What should we ask an AI vendor during due diligence?

When conducting due diligence on an AI vendor, organisations should primarily inquire about their adherence to ISO 42001 principles, focusing on AI system governance, risk management, and ethical considerations. Key questions should cover data provenance, model transparency, bias mitigation strategies, and the vendor's incident response capabilities. Understanding their AI lifecycle management and compliance with relevant regulations is crucial for ensuring responsible AI deployment and mitigating organisational risk.

Practitioners often overlook the depth of inquiry required beyond a simple "Are you ISO 42001 compliant?" It is insufficient to accept a general affirmation; due diligence must delve into how the vendor implements the standard's controls. For instance, regarding Clause 6.1.2, "AI system risk assessment," organisations should request evidence of risk identification, analysis, and treatment plans specific to the AI system being procured, including potential societal and ethical impacts. A common pitfall is failing to assess the vendor's capability to provide ongoing assurance, such as regular audits or performance monitoring, which is critical for maintaining compliance and managing evolving AI risks throughout the system's lifecycle.

Another critical area often neglected is the vendor's approach to data governance and model explainability, directly relevant to ISO 42001 Clause 8.2.1, "AI system data management," and Clause 8.2.3, "AI system explainability." Organisations must ascertain the vendor's processes for ensuring data quality, managing data privacy, and handling intellectual property rights associated with training data. Furthermore, understanding the degree of explainability the AI system offers, and the vendor's methods for documenting model decisions, is vital for regulatory compliance, auditability, and building user trust. Without clear answers in these areas, organisations risk inheriting significant legal, ethical, and reputational liabilities from their AI supply chain.

Sources

  • ISO/IEC 42001:2023, Clause 6.1.2
  • ISO/IEC 42001:2023, Clause 8.2.1
  • ISO/IEC 42001:2023, Clause 8.2.3

Related