Vendor AI Due Diligence
A structured due-diligence questionnaire for assessing an AI vendor across EU AI Act value-chain obligations, data protection, model risk, security and DORA overlap. Weighted, re-performable scoring with a live scoreboard, critical-question floors, a gap list and a recommended contract-clause checklist. Export to CSV or print; nothing leaves your machine.
Vendor AI Due Diligence is a structured questionnaire for assessing an AI vendor before you contract. A short scoping section establishes what is being procured (a GPAI model, an AI system, a component) and the context — whether you might become the provider under Art. 25, whether the use touches an Art. 5 prohibited practice or an Annex III high-risk area, whether the vendor is outside the EU, and whether DORA applies — and that switches the relevant sections on or off. The questionnaire then covers transparency and AI Act documentation, data protection and governance, model performance and oversight, security and resilience, contract and value chain, and (for financial entities) the DORA and CSSF overlap. Scoring is deliberately simple and disclosed on screen: Yes / Partial / No / Unsure map to points, sections carry editable weights that renormalise as scoping hides them, and the whole thing can be re-performed in Excel from the CSV export. Two overrides sit on top of the arithmetic — a No or Unsure on a critical question floors the tier at Elevated, and an Art. 5 prohibited use sets the outcome to Blocked. The output is a findings report: the tier, the critical exceptions, the gaps to follow up, and a recommended contract-clause checklist. It runs entirely in the browser and performs no network calls.
- A scoping section that determines which obligations apply and shows only the relevant questions
- Six weighted assessment areas — documentation, data protection, model oversight, security, contract, DORA overlap
- A live scoreboard with fully disclosed, re-performable scoring (points, weights and formulas on screen)
- Critical-question floors and an Art. 5 "Blocked" override on top of the arithmetic
- A findings report — tier, critical exceptions, gaps, and a recommended contract-clause checklist
- CSV export for reperformance in Excel, plus print / PDF, and JSON save / load
- Fully browser-based — no server, nothing leaves your machine
Buying an AI system pulls in obligations from several directions at once — the EU AI Act value chain (are you about to become the provider? is it high-risk? is the use even permitted?), GDPR, and, for financial entities, DORA and the CSSF outsourcing regime. Vendor assessments tend to be one-off spreadsheets whose scoring nobody can reproduce, and a red flag on a make-or-break question gets diluted into an overall percentage. This questionnaire encodes those obligations into one scoped, weighted assessment where the methodology is on screen and re-performable from the export, and where critical questions and prohibited uses override the average rather than being lost in it — producing a defensible vendor score, a gap list and a contract-clause checklist to take into negotiation.
Status
LiveRegulation
EU AI ActFormat
This tool runs entirely in your browser. Don't take my word for it — open it, switch your device to airplane mode, and keep working. If it still works offline, nothing is being sent anywhere.
You can also inspect what the server sends back. The response headers are public; scan them yourself.
Scan iddi-labs.comNo account, no upload, no server-side storage of your data.