AI due diligence
AI due diligence

AI Vendor Due Diligence Questionnaire Template

Use this AI vendor due diligence questionnaire to assess third-party AI risk.

Date

An AI vendor due diligence questionnaire helps regulated institutions evaluate how third-party vendors use AI, what data their AI systems process, what risks they introduce, and what evidence the vendor can provide. Standard vendor reviews and SOC 2 reports are not enough to govern AI risk because AI features, models, data use, and system behavior can change over time.

Below, we've listed key components of an effective an AI vendor due diligence questionnaire. If you need an extra hand in assess risk of your current vendors, we'd love to help you out with our complimentary AI Vendor Risk assessment.

Why AI vendor due diligence needs to change

Financial institutions have long relied on third-party risk management processes to evaluate vendors. These processes typically review areas such as security, business continuity, privacy, compliance, financial condition, operational resilience, and contractual controls.

Those areas still matter.

But AI introduces new questions that traditional vendor reviews often do not answer.

A vendor may pass a standard security review while still using AI in ways that create governance, privacy, compliance, consumer protection, explainability, or audit exposure. A vendor may provide a SOC 2 report, but that report may not tell you whether the vendor uses AI in customer-facing workflows, trains models on customer data, changes AI features after onboarding, or relies on human oversight for high-impact outputs.

For regulated financial institutions, AI vendor due diligence needs to become more specific, more operational, and more continuous. See our related post on the three AI vendor risks a SOC 2 report will never catch for the specific gaps this questionnaire is built to close.

The accountability question isn’t hypothetical either. Under the EU AI Act, deployers carry accountability for high-risk systems operating in their environment, on top of whatever obligations the vendor building the AI already carries. If a vendor’s AI touches an EU resident’s credit decision, the institution using that vendor carries regulatory exposure regardless of who built the model. A due diligence questionnaire is one of the few tools that gets that accountability question answered up front, while there’s still time to change course. Waiting for an examiner to raise it is a far more expensive way to find out.

What is an AI vendor due diligence questionnaire?

An AI vendor due diligence questionnaire is a structured set of questions used to evaluate a vendor’s AI functionality, data use, model behavior, governance controls, documentation, monitoring practices, and change management process.

It should help teams answer:

  • Does this vendor use AI?

  • Where is AI embedded in the product or service?

  • What data does the AI process?

  • Is customer, borrower, member, employee, or confidential data involved?

  • Does the AI affect regulated decisions, communications, or workflows?

  • How does the vendor test, monitor, and update the AI?

  • What documentation and evidence can the vendor provide?

  • What changes will trigger notification or reassessment?

The goal is not to block vendors from using AI. The goal is to understand and govern the risk.

When should financial institutions use an AI vendor questionnaire?

Use an AI vendor due diligence questionnaire when:

  • Onboarding a new vendor

  • Reviewing an existing vendor that has added AI features

  • Evaluating a vendor that processes sensitive or regulated data

  • Reviewing a vendor that supports customer-facing workflows

  • Assessing a vendor involved in lending, servicing, underwriting, fraud, marketing, compliance, support, or decisioning workflows

  • Renewing a contract with a vendor that has changed its product functionality

  • Preparing for an audit, exam, board review, or customer diligence request

AI vendor review should not be limited to procurement. It should be part of the broader AI governance lifecycle.

AI vendor due diligence questionnaire

Use the questions below as a starting point for vendor review.

Vendor AI use

  1. Does your product, service, or platform use AI, machine learning, generative AI, large language models, or AI agents?

  2. Which product features or workflows use AI?

  3. Is AI core to the product or limited to optional features?

  4. Are AI features enabled by default or configurable by the customer?

  5. Can customers disable AI functionality?

  6. Are any AI features currently in beta, pilot, or experimental release?

  7. Do you use third-party AI models, APIs, or infrastructure providers?

  8. Do you use proprietary models, open-source models, commercial models, or a combination?

  9. Do you provide customers with documentation describing AI functionality?

  10. How often do AI features change?

Business process and customer impact

  1. What business process does the AI support?

  2. Does the AI influence customer, borrower, member, employee, or applicant outcomes?

  3. Does the AI generate recommendations, decisions, summaries, scores, classifications, or communications?

  4. Are AI outputs used in regulated workflows?

  5. Can AI outputs affect access to financial products, pricing, eligibility, servicing, fraud review, collections, or dispute handling?

