AI Vendor Due Diligence Checklist: 30 Questions Your SIG and CAIQ Miss
30 questions a standard SIG Lite or CAIQ never asks an AI vendor: where the model runs, who trained it, how the vendor logs a single AI decision for audit, what is behind the vendor in the AI supply chain, and where the EU AI Act obligations land. This checklist covers model provenance, identity and access, data flow, logging and audit, regulatory mapping, and the AI supply chain, the AI-specific surface a SaaS vendor review leaves untouched. It is designed to be added to an existing vendor-risk workflow without replacing it.