Job to be done · Vendor due diligence

Ask before the contract, not after the audit.

Buying an AI tool moves the technology, not the duty. The questions that matter are answerable in a sales call — can you produce the instructions for use, what is the intended purpose, what model sits underneath — and unanswerable a year later when the system is embedded.

No card · EU-hosted · 5 minutes to a first classification
Veritome evidence register — files with fingerprints, the clauses each satisfies, scope and status
The reality

What procurement misses.

What we hear

“We asked for their SOC 2 and stopped there.”

What the product does

A security attestation says the vendor can hold data safely. It says nothing about whether you can operate the system lawfully, which is a different question with a different answer.

What we hear

“The contract was signed before anyone asked about the model.”

What the product does

The general-purpose model underneath can change the behaviour you assessed. Asking afterwards means renegotiating; asking first means choosing.

What we hear

“The vendor told us it was not high-risk.”

What the product does

Their classification governs their duties. Yours follows how you deploy it — the same model can be limited risk in their catalogue and Annex III high-risk in your process.

What you get

A record that outlives the sales call.

01

The instructions, or the gap

Log the Art. 13 package the vendor supplied and hold a dated receipt. Where nothing arrived, the absence is visible rather than assumed.

02

Intended purpose, written down

The purpose the vendor states is the purpose you are permitted to use it for. Recording it makes a later drift a visible change rather than an accident.

03

The model underneath, named

What general-purpose model, on what terms, and what happens if it changes. A dependency nobody wrote down is one nobody revisits.

04

Your duties, separated from theirs

The engine gives you the deployer set. Provider conformity is their obligation; oversight, input data and logs are yours whatever their paperwork says.

05

Evidence filed once

The due-diligence record is credited to every obligation it evidences rather than re-uploaded per duty.

06

Ready for the next buyer

When your own customers run a security review on you, the same register answers it.

In practice

Three purchases, three questions that mattered.

Use case 01

An HR team buying a CV-screening tool.

  • Annex III point 4 applies to how they will deploy it, not how it is sold.
  • The Art. 13 instructions are requested before signature, not after.
  • Oversight and the Art. 26(7) worker notice are planned into the rollout.
  • The vendor's CE claim is recorded, not relied on as their compliance.
Veritome obligations register — EU AI Act and GDPR duties per system and for the organisation, with owners, dates and status
Use case 02

A product team embedding a third-party model.

  • Which GPAI model, on what terms, and notice if it changes.
  • Whether embedding it makes them a provider under Art. 25.
  • The intended purpose recorded, so drift becomes visible.
  • The answer changes the price of the decision, so it is asked first.
Veritome guided classification — the register wizard that walks Article 5, Annex I, Annex III and the Article 6(3) exception
Use case 03

A firm renewing a tool bought before the Act applied.

  • Renewal is the natural moment to classify what was never classified.
  • The instructions for use are requested as a condition of renewal.
  • Duties that were always theirs are recorded rather than discovered.
  • Where the vendor cannot answer, that is itself the finding.
Veritome evidence register — files with fingerprints, the clauses each satisfies, scope and status
Also included

What sits either side of the purchase.

Straight answers

Straight answers on due diligence.

What is the single most important thing to ask a vendor?

For the instructions for use. Article 13 obliges the provider of a high-risk system to supply them, and Article 26 obliges you to use the system in accordance with them. If they cannot produce the document, you cannot discharge your own duty — and that gap is yours to carry, not theirs.

Is a CE mark enough?

No. A CE mark is a claim the provider makes about their own conformity. It says nothing about your oversight arrangements, your input data, your logging or your worker notification, all of which remain yours under Article 26.

The vendor says they are not high-risk. Do we accept that?

Their classification governs their duties, not yours. Risk class follows the intended purpose and the deployment, so the same model can be limited risk in one use and Annex III high-risk in another. Classify the system as you will actually use it.

What about GPAI models underneath the product?

Ask what general-purpose model sits underneath and on what terms, because a change there can change the behaviour you assessed. Record the answer — a dependency you did not write down is one nobody revisits when it moves.

Where does this fit with security questionnaires?

Beside them, not inside them. A security review asks whether the vendor can keep data safe; this asks whether the system can be operated lawfully. Both matter and neither substitutes for the other.