  6. Is human review required before AI outputs are used?

  7. Can customers configure when human review is required?

  8. Are AI-generated outputs labeled or disclosed?

  9. How do you prevent inappropriate reliance on AI outputs?

  10. How do you document the intended and prohibited uses of the AI?

Data use and privacy

  1. What customer data does the AI process?

  2. Does the AI process personally identifiable information, financial data, credit data, transaction data, health data, biometric data, or other sensitive data?

  3. Is customer data used to train, fine-tune, evaluate, or improve AI models?

  4. Can customers opt out of data use for model training or improvement?

  5. Is customer data shared with third-party AI providers?

  6. Where is data processed and stored?

  7. How long is data retained?

  8. Is data encrypted in transit and at rest?

  9. How is data segregated between customers?

  10. How do you delete or return customer data upon request or contract termination?

Model governance and testing

  1. How are AI models selected, approved, and documented?

  2. What testing is completed before an AI feature is released?

  3. Do you test for accuracy, reliability, bias, security, privacy, explainability, and misuse?

  4. Do you maintain model cards, system cards, evaluation reports, or other AI documentation?

  5. How do you define acceptable performance thresholds?

  6. How do you test model behavior across different user groups, scenarios, and edge cases?

  7. How are defects, incidents, or unexpected outputs documented?

  8. How often are models reassessed?

  9. What happens when model performance degrades?

  10. Who is accountable for model governance?

Human oversight and controls

  1. What human oversight is required before AI outputs are used?

  2. Which AI outputs can be accepted automatically?

  3. Which AI outputs require review or approval?

  4. Who reviews high-risk AI outputs?

  5. Can customers configure approval thresholds?

  6. How are overrides documented?

  7. How are exceptions escalated?

  8. Can customers audit user interactions with AI features?

  9. Can customers restrict AI use by role, business unit, workflow, or data type?

  10. What controls prevent unauthorized or inappropriate AI use?

AI agents and autonomous actions

  1. Does your product include AI agents or autonomous workflows?

  2. Can AI features take action without human approval?

  3. What tools, systems, or data sources can AI agents access?

  4. What permissions can AI agents hold?

  5. Can customers define what agents are allowed to do?

  6. Can customers require human approval before agent actions?

  7. Are agent actions logged?

  8. Can customers review, export, or audit agent activity?

  9. How are agent permissions changed or revoked?

  10. What controls prevent agents from exceeding approved scope?

Monitoring and change management

  1. How do you monitor AI features after release?

  2. How do you detect performance issues, drift, misuse, or unexpected behavior?

  3. What AI changes trigger customer notification?

  4. Do you notify customers before enabling new AI functionality?

  5. Do you notify customers when models, data use, subprocessors, or AI providers change?

  6. How much advance notice is provided for material AI changes?

  7. Can customers review and approve AI feature changes before activation?

  8. How are incidents communicated?

  9. Do you provide AI release notes or change logs?

  10. Can customers export AI change history for audit purposes?

Compliance, audit, and evidence

  1. What AI governance policies do you maintain?

  2. What AI documentation can you provide to customers?

  3. Can you provide evidence of AI testing, review, monitoring, and approval?

  4. Can customers access audit logs related to AI functionality?

  5. Can customers see when AI features were enabled, modified, or disabled?

  6. Do you maintain records of human review, overrides, exceptions, and incidents?

  7. How do you support customer audits, exams, or regulatory inquiries?

  8. Have your AI features been reviewed against applicable laws, regulations, or frameworks?

  9. Do you map AI controls to frameworks such as NIST AI RMF or ISO 42001?

  10. Who is responsible for responding to AI governance and compliance questions?

Contract and notification terms

  1. Does the contract define AI functionality and AI-related data use?

  2. Does the contract restrict use of customer data for model training?

  3. Does the contract require notification before material AI changes?

  4. Does the contract include audit rights related to AI features?

  5. Does the contract address third-party AI providers or subprocessors?

  6. Does the contract include incident notification requirements for AI-related events?

  7. Does the contract allow customers to disable AI features?

  8. Does the contract require documentation for regulated use cases?

  9. Does the contract specify responsibility for AI outputs or AI-enabled workflows?

  10. Does the contract require ongoing cooperation for audits, exams, or customer diligence?

How to score AI vendor risk

Not every vendor requires the same depth of review. A financial institution should classify AI vendor risk based on the nature of the vendor relationship and the AI use case.

