AI Vendor Due Diligence Checklist for Internal Audit Teams
AI vendor due diligence is the review of whether an external AI tool, model provider, SaaS platform or automation vendor can be used without creating unacceptable data, security, regulatory, operational, intellectual-property or audit-evidence risk. For internal audit, the review should cover both the vendor and the business process that will rely on the vendor's AI output.
This is not just an IT procurement checklist. If the AI vendor is used for finance, payroll, customer service, lending, claims, compliance, audit analytics or management reporting, internal audit should understand how the tool affects controls, evidence, accountability and incident response.
Quick AI vendor due diligence checklist
| Area | Internal audit question |
|---|---|
| Use case | What business decision, workflow or control will the AI tool support? |
| Data | What personal, financial, client, employee, customer or confidential data will be processed? |
| Hosting and retention | Where is data processed, how long is it retained and can it be deleted? |
| Training on data | Does the vendor use customer inputs or outputs to train models? |
| Security | Are access, encryption, logging, vulnerability management and incident response documented? |
| Model governance | Is the model version, update process, testing, limitation and human review model understood? |
| Accuracy and monitoring | How are errors, drift, hallucinations, false positives and user overrides monitored? |
| Explainability | Can the business explain why the AI output was used in a process or decision? |
| Contract rights | Are audit rights, breach notification, subcontractors, data return and exit clauses usable? |
| Regulatory fit | Does the tool create DPDP, sector regulation, client confidentiality or cross-border risk? |
| Business continuity | What happens if the vendor goes down, changes terms, removes a model or exits the market? |
| Evidence | What records can internal audit inspect later? |
The answer should be documented before critical AI use begins, not after an incident.
Why this matters in 2026
AI adoption has moved faster than governance. Gartner reported in August 2026 that 93% of audit leaders use some AI, but only 38% have an AI strategy. The same pattern exists in business teams: tools are adopted for speed, while vendor-risk, privacy, monitoring and exit controls lag behind.
NIST's AI Risk Management Framework is useful for internal audit because it names four practical functions: govern, map, measure and manage. Its AI RMF Core also calls out risks from third-party AI systems, software, data and supply-chain relationships. That is exactly where vendor due diligence sits.
NIST also published a July 2026 quick-start guide for cybersecurity supply-chain due diligence. It is scoped to ICT suppliers, but the structure is useful for AI vendors too: supplier due diligence should examine provenance, resilience, foundational cyber practices and supply-chain tiers.
AI vendor risk areas
1. Use-case and decision risk
Start by asking what the tool will actually do. A chatbot used to draft marketing copy is not the same risk as an AI tool used to approve credit, screen employees, draft audit observations or reconcile GST data.
Document:
- Business process
- User group
- Decision supported
- Whether output is advisory or operational
- Whether human approval is required
- Whether the output affects customers, employees, vendors, financial reporting or compliance
If nobody can explain the use case, the vendor should not be approved for production use.
2. Data privacy and confidentiality
For Indian companies and CA firms, AI vendor review must cover DPDP Act exposure, contractual confidentiality and sector-specific restrictions. The key question is not only "Is the vendor secure?" It is "Are we allowed to send this data to this vendor under this contract and this law?"
Review:
- Personal data categories
- Sensitive financial or client information
- Data-processing location
- Sub-processors
- Retention period
- Deletion controls
- User access to prompts, uploads and outputs
- Training-on-customer-data terms
- Breach notification timelines
Public AI tools may be acceptable for public or anonymised content. They are not automatically acceptable for payroll, customer, vendor, tax, ledger or client books.
3. Model governance
AI vendor due diligence should identify how the model is governed, tested and changed. Internal audit does not need source code for every model, but it does need enough transparency to understand risk.
Ask for:
- Model or model family used
- Versioning and release cadence
- Known limitations
- Evaluation approach
- Human review design
- Audit logs
- Incident and complaint handling
- Controls over model changes
- Whether customers are notified of material changes
If model changes can materially affect output, the business needs a monitoring and revalidation process.
4. Security and access controls
AI tools often create new access surfaces: browser extensions, API keys, plugins, file upload portals, connectors, shared workspaces and admin dashboards.
