What Should I Ask Suppliers About Their AI Features and Their Own Use of AI?
A copy-usable supplier AI due diligence question set: what to ask about AI in the product, what to ask about the supplier's own AI use, and how to score it.
Ask suppliers two separate sets of questions: one about AI features inside the product you are buying, and one about how the supplier uses AI internally on your data. Most questionnaires cover the first and miss the second. Both belong in your standard due diligence pack, scored and evidenced like any other control area.
This page is written for procurement and compliance owners updating supplier due diligence for AI. The questions are deliberately generic so you can lift them into an existing questionnaire without rewriting your process.
What should I ask suppliers about the AI features in their product?
Start with scope and data flow, then move to control. Five questions cover the ground that matters for a security and compliance review.
- Which functions in the product use AI or machine learning, and can they be disabled? This establishes scope. A feature that cannot be turned off becomes a permanent part of your risk surface.
- Which models do you use, are they hosted by you or by a third party and in which jurisdictions? A supplier routing your data to a model provider you have never assessed is a fourth-party dependency you now own.
- Is our data used to train, fine-tune or evaluate any model? Ask in writing, and ask whether the answer applies to prompts, outputs, telemetry and support tickets separately.
- What retention period applies to prompts and outputs, and who inside your organisation can read them? Human review pipelines are common and rarely volunteered.
- How do you test the feature for accuracy, bias and prompt injection, and will you share results? Vague assurances about testing are a finding in themselves.
What should I ask about a supplier’s own internal use of AI?
This is the half most questionnaires omit. Your data does not only pass through the product; it passes through the supplier’s staff, tooling and support desk.
- Do your staff use AI assistants when handling our data, and under what policy? A support engineer pasting your incident detail into a personal AI account is Shadow AI in someone else’s environment.
- Do you use AI in support, engineering, security operations or content moderation on customer data? Naming functions produces better answers than asking about AI generally.
- Do you have an AI acceptable use policy, and how is it enforced technically? Policy without enforcement tells you little. Ask what blocks or monitors unsanctioned tools.
- Do you have an AI management system, and is it certified or independently assessed? ISO 42001 is the reference point, and a supplier working towards certification is a reasonable answer.
- Do you use AI in any decision that affects our contract, pricing, access or security posture? This is the automated decision-making question, and it matters for fairness and auditability.
Does my supplier use AI on my data even if the product has no AI features?
Often, yes. A product with no AI functionality can still be operated by staff who use AI assistants, supported by a helpdesk running AI summarisation or monitored by a security platform with AI features enabled. The absence of AI in the product tells you nothing about the absence of AI in the supply chain around it. If a supplier answers that they do not use AI to a product question, ask the internal question separately and in writing.
How should I score supplier AI answers?
Score evidence, not assertion. A documented answer with supporting artefacts, meaning a policy, a DPA amendment, test results or a certification scope, is acceptable. A confident answer with no artefact is a conditional pass with a follow-up date. A refusal, a deflection to a marketing page or an answer that contradicts the contract is a finding for the risk register. Our AI Security Gap Analysis applies the same principle internally: assess against a control baseline, then evidence each answer.
Which standards should I anchor the questions to?
Four references cover most of what a mid-sized organisation needs. ISO 42001 gives you the management-system question, and ISO 42001 audit evidence shows what an auditor expects to see. The NIST AI Risk Management Framework gives you the map, measure and manage language for testing questions, and the OWASP LLM Top 10 gives you the technical failure modes to ask about specifically. The EU AI Act matters where the supplier’s feature could be classified as high-risk in a use case you operate.
What contract terms should follow from the answers?
Three clauses do most of the work. First, a no-training commitment covering prompts, outputs and telemetry, with named exceptions if any exist. Second, a notification obligation when the supplier introduces new AI features or new model sub-processors, with a right to review before activation. Third, an audit or evidence right that extends to AI controls rather than stopping at general information security. Without the second clause, a clean assessment expires the moment the supplier ships a release note, which is the position covered in our software just added AI features.
How often should we re-ask these questions?
Annually as a minimum, and on any material product change. AI feature velocity is high, so a twelve-month-old questionnaire response is frequently inaccurate through no fault of the supplier. Tie the review to your existing supplier re-assessment cycle rather than creating a separate one. Where a supplier holds high-sensitivity data, a shorter cycle with a lighter question set is more useful than a long annual form.
Who owns this inside our organisation?
Procurement owns the process, but the questions need a technical reviewer. The workable split is procurement issuing and tracking the questionnaire, security or AI governance reviewing the substance of the answers, and legal converting accepted answers into contract terms. Without a technical reviewer, answers are filed rather than assessed.
Related reading: how to assess an AI supplier’s security and AI Behaviour Verification, which tests whether a supplier’s AI behaves as described. Contact us to discuss applying this to your own supplier base.
Assess against a control baseline
We apply the same evidence-first approach across your own estate, not only your supplier list.