The Shift in Enterprise AI Procurement
As the European Union AI Act (Regulation 2024/1689) moves from legislative debate into the implementation phase, the focus for Chief Technology Officers and digital transformation leaders has shifted. The primary challenge is no longer merely finding a performant model, but ensuring that the integration of third-party systems does not introduce unmanaged legal liability. Effective AI vendor due diligence is now a prerequisite for operational stability. When an enterprise integrates a third-party AI solution, it is not just buying a software license; it is adopting the compliance posture of the vendor.
The EU AI Act classifies AI systems based on risk, imposing stringent requirements on ‘high-risk’ systems as defined in Article 6 and Annex III. For enterprises in sectors like retail, finance, and human resources, many common AI use cases—such as automated recruitment screening or credit scoring—fall directly into this category. Failure to conduct thorough AI vendor due diligence can lead to significant fines, which can reach up to 7% of global annual turnover for the most severe violations involving prohibited AI practices under Article 5.
Defining Roles under the EU AI Act
To perform effective due diligence, an organization must first identify its role. Most enterprises act as ‘deployers’ under Article 3(4) of the Act. A deployer is a person or entity using an AI system under its authority. However, the boundary between a deployer and a provider is fluid. Under Article 28, a deployer can be reclassified as a ‘provider’ if they put their own name or trademark on a high-risk AI system, make a substantial modification to it, or change its intended purpose. This shift in status transfers the full weight of provider obligations—including conformity assessments and technical documentation—onto the enterprise. Due diligence must therefore assess whether the vendor’s delivery model forces the enterprise into a provider role.

The Article 10 Checklist: Data Governance and Quality
One of the most technically demanding aspects of the AI Act is Article 10, which governs data and data governance for high-risk AI systems. During the AI vendor due diligence process, enterprises must verify that the vendor’s training, validation, and testing data sets meet specific quality criteria. This is not a simple request for a data privacy policy; it is an audit of the data lifecycle.
- Design choices: The vendor must demonstrate the rationale behind their data collection processes and the original purpose of the data.
- Data collection: Documentation must show how the data was acquired and whether it was sourced in compliance with intellectual property and privacy laws.
- Data preparation: This includes cleaning, transformation, and labeling processes. Enterprises should ask for details on how labels are verified and who performed the labeling.
- Bias detection and mitigation: Article 10(2)(f) specifically requires providers to examine datasets for biases that could lead to prohibited discrimination. A vendor must provide evidence of their bias testing methodologies.
For organizations looking to evaluate their current standing before engaging with new vendors, our AI Readiness Test provides a structured framework to identify gaps in internal data governance that could conflict with vendor requirements.
Technical Documentation and Article 11
Article 11 requires that technical documentation for high-risk AI systems be drawn up before the system is placed on the market. In an enterprise context, this documentation is the ‘source of truth’ for compliance. During due diligence, a vendor’s refusal to provide detailed technical documentation should be a red flag. This documentation must include the system’s architecture, algorithmic logic, and a detailed description of the hardware resources used. It must also outline the system’s performance metrics and the methods used to monitor its output. Without this level of transparency, the enterprise cannot fulfill its own obligations as a deployer, particularly regarding human oversight.

Transparency and Information for Deployers
Article 13 of the EU AI Act mandates that high-risk AI systems be designed and developed in a way that ensures their operation is sufficiently transparent to enable deployers to interpret the system’s output and use it appropriately. This translates into a requirement for comprehensive ‘Instructions for Use.’ These instructions are a core component of AI vendor due diligence.
Enterprises should evaluate these instructions to ensure they clearly define the system’s intended purpose, the level of accuracy, the known limitations, and the specific circumstances under which the system may fail or produce biased results. A compliant vendor will provide clear guidance on human oversight (Article 14), specifying how a human operator can intervene, override, or shut down the system if necessary. At CONAIS, our AI transition services prioritize the establishment of these oversight frameworks to ensure that human-in-the-loop requirements are met without sacrificing operational efficiency.