Risk factor

Lower risk

Higher risk

Data use

Public or non-sensitive data

Customer, borrower, employee, financial, or regulated data

Business impact

Internal productivity

Customer-facing, decision-supporting, or regulated workflow

Autonomy

Human-reviewed outputs

Automated actions or agentic workflows

Vendor control

Customer-configurable

Vendor-controlled with limited transparency

Change frequency

Stable AI functionality

Frequent model, feature, or data-use changes

Documentation

Strong documentation and logs

Limited evidence or unclear governance

Oversight

Clear review and escalation

Limited human oversight

Higher-risk vendors should be reviewed more deeply and reassessed more frequently.

Why point-in-time review is not enough

AI vendor risk changes after onboarding.

A vendor may add a new AI feature. A model provider may change. A product may begin using customer data in new ways. A workflow may become more automated. A feature that was once optional may become default. An internal AI assistant may evolve into an AI agent with broader permissions.

That means AI vendor due diligence cannot be a one-time checklist.

Financial institutions need a way to monitor vendor AI changes over time and route material changes back through review.

What evidence should financial institutions maintain?

For audit, exam, board, or customer diligence purposes, institutions should be able to produce:

  • Vendor AI questionnaire responses

  • Vendor AI documentation

  • Risk tier and rationale

  • Review and approval history

  • Data-use analysis

  • Human oversight requirements

  • Contract terms related to AI

  • Vendor change notifications

  • Reassessment history

  • Exceptions and mitigation plans

  • Audit logs or evidence of monitoring

Asking the right questions matters, but the value comes from retaining the answers in a system of record that can be updated and proven later.

How LucidTrust helps

LucidTrust’s AI vendor due diligence capability helps regulated institutions govern AI vendor risk as part of a broader AI governance program.

With LucidTrust, teams can:

  • Inventory vendors with AI functionality

  • Capture AI vendor questionnaire responses

  • Track vendor AI features, data use, and risk tier

  • Route vendor AI reviews to risk, compliance, legal, security, privacy, procurement, and business owners

  • Document approvals, conditions, exceptions, and reassessments

  • Monitor vendor AI changes over time

  • Maintain audit-ready evidence for exams, boards, audits, and customer diligence

LucidTrust helps turn AI vendor risk review into an ongoing governance process that runs for the life of the vendor relationship.


FAQs

What is an AI vendor due diligence questionnaire?

An AI vendor due diligence questionnaire is a structured set of questions used to evaluate how a vendor uses AI, what data its AI systems process, what risks its AI features create, and what governance evidence the vendor can provide.

Why are standard vendor questionnaires not enough for AI?

Standard vendor questionnaires often focus on security, privacy, business continuity, and compliance. AI vendor risk requires additional review of model use, data use, customer impact, human oversight, monitoring, change management, and audit evidence.

Should SOC 2 be enough to approve an AI vendor?

No. SOC 2 can provide useful information about security and controls, but it may not answer AI-specific questions about model behavior, training data, AI feature changes, customer impact, human oversight, or AI governance evidence.

How often should AI vendors be reassessed?

AI vendors should be reassessed when AI functionality changes, data use changes, model providers change, permissions expand, customer impact increases, incidents occur, or regulatory requirements change. Higher-risk vendors may require more frequent review.

Who should review AI vendors?

AI vendor review should include procurement, third-party risk, compliance, legal, security, privacy, business owners, and AI governance leaders. The exact review group should depend on the vendor’s risk level and business impact.

What should financial institutions document for AI vendor risk?

Financial institutions should document vendor AI functionality, data use, risk tier, review history, approval decisions, contractual controls, human oversight, change notifications, reassessments, exceptions, and evidence retained for audit or examiner review.

More Articles