Third-party AI
EU AI Act supplier assurance questionnaire
A useful supplier questionnaire asks for facts and evidence relevant to the system your organisation will actually use. It should not reward long generic answers or treat supplier self-declaration as verification.
Prepared by EU AI Fit editorial team · Published 24 August 2026 · Source review 31 August 2026
Product, role and value chain
Identify the legal supplier, product, model and version; who places the system on the market; intended purpose; contractual responsibilities; downstream information; and any authorised representative or distributor relationship.
Risk, data and technical controls
Ask for the supplier's classification rationale, prohibited-practice screening, data-governance approach, testing, known limitations, accuracy claims, cybersecurity controls, logging and human-oversight instructions.
- Evidence supporting performance claims
- Known failure modes and affected groups
- Personal-data and retention facts
- Security and incident processes
- Technical documentation available to the customer
Transparency, support and change
Establish required disclosures, content marking, customer instructions, complaint routes, monitoring support, incident notification, subcontractors and how model or product changes will be communicated.
Review the response, not just completion
Record missing evidence, contradictions, conditions of use, corrective actions and a reassessment date. Approve, approve conditionally or decline through an authorised reviewer, keeping the response connected to every relying AI system.
Recommended next step
Tailor the questionnaire to one real system and decision, then retain the supplier response, reviewer findings, conditions and reassessment trigger together.
Run the free exposure checkRelated practical guides
Put the guidance into practice