shared with third-party AI providers?
Where is data processed and stored?
How long is data retained?
Is data encrypted in transit and at rest?
How is data segregated between customers?
How do you delete or return customer data upon request or contract termination?
Model governance and testing
How are AI models selected, approved, and documented?
What testing is completed before an AI feature is released?
Do you test for accuracy, reliability, bias, security, privacy, explainability, and misuse?
Do you maintain model cards, system cards, evaluation reports, or other AI documentation?
How do you define acceptable performance thresholds?
How do you test model behavior across different user groups, scenarios, and edge cases?
How are defects, incidents, or unexpected outputs documented?
How often are models reassessed?
What happens when model performance degrades?
Who is accountable for model governance?
Human oversight and controls
What human oversight is required before AI outputs are used?
Which AI outputs can be accepted automatically?
Which AI outputs require review or approval?
Who reviews high-risk AI outputs?
Can customers configure approval thresholds?
How are overrides documented?
How are exceptions escalated?
Can customers audit user interactions with AI features?
Can customers restrict AI use by role, business unit, workflow, or data type?
What controls prevent unauthorized or inappropriate AI use?
AI agents and autonomous actions
Does your product include AI agents or autonomous workflows?
Can AI features take action without human approval?
What tools, systems, or data sources can AI agents access?
What permissions can AI agents hold?
Can customers define what agents are allowed to do?
Can customers require human approval before agent actions?
Are agent actions logged?
Can customers review, export, or audit agent activity?
How are agent permissions changed or revoked?
What controls prevent agents from exceeding approved scope?
Monitoring and change management
How do you monitor AI features after release?
How do you detect performance issues, drift, misuse, or unexpected behavior?
What AI changes trigger customer notification?
Do you notify customers before enabling new AI functionality?
Do you notify customers when models, data use, subprocessors, or AI providers change?
How much advance notice is provided for material AI changes?
Can customers review and approve AI feature changes before activation?
How are incidents communicated?
Do you provide AI release notes or change logs?
Can customers export AI change history for audit purposes?
Compliance, audit, and evidence
What AI governance policies do you maintain?
What AI documentation can you provide to customers?
Can you provide evidence of AI testing, review, monitoring, and approval?
Can customers access audit logs related to AI functionality?
Can customers see when AI features were enabled, modified, or disabled?
Do you maintain records of human review, overrides, exceptions, and incidents?
How do you support customer audits, exams, or regulatory inquiries?
Have your AI features been reviewed against applicable laws, regulations, or frameworks?
Do you map AI controls to frameworks such as NIST AI RMF or ISO 42001?
Who is responsible for responding to AI governance and compliance questions?
Contract and notification terms
Does the contract define AI functionality and AI-related data use?
Does the contract restrict use of customer data for model training?
Does the contract require notification before material AI changes?
Does the contract include audit rights related to AI features?
Does the contract address third-party AI providers or subprocessors?
Does the contract include incident notification requirements for AI-related events?
Does the contract allow customers to disable AI features?
Does the contract require documentation for regulated use cases?
Does the contract specify responsibility for AI outputs or AI-enabled workflows?
Does the contract require ongoing cooperation for audits, exams, or customer diligence?
How to score AI vendor risk
Not every vendor requires the same depth of review. A financial institution should classify AI vendor risk based on the nature of the vendor relationship and the AI use case.
Risk factor | Lower risk | Higher risk |
|---|---|---|
Data use | Public or non-sensitive data | Customer, borrower, employee, financial, or regulated data |
Business impact | Internal productivity | Customer-facing, decision-supporting, or regulated workflow |
Autonomy | Human-reviewed outputs | Automated actions or agentic workflows |
Vendor control | Customer-configurable | Vendor-controlled with limited transparency |
Change frequency | Stable AI functionality | Frequent model, feature, or data-use changes |
Documentation | Strong documentation and logs | Limited evidence or unclear governance |
Oversight | Clear review and escalation | Limited human oversight |
Higher-risk vendors should be reviewed more deeply and reassessed more frequently.
Why point-in-time review is not enough
AI vendor risk changes after onboarding.
A vendor may add a new AI feature. A model provider may change. A product may begin using customer data in new ways. A workflow may become more automated. A feature that was once optional may become default. An internal AI assistant may evolve into an AI agent with broader permissions.
That means AI vendor due diligence cannot be a one-time checklist.
Financial institutions need a way to monitor vendor AI changes over time and route material changes back through review.
What evidence should financial institutions maintain?
For audit, exam, board, or customer diligence purposes, institutions should be able to produce:
Vendor AI questionnaire responses
Vendor AI documentation
Risk tier and rationale
Review and approval history
Data-use analysis
Human oversight requirements
Contract terms related to AI
Vendor change notifications
Reassessment history
Exceptions and mitigation plans
Audit logs or evidence of monitoring
Asking the right questions matters, but the value comes from retaining the answers in a system of record that can be updated and proven later.
How LucidTrust helps
LucidTrust’s AI vendor due diligence capability helps regulated institutions govern AI vendor risk as part of a broader AI governance program.
With LucidTrust, teams can:
Inventory vendors with AI functionality
Capture AI vendor questionnaire responses
Track vendor AI features, data use, and risk tier
Route vendor AI reviews to risk, compliance, legal, security, privacy, procurement, and business owners
Document approvals, conditions, exceptions, and reassessments
Monitor vendor AI changes over time
Maintain audit-ready evidence for exams, boards, audits, and customer diligence
LucidTrust helps turn AI vendor risk review into an ongoing governance process that runs for the life of the vendor relationship.
FAQs
What is an AI vendor due diligence questionnaire?
An AI vendor due diligence questionnaire is a structured set of questions used to evaluate how a vendor uses AI, what data its AI systems process, what risks its AI features create, and what governance evidence the vendor can provide.
Why are standard vendor questionnaires not enough for AI?
Standard vendor questionnaires often focus on security, privacy, business continuity, and compliance. AI vendor risk requires additional review of model use, data use, customer impact, human oversight, monitoring, change management, and audit evidence.
Should SOC 2 be enough to approve an AI vendor?
No. SOC 2 can provide useful information about security and controls, but it may not answer AI-specific questions about model behavior, training data, AI feature changes, customer impact, human oversight, or AI governance evidence.
How often should AI vendors be reassessed?
AI vendors should be reassessed when AI functionality changes, data use changes, model providers change, permissions expand, customer impact increases, incidents occur, or regulatory requirements change. Higher-risk vendors may require more frequent review.
Who should review AI vendors?
AI vendor review should include procurement, third-party risk, compliance, legal, security, privacy, business owners, and AI governance leaders. The exact review group should depend on the vendor’s risk level and business impact.
What should financial institutions document for AI vendor risk?
Financial institutions should document vendor AI functionality, data use, risk tier, review history, approval decisions, contractual controls, human oversight, change notifications, reassessments, exceptions, and evidence retained for audit or examiner review.



