
In 2026, every procurement file with an "AI" label triggers the same question. Specifically: "Have we done the vendor risk assessment?" Meanwhile, most teams discover they have no defensible process to answer.
Today, this is the single fastest-growing compliance gap we see across global clients. Furthermore, the EU AI Act, GDPR, and enterprise buyers all demand evidence, not assertions.
Below is the methodology our team uses when onboarding any new AI vendor.
Why AI vendor risk is different
To begin with, AI vendors do not behave like traditional SaaS suppliers. Specifically, they:
- Train on your data unless contractually restricted.
- Route inference through unknown geographic regions.
- Update models without notice or version control.
- Subcontract compute to hyperscalers in multiple jurisdictions.
Consequently, a single AI procurement decision can trigger a GDPR Article 28 processor obligation, an EU AI Act classification, a cross-border transfer, and a DPIA simultaneously. As a result, treating AI vendors like any other SaaS purchase is no longer defensible.
Step 1: Classify the AI system before you sign
First, classify the system using the EU AI Act risk tiers. Specifically:
- Prohibited — social scoring, untargeted facial scraping, etc.
- High-risk — recruitment, credit, biometric ID, critical infrastructure, education.
- Limited-risk — chatbots and content generators with transparency duties.
- Minimal-risk — spam filters, basic analytics.
For deeper context on how to map systems and entities, see our EU AI Act Entity and System Risk Matrix guide. Furthermore, the official EU AI Act portal sets out Article 6 classification rules.
Step 2: Run a parallel DPIA and AI assessment
Next, every AI deployment processing personal data triggers a DPIA under GDPR Article 35. However, a standard DPIA is not enough. Instead, AI requires a parallel risk lens covering bias, hallucination, automation bias, and explainability. We cover the methodology in detail in our AI and GDPR compliance guide.
Importantly, high-risk systems also require a Fundamental Rights Impact Assessment (FRIA). Therefore, your assessment pack must include both DPIA and FRIA outputs.
Step 3: Audit the vendor's contractual position
Then, audit the vendor's contractual stance. In practice, that means asking five questions:
- Are you the provider or the deployer under the EU AI Act?
- Where do training data, inference data, and logs physically reside?
- Will my data be used to train or fine-tune any model?
- What transparency information do you publish under Article 13?
- What human oversight mechanism do you support?
Crucially, missing answers are red flags, not negotiating positions. For boards needing a wider lens, our AI Governance for Boards article provides a strategic perspective.
Step 4: Lock in AI literacy
Equally, Article 4 of the EU AI Act imposes an AI literacy obligation on every deployer. Therefore, your procurement, HR, and operational teams must be documented as trained.
For a structured approach across borders, see our guide on AI governance practical steps under GDPR, PDPA, FADP and the EU AI Act.
How the three-team model accelerates the process
At Formiti, AI vendor assessments are delivered by three coordinated teams.
- The Legal Team redlines vendor contracts, DPAs, and AI provider clauses to close supply-chain risk.
- The Privacy Team runs the DPIA, FRIA, and transfer assessment in parallel.
- The Operations Team maintains the evidence trail and the literacy records auditors will request.
As a result, a vendor that would traditionally take six weeks to onboard typically clears in ten days. Moreover, every output sits in audit-ready form from day one.
For a packaged engagement, see our AI Vendor Risk Management service and the recently launched AI Governance Add-on to the Outsourced DPO service.
Where Privacy360 fits
In parallel, the Privacy360 platform operationalises every output. Specifically, the Privacy360 AI Governance & Risk module, aligned to the NIST AI RMF, classifies systems and tracks remediation. Equally, the Vendor Assessment Module flags weak responses in real time, while the Cross-Border Transfer Impact module maps data flows by jurisdiction.
Therefore, when a regulator or enterprise buyer asks "show me the assessment," you generate it in one click.
Key takeaway
In short, AI vendor risk is now a procurement gate, not a privacy afterthought. Consequently, the organisations winning enterprise deals in 2026 are those with a defensible, documented assessment process. To accelerate yours, book a discovery call with Formiti or explore the AI Vendor Risk Management service.