What procurement misses.
A record that outlives the sales call.
Three purchases, three questions that mattered.
An HR team buying a CV-screening tool.
- Annex III point 4 applies to how they will deploy it, not how it is sold.
- The Art. 13 instructions are requested before signature, not after.
- Oversight and the Art. 26(7) worker notice are planned into the rollout.
- The vendor's CE claim is recorded, not relied on as their compliance.
A product team embedding a third-party model.
- Which GPAI model, on what terms, and notice if it changes.
- Whether embedding it makes them a provider under Art. 25.
- The intended purpose recorded, so drift becomes visible.
- The answer changes the price of the decision, so it is asked first.
A firm renewing a tool bought before the Act applied.
- Renewal is the natural moment to classify what was never classified.
- The instructions for use are requested as a condition of renewal.
- Duties that were always theirs are recorded rather than discovered.
- Where the vendor cannot answer, that is itself the finding.
What sits either side of the purchase.
Straight answers on due diligence.
What is the single most important thing to ask a vendor?
For the instructions for use. Article 13 obliges the provider of a high-risk system to supply them, and Article 26 obliges you to use the system in accordance with them. If they cannot produce the document, you cannot discharge your own duty — and that gap is yours to carry, not theirs.
Is a CE mark enough?
No. A CE mark is a claim the provider makes about their own conformity. It says nothing about your oversight arrangements, your input data, your logging or your worker notification, all of which remain yours under Article 26.
The vendor says they are not high-risk. Do we accept that?
Their classification governs their duties, not yours. Risk class follows the intended purpose and the deployment, so the same model can be limited risk in one use and Annex III high-risk in another. Classify the system as you will actually use it.
What about GPAI models underneath the product?
Ask what general-purpose model sits underneath and on what terms, because a change there can change the behaviour you assessed. Record the answer — a dependency you did not write down is one nobody revisits when it moves.
Where does this fit with security questionnaires?
Beside them, not inside them. A security review asks whether the vendor can keep data safe; this asks whether the system can be operated lawfully. Both matter and neither substitutes for the other.


