AI Vendor Due Diligence Checklist
Comprehensive Assessment for AI Tool Procurement
Vendor Name:
Product / Service:
Assessment Date:
Assessor:
About This Checklist
This checklist provides a structured framework for evaluating AI vendors and tools before procurement. It covers data handling, security, compliance, AI-specific risks, contractual terms, and Singapore-specific regulatory requirements. Use it to identify risks, compare vendors, and ensure your organisation meets its obligations under the PDPA and emerging AI governance standards.
How to Use This Checklist
Complete one checklist per AI vendor or product under evaluation
Request supporting documentation from the vendor for each item
Mark each item as you verify compliance
Use the scoring guide at the end to determine overall risk level
Review the Red Flags section for automatic disqualifiers
Important: This checklist covers 31 due diligence items across 6 key assessment areas. Vendors should be able to provide evidence or documentation for each item. Inability or refusal to answer should be treated as a risk indicator.
1. Data Handling & Privacy
1.1 Data Storage & Processing
Data storage locations clearly documented (country and data centre provider)
Data processing locations identified, including any sub-processing in third countries
Data retention policies defined with specific retention periods per data category
1.2 Data Control & Transfers
Data deletion capabilities confirmed, including permanent erasure from backups
Cross-border transfer safeguards in place (contractual clauses, adequacy assessments)
Data ownership terms explicitly state that customer data remains customer property
2. Security & Infrastructure
2.1 Encryption & Certification
Encryption implemented for data at rest (AES-256 or equivalent) and in transit (TLS 1.2+)
SOC 2 Type II and/or ISO 27001 certification current and available for review
Role-based access controls with least-privilege principles enforced
2.2 Resilience & Testing
Documented incident response plan with defined escalation procedures and timelines
Penetration testing conducted at least annually by independent third parties
Backup and disaster recovery plan with defined RTO and RPO targets
3. Compliance & Legal
3.1 Regulatory Compliance
PDPA compliance documentation provided, including data protection policies and practices
Data Processing Agreement (DPA) available and aligned with PDPA requirements
Liability and indemnification terms clearly defined for data breaches and non-compliance
3.2 Audit & Breach Response
Vendor supports regulatory audits and provides access to compliance records on request
Breach notification timeline defined (must notify within 72 hours or as required by PDPA)
4. AI-Specific Assessment
4.1 Transparency & Fairness
Model transparency and explainability documentation available (model cards, decision logic)
Bias testing and monitoring processes in place with documented results
Human override capabilities available for automated decisions affecting individuals
4.2 Data Provenance & Quality
Training data provenance documented, including sources, consent basis, and data rights
Output accuracy metrics published or available, with ongoing performance monitoring
Version control and model update processes defined, with change notification to customers
5. Contractual Terms
5.1 Service & Exit
SLA guarantees documented (uptime, response time, support availability)
Exit and migration provisions defined, including data export format and transition support
5.2 Rights & Disclosure
IP rights for AI-generated outputs clearly assigned to the customer
Subprocessor list disclosed, with notification of changes and right to object
6. Singapore-Specific Requirements
6.1 Local Compliance
Local data residency option available (data can be stored within Singapore)
PDPC registration and compliance status verified
6.2 Governance & Support
Alignment with IMDA Model AI Governance Framework demonstrated
Support available during Singapore business hours (SGT, UTC+8) with local escalation path
Scoring Guide
Count the number of checked items from all 6 sections above (31 items total):
25 - 31 items checked = Low Risk: Vendor demonstrates strong due diligence readiness. Proceed with standard contract review.
18 - 24 items checked = Medium Risk: Gaps identified. Request remediation plan from vendor before proceeding. Consider additional contractual protections.
Below 18 items checked = High Risk: Significant concerns. Consider alternative vendors or require substantial risk mitigation measures before engagement.
Red Flags: Automatic Disqualifiers
The following issues should be treated as automatic red flags regardless of overall score. Any one of these warrants serious reconsideration of the vendor:
No Data Processing Agreement (DPA): Vendor refuses or is unable to provide a DPA
Data stored in sanctioned or high-risk countries: Data processed or stored in jurisdictions with inadequate data protection
No breach notification commitment: Vendor has no defined timeline or process for notifying customers of data breaches
No data deletion capability: Vendor cannot permanently delete customer data upon request or contract termination
Customer data used for model training without consent: Vendor uses customer input data to train or improve models without explicit opt-in
No human override for automated decisions: AI system makes consequential decisions with no mechanism for human review or intervention
Assessor Notes
Overall Risk Rating: ________________ Recommendation: ________________
Key Concerns:
Document Version: 1.0 | Last Updated: February 2026
Prepared by: DataCare Solutions Pte. Ltd.
© 2026 DataCare Solutions Pte. Ltd. All rights reserved.
This checklist is for informational purposes only and does not constitute legal advice.