Is your vendor's AI safe with your data?
Build a questionnaire for any supplier that uses AI: what happens to your data, whether their AI agents can act on it, who approves those actions, how they're stopped and logged, and which models and sub-processors see it.
Everything stays in your browser. The files are created on your computer.
Areas
What's in it
- AI use on your data: 5 questions
- AI agents at your vendor: 10 questions
- Models, providers and data: 5 questions
- Governance and assurance: 5 questions
- EU AI Act: 2 questions
When the answers come back, score them with the AI Vendor Risk Assessment: load the returned spreadsheet and get a risk tier, red flags and the contract terms to ask for.
The 10 agent questions are also listed on AI agent questions for vendors.
Questions
Is anything I type saved or uploaded?
No. The questionnaire is built in this page and the files are created on your computer. The page blocks every outgoing request.
Why a section on AI agents?
Agents don't just answer; they act with real access. If a vendor's agents touch your data or systems, you need to know who approves their actions, how they can be stopped, what they log and which models and sub-processors they use.
How do I score the answers?
Download the spreadsheet, send it, and when it comes back load it into the AI Vendor Risk Assessment. The question references match, so each answer is scored automatically.
Is this legal advice?
No. It's a starting point. Adapt it to your contracts, your sector and the laws that apply to you.
Sources
- EU AI Act (Regulation (EU) 2024/1689), EUR-Lex: Article 4 (AI literacy, applying since 2 February 2025) and the high-risk classification rules.
- NIST AI Risk Management Framework
- Checked 28 September 2026.