Monitoring and Post-Market Oversight
The relationship between an enterprise and an AI vendor does not end at deployment. Article 61 requires providers of high-risk AI systems to establish a post-market monitoring system. This system must actively collect and analyze data on the performance of the AI tool throughout its lifetime. During the procurement phase, the due diligence process must confirm how the vendor will share this monitoring data with the enterprise. If the AI system encounters a serious incident or malfunctions in a way that constitutes a breach of fundamental rights, the vendor is obligated to report this. The enterprise needs a clear contractual agreement specifying the timelines for such notifications.
Managing the General-Purpose AI (GPAI) Variable
Many modern enterprise applications are built on top of General-Purpose AI models, such as those provided via Azure OpenAI. The AI Act introduces specific obligations for providers of GPAI models under Article 51. When an enterprise is conducting AI vendor due diligence on a software-as-a-service (SaaS) provider that uses a GPAI backend, the enterprise must look through the SaaS layer. The due diligence must confirm that the underlying model provider is compliant with transparency requirements, such as providing a summary of the content used for training and adhering to EU copyright law.
For retailers utilizing advanced analytics, the complexity of GPAI integration is significant. We often see this when implementing specialized AI solutions where the orchestration layer must handle both the specific business logic and the compliance data from the foundation model provider. Ensuring that your vendor has a robust agreement with their own upstream providers is a critical, yet often overlooked, part of the process.
Contractual Safeguards and Indemnification
Technical due diligence must be mirrored by legal due diligence. Traditional software contracts are often insufficient for AI. Contracts should include specific clauses regarding the EU AI Act, including warranties that the system has undergone the necessary conformity assessments (Article 43) and bears the CE marking where required. Furthermore, the contract should define liability for ‘model drift’ or performance degradation over time. If a vendor’s update to an algorithm causes the system to become non-compliant or biased, the enterprise must have clear legal recourse.
Implementing a Sustainable Due Diligence Workflow
To manage AI vendor due diligence at scale, enterprises should move away from ad-hoc assessments and toward a standardized framework. This workflow should involve a cross-functional team including legal, IT, data science, and procurement. The first step is a classification triage: Is the tool high-risk? If yes, the depth of documentation required increases exponentially. The second step is a technical audit of the vendor’s Article 10 and Article 13 compliance. The third step is a review of the vendor’s post-market monitoring capabilities.
For a detailed breakdown of the official requirements, practitioners should refer to the full EUR-Lex AI Act text. This primary source is essential for understanding the nuances of the legal obligations that vendors must satisfy. Relying on secondary summaries can often miss the specific technical requirements that an auditor will eventually look for.
Conclusion: Moving Toward Proactive Compliance
AI vendor due diligence is no longer an optional check-box for procurement; it is a critical component of risk management in the EU. By rigorously evaluating vendors against the requirements of the AI Act—specifically focusing on data governance, transparency, and the potential for role reclassification—enterprises can adopt innovative AI solutions without inheriting unquantified risks. This proactive approach ensures that AI adoption remains a driver of growth rather than a source of legal and operational friction.
At CONAIS, we help enterprises navigate these complexities by combining deep technical expertise with a thorough understanding of the regulatory landscape. Whether you are modernizing legacy IT or deploying new agentic workflows, we ensure your AI transition is audit-grade and future-proof. To discuss your specific AI governance needs or to start an assessment of your vendor ecosystem, contact our advisory team today.
Frequently asked questions
What is the most critical part of AI vendor due diligence under the AI Act?
The most critical part is verifying the vendor’s compliance with Article 10 (Data Governance) and Article 13 (Transparency), especially for high-risk systems, to ensure you do not inherit unmanaged legal liability.
Can an enterprise become a ‘provider’ instead of a ‘deployer’?
Yes, under Article 28, if an enterprise substantially modifies a high-risk AI system or changes its intended purpose, they assume the full legal responsibilities of the provider.
What documentation should I ask for from an AI vendor?
You should request the technical documentation required by Article 11 and the comprehensive ‘Instructions for Use’ mandated by Article 13, which detail the system’s capabilities, limitations, and oversight requirements.
![]()






