DataCare Solutions
DataCare Solutions Pte. Ltd.
UEN: 202530943R
Website: www.datacaresolutions.biz
Email: info@datacaresolutions.biz

AI Vendor Due Diligence Checklist

Comprehensive Assessment for AI Tool Procurement

Vendor Name:
Product / Service:
Assessment Date:
Assessor:

About This Checklist

This checklist provides a structured framework for evaluating AI vendors and tools before procurement. It covers data handling, security, compliance, AI-specific risks, contractual terms, and Singapore-specific regulatory requirements. Use it to identify risks, compare vendors, and ensure your organisation meets its obligations under the PDPA and emerging AI governance standards.

How to Use This Checklist

Complete one checklist per AI vendor or product under evaluation
Request supporting documentation from the vendor for each item
Mark each item as you verify compliance
Use the scoring guide at the end to determine overall risk level
Review the Red Flags section for automatic disqualifiers

Important: This checklist covers 31 due diligence items across 6 key assessment areas. Vendors should be able to provide evidence or documentation for each item. Inability or refusal to answer should be treated as a risk indicator.

DataCare Solutions Pte. Ltd. | UEN: 202530943R | www.datacaresolutions.biz | info@datacaresolutions.biz

1. Data Handling & Privacy

1.1 Data Storage & Processing

Data storage locations clearly documented (country and data centre provider)
Data processing locations identified, including any sub-processing in third countries
Data retention policies defined with specific retention periods per data category

1.2 Data Control & Transfers

Data deletion capabilities confirmed, including permanent erasure from backups
Cross-border transfer safeguards in place (contractual clauses, adequacy assessments)
Data ownership terms explicitly state that customer data remains customer property

2. Security & Infrastructure

2.1 Encryption & Certification

Encryption implemented for data at rest (AES-256 or equivalent) and in transit (TLS 1.2+)
SOC 2 Type II and/or ISO 27001 certification current and available for review
Role-based access controls with least-privilege principles enforced

2.2 Resilience & Testing

Documented incident response plan with defined escalation procedures and timelines
Penetration testing conducted at least annually by independent third parties
Backup and disaster recovery plan with defined RTO and RPO targets

3. Compliance & Legal

3.1 Regulatory Compliance

PDPA compliance documentation provided, including data protection policies and practices
Data Processing Agreement (DPA) available and aligned with PDPA requirements
Liability and indemnification terms clearly defined for data breaches and non-compliance

3.2 Audit & Breach Response

Vendor supports regulatory audits and provides access to compliance records on request
Breach notification timeline defined (must notify within 72 hours or as required by PDPA)

4. AI-Specific Assessment

4.1 Transparency & Fairness

Model transparency and explainability documentation available (model cards, decision logic)
Bias testing and monitoring processes in place with documented results
Human override capabilities available for automated decisions affecting individuals

4.2 Data Provenance & Quality

Training data provenance documented, including sources, consent basis, and data rights
Output accuracy metrics published or available, with ongoing performance monitoring
Version control and model update processes defined, with change notification to customers

5. Contractual Terms

5.1 Service & Exit

SLA guarantees documented (uptime, response time, support availability)
Exit and migration provisions defined, including data export format and transition support

5.2 Rights & Disclosure

IP rights for AI-generated outputs clearly assigned to the customer
Subprocessor list disclosed, with notification of changes and right to object

6. Singapore-Specific Requirements

6.1 Local Compliance

Local data residency option available (data can be stored within Singapore)
PDPC registration and compliance status verified

6.2 Governance & Support

Alignment with IMDA Model AI Governance Framework demonstrated
Support available during Singapore business hours (SGT, UTC+8) with local escalation path
DataCare Solutions
DataCare Solutions Pte. Ltd.
UEN: 202530943R
Website: www.datacaresolutions.biz
Email: info@datacaresolutions.biz

Scoring Guide

Count the number of checked items from all 6 sections above (31 items total):


25 - 31 items checked = Low Risk: Vendor demonstrates strong due diligence readiness. Proceed with standard contract review.
18 - 24 items checked = Medium Risk: Gaps identified. Request remediation plan from vendor before proceeding. Consider additional contractual protections.
Below 18 items checked = High Risk: Significant concerns. Consider alternative vendors or require substantial risk mitigation measures before engagement.

Red Flags: Automatic Disqualifiers

The following issues should be treated as automatic red flags regardless of overall score. Any one of these warrants serious reconsideration of the vendor:


No Data Processing Agreement (DPA): Vendor refuses or is unable to provide a DPA
Data stored in sanctioned or high-risk countries: Data processed or stored in jurisdictions with inadequate data protection
No breach notification commitment: Vendor has no defined timeline or process for notifying customers of data breaches
No data deletion capability: Vendor cannot permanently delete customer data upon request or contract termination
Customer data used for model training without consent: Vendor uses customer input data to train or improve models without explicit opt-in
No human override for automated decisions: AI system makes consequential decisions with no mechanism for human review or intervention

Assessor Notes

Overall Risk Rating: ________________    Recommendation: ________________


Key Concerns:

 

 

 

Using this checklist

AI governance is not something DataCare Solutions sells as a separate service. Our free AI governance guide explains how to weigh what this checklist turns up, including which findings should stop a procurement. Where a vendor processes personal data on your behalf, the disclosure and transfer questions sit inside your PDPA obligations and are handled through the outsourced DPO engagement.


DataCare Solutions Pte. Ltd.

Website: www.datacaresolutions.biz
Email: info@datacaresolutions.biz

Document Version: 1.0 | Last Updated: February 2026
Prepared by: DataCare Solutions Pte. Ltd.

© 2026 DataCare Solutions Pte. Ltd. All rights reserved.
This checklist is for informational purposes only and does not constitute legal advice.