Test:
- SSO/MFA availability
- Role-based access
- Admin rights
- User provisioning and deprovisioning
- API key storage
- Connector permissions
- Logging and export controls
- Encryption in transit and at rest
- Vulnerability and patch management
- Security certifications or independent assessments
For internal audit, evidence matters. A vendor questionnaire is not enough for a critical tool. Ask for reports, attestations, logs, architecture summaries and contractual commitments where appropriate.
5. Contract, subcontractor and exit risk
Many AI vendor failures are contract failures. The tool looks useful, but the agreement does not protect data, preserve records, permit audit, restrict sub-processors or define exit support.
The contract should cover:
- Data ownership
- Confidentiality
- No training on customer data, where required
- Sub-processor disclosure and approval
- Right to audit or receive assurance reports
- Incident notification
- Data return and deletion
- SLA and support
- Model or feature discontinuation
- Termination assistance
- Survival of confidentiality and deletion obligations
Exit matters because AI tools can become embedded in workflows quickly. If a tool supports monthly monitoring, report drafting or compliance review, the entity should know how it will operate if the vendor is unavailable.
Internal audit procedures
| Procedure | Evidence to inspect |
|---|---|
| Build an AI vendor inventory | Procurement list, IT app inventory, expense claims, browser extensions, API keys and department tool lists |
| Classify criticality | Use case, data class, process dependency, user count, regulatory exposure and decision impact |
| Review due diligence | Vendor questionnaire, security documents, privacy terms, model documentation and legal review |
| Inspect contract controls | DPA, SLA, sub-processor terms, breach clause, audit rights, data return and termination support |
| Test access | User list, admin list, SSO/MFA, API keys, connector scopes and leaver removal |
| Test data handling | Upload logs, retention settings, deletion evidence, location, sub-processors and training terms |
| Review output governance | Human review evidence, override logs, quality checks, model-change notices and incident tickets |
| Test monitoring | Error reports, false-positive rates, complaints, drift checks, usage metrics and periodic review minutes |
| Assess exit readiness | Alternative process, data export, model dependency, termination checklist and continuity plan |
The output should feed the third-party risk register, AI inventory, internal audit annual plan and monitoring rules.
Red flags
- The vendor will not state whether customer data trains models
- No sub-processor list
- No enterprise retention or deletion controls
- No user access logs
- No model-change notification
- Tool is used in a critical process without human review
- Contract has no breach notification timeline
- Vendor refuses audit rights or assurance reports for a high-risk service
- Business owner cannot explain how output is reviewed
- AI output enters reports, letters, filings or workpapers without source support
AI vendor due diligence FAQ
What is AI vendor due diligence?
AI vendor due diligence is the review of an external AI tool or provider before and during use. It checks use case, data handling, security, model governance, contracts, subcontractors, monitoring, regulatory fit, business continuity and exit readiness.
Who should own AI vendor due diligence?
Ownership should sit with procurement, IT/security, legal/privacy and the business owner. Internal audit should assess whether the process works, test high-risk vendors and report control gaps. Internal audit should not become the owner of vendor onboarding.
What evidence should internal audit request for an AI vendor review?
Request the AI vendor inventory, use-case register, data-flow map, contract, data processing terms, security documents, sub-processor list, access logs, model documentation, incident reports, human-review evidence and exit plan.
Is NIST AI RMF mandatory in India?
No. NIST AI RMF is a voluntary framework. It is still useful for internal audit because its govern, map, measure and manage structure helps organise AI risk, including third-party AI systems and data.
Can a public LLM be approved as an AI vendor?
It can be approved for limited public or anonymised use if the contract, data rules and review controls are acceptable. It should not be used for personal data, client books, payroll, tax records or confidential company data unless the enterprise agreement and governance controls permit that use.
Related CORAA resources
- Third-Party Outsourcing Risk Internal Audit Checklist
- AI Governance Internal Audit Workpaper
- Internal Audit AI Strategy Template
- AI Audit Tool Evaluation Checklist
- Internal Audit Data Governance and Master Data Controls
Sources
- NIST AI Risk Management Framework
- NIST AI RMF Core, third-party AI risk outcomes
- NIST AI RMF Playbook, Manage 3 third-party AI risk
- NIST SP 1326, Cybersecurity Supply Chain Risk Management: Due Diligence Assessment Quick-Start Guide, July 2026
- Gartner, audit teams' AI use and strategy gap, 11 August 2026
- ICAI Internal Audit Standards Board, Compendium of Standards on Internal Audit