Third-party AI

EU AI Act supplier assurance questionnaire

A useful supplier questionnaire asks for facts and evidence relevant to the system your organisation will actually use. It should not reward long generic answers or treat supplier self-declaration as verification.

Prepared by EU AI Fit editorial team · Published 24 August 2026 · Source review 31 August 2026

Product, role and value chain

Identify the legal supplier, product, model and version; who places the system on the market; intended purpose; contractual responsibilities; downstream information; and any authorised representative or distributor relationship.

Risk, data and technical controls

Ask for the supplier's classification rationale, prohibited-practice screening, data-governance approach, testing, known limitations, accuracy claims, cybersecurity controls, logging and human-oversight instructions.

  • Evidence supporting performance claims
  • Known failure modes and affected groups
  • Personal-data and retention facts
  • Security and incident processes
  • Technical documentation available to the customer

Transparency, support and change

Establish required disclosures, content marking, customer instructions, complaint routes, monitoring support, incident notification, subcontractors and how model or product changes will be communicated.

Review the response, not just completion

Record missing evidence, contradictions, conditions of use, corrective actions and a reassessment date. Approve, approve conditionally or decline through an authorised reviewer, keeping the response connected to every relying AI system.

Recommended next step

Tailor the questionnaire to one real system and decision, then retain the supplier response, reviewer findings, conditions and reassessment trigger together.

Run the free exposure check

Related practical guides

Put the guidance into practice

Continue your EU AI Act review