AI & Computingarticle2026-08-30

AVRF: AI Vendor Risk Framework. The AI Vendor Due-Diligence Questionnaire

Open access2 citations

Abstract

This instrument is published to be taken and used. Any institution may issue this questionnaire, any vendor may answer it, and anyone may reproduce, translate, extend or embed it, including in commercial products, under CC BY 4.0 with attribution and without asking permission. That is the point of publishing it rather than a courtesy attached to it: a due-diligence questionnaire is useful in proportion to how many institutions ask the same questions, because a vendor that has answered once can answer again, and an institution can compare two vendors only if both were asked the same thing in the same form. Most of an institution's exposure to artificial intelligence arrives through a vendor boundary it cannot inspect. The model is not visible, the training data is not disclosed, the evaluation was performed by the party selling the result, and the institution's governance machinery stops at the contract. The instruments that exist do not close that gap: general third-party security questionnaires establish that a supplier manages information security, which is necessary and says nothing about what a model was trained on, how it was evaluated, whether it has failed before, or what happens when it is silently replaced. This specification publishes a questionnaire of fifty-six questions in seven sections: provenance and identity, training data, evaluation and performance, incident history, subprocessors and supply chain, model change and notification, and exit and portability. Every question carries a fixed answer format and a stated evidence expectation, which is what makes two completed questionnaires comparable rather than merely similar. Its central discipline is one line of bookkeeping. An answer supplied without its stated evidence is recorded as an assertion and must not be recorded as a finding. A vendor stating that its training data excludes a category is telling you what it believes or wishes to convey; a vendor stating it and attaching the provenance record is giving you something a third party could examine. Both are useful and they are not the same, and an institution that files them identically has lost the distinction at exactly the point where it matters. Declines are recorded with a reason rather than erased, because a pattern of declines is itself a finding and is invisible if declines become blanks. The questionnaire ships in four forms generated from one source, so they cannot disagree: this specification, a machine-readable form definition, a JSON Schema for validating a completed response, and a fillable spreadsheet. A scoring appendix is provided and is explicitly informative, because a score expresses a risk appetite and a scheme published as normative would assert an appetite on behalf of every institution using it. The specification states what it does not do. It elicits answers and evidence; it does not establish that the answers are true. It does not assess security posture, financial standing, or the permissibility of a vendor's products. No institution unconnected to the author has been observed issuing it and no vendor has answered it, which means its central property, comparability across vendors, is one it can only acquire through use by parties other than its author, and it does not have it yet. The author operates a consulting practice performing vendor assessments, which is a conflict of interest stated in the document and only partly mitigated by giving the instrument away. It is a specification and an instrument, not a certification scheme. Completing it is not a certification and must not be represented as one.

// Source

View paper (DOI)Open access versionOpenAlexZenodo (CERN European Organization for Nuclear Research)Published 2026-08-30

Authors: Nabeel A. Khan

Institutions: Instituto Superior Manuel Teixeira Gomes