In short
- 12 questions, grouped in 4 areas: documentation, incident cooperation, credentials, and change notice.
- Article 25(2) obliges an original provider to cooperate if you become the provider, which is the hook for asking about the Annex IV pack before signing.
- Article 73 gives as little as 2 days to notify. A vendor whose support SLA is 5 business days cannot help you meet it.
- The September 2026 threat report documents production API keys stolen from a vendor sandbox, which makes the credential storage question a security question rather than an administrative one.
- NIS2 Article 21 already requires supply chain security measures of essential and important entities, so for many buyers this is an existing duty rather than a new one.
What do AI assistants say about your organisation?
Model answers are becoming a channel your communications team does not control. EntityRise audits how assistants describe your company and whose name they give instead. From $19.
A standard AI vendor questionnaire asks whether the supplier has an AI policy. Every supplier has an AI policy.
The useful questions ask whether the supplier can hand you something, and how quickly.
01Why reframe the questionnaire around artefacts?
Because your obligations are discharged with documents, not with assurances.
If you become the provider of a high-risk system under Article 25, you owe Annex IV technical documentation, and you cannot write it for a system somebody else built. Article 25(2) obliges the original provider to cooperate and supply what is reasonably needed, but that duty crystallises after the fact. Before signing, it is a negotiation.
The same logic applies to incidents. Article 73 can require notification in two days. A supplier who will confirm facts within five business days has made that deadline unmeetable, and no clause about cooperation fixes a support process built for a different purpose.
02Which twelve questions?
| Area | Question | Why it matters |
|---|---|---|
| Documentation | Will you supply Annex IV documentation on request? | Article 25(2) cooperation, in advance |
| Documentation | What evaluation evidence exists, and dated when? | Annex IV points 3 and 4 |
| Documentation | Is the system classified high risk by you, and why? | Their classification constrains yours |
| Incidents | Notification time in hours, not business days? | Article 73 allows 2 days |
| Incidents | Who is the named contact out of hours? | Incidents do not start on Monday |
| Incidents | Will you supply logs, and in what format? | Article 73(6) investigation duty |
| Credentials | Where is our API key stored, and who can reach it? | Vendor sandbox key theft, 2026 |
| Credentials | Can the key be scoped below account level? | Limits blast radius to 1 project |
| Credentials | What is your rotation and revocation process? | NIS2 Article 21 access control |
| Change | How much notice before a model version changes? | Evaluations are version specific |
| Change | Can we pin a version, and for how long? | Stability of your own evidence |
| Change | What changed in the last 12 months? | Past behaviour predicts notice quality |
The last question is the cheapest signal in the list. A vendor that can produce a change history for the past year has one. A vendor that cannot will not produce one for you either.
03What separates a good answer from a compliant one?
| Question | Weak answer | Strong answer |
|---|---|---|
| Incident notification | Without undue delay | 24 hours, named contact, tested |
| Technical documentation | Available on request | Sample pack provided during evaluation |
| Credential storage | Encrypted at rest | Named store, 1 scope, rotation every 90 days |
| Version change notice | Customers are informed | 30 days, changelog, pinning available |
Every weak answer in that table is true and useless. Without undue delay is the legal standard, not a commitment. Available on request is a description of the postal system.
The strong answers share one property: a number a buyer can hold them to.
04Where does this sit against existing duties?
For many buyers it is not new work.
NIS2 Article 21 already requires essential and important entities to take measures covering supply chain security, including security related aspects of relationships with direct suppliers, and access control policies. An AI supplier holding a credential that grants inference at your expense is squarely inside that. For those organisations the AI vendor questionnaire is an extension of a register that exists.
For everyone else, the practical trigger is the first system that could plausibly be classified high risk, because that is the point at which the documentation questions stop being hypothetical.
05What should be done with the answers?
Kept, dated, and reread at renewal.
The value of the pack is not the decision to sign. It is having a record of what was represented, so that when a model version changes without notice or an incident is disclosed after nine days, the gap between the answer and the behaviour is documented rather than remembered.
That record is also the cheapest input to your own audit. An assurance function asked how supplier risk is managed can produce twelve questions, twelve dated answers per vendor, and a review cycle. That is a functioning control, and it fits on one page.
06Frequently asked questions
What should you ask an AI vendor about compliance?
Ask for artefacts rather than assurances. Whether they will supply Annex IV technical documentation on request, what their incident notification time is in hours, where any credential you give them is stored, and how much notice you get before a model version changes.
Why does vendor incident response time matter so much?
Because your own deadline can be two days. Article 73 requires notification within two days for a widespread infringement or serious disruption of critical infrastructure, and a vendor working to a five day support SLA cannot supply the facts in time.
Is a SOC 2 report enough for an AI supplier?
It is useful and it is not sufficient. A SOC 2 report addresses the control environment, not the AI specific artefacts your own obligations require, such as technical documentation, evaluation evidence and model version history.
What is the most overlooked question?
Where the credential you hand over is stored, and who can reach it. The September 2026 threat report describes production AI API keys being taken from a vendor sandbox, which is an exposure the buyer created by integrating and cannot see from outside.
07References and method
- Regulation (EU) 2024/1689, Article 25(2) for the cooperation duty, Annex IV for the technical documentation contents, and Article 73 for the notification deadlines.
- Directive (EU) 2022/2555 (NIS2), Article 21, for the supply chain security measures required of essential and important entities.
- Anthropic, Countering misuse of AI: September 2026, for the vendor sandbox case in which production AI API keys were obtained from a supplier environment.
- The twelve questions are editorial, prepared by The Guardrail. They are mapped to the obligations cited above and are not drawn from a published questionnaire standard.