Skip to the content.

Vendor Intake Checklist

What an HR AI vendor must hand over before you sign, renew, or deploy. Use this for any tool that scores, ranks, recommends, screens, summarizes, or otherwise influences decisions about workers or candidates in the EU.

If you haven’t picked a vendor yet, or you’re deciding whether to build instead, start with the build vs. buy and vendor selection framework first.

Not legal advice. Pair with Legal, Privacy, and Procurement review.

How to use

Required artifacts

1. Instructions for use (Article 13)

The vendor must provide written instructions covering:

Red flag: vendor provides marketing material instead of instructions for use, or instructions are not version-locked to the model.

2. Technical documentation summary (Annex IV)

You do not need the full technical file. You need a summary that lets you and your auditors verify the system is what the vendor claims.

Red flag: vendor refuses to share any part of the technical documentation summary, even under NDA.

3. Conformity assessment status

For high-risk systems, the vendor must complete a conformity assessment before placing on the market.

Red flag: vendor claims the system is not high-risk without written analysis, or the declaration of conformity is for a different version than what you are buying.

4. Logging posture

The deployer needs logs to meet Article 26(6). The vendor must enable them.

Red flag: logs are not exportable, retention is hard-capped below six months, or logs are aggregated in a way that prevents per-decision review.

5. Human oversight guidance

The vendor must explain how a human is meant to oversee the system in practice. Generic “humans can override” language is not enough.

Red flag: oversight is described as a checkbox in the UI with no supporting context.

6. Fairness and accuracy evidence

Red flag: vendor reports aggregate accuracy only, refuses to break down performance, or has no drift monitoring.

7. Deployer support commitments

Red flag: vendor disclaims all responsibility for supporting deployer compliance, treats compliance support as a premium tier, or refuses to take a position on Article 22 controller status.

8. Incident reporting

Red flag: incident definition is narrower than the AI Act post-market monitoring concept, or the vendor only commits to “commercially reasonable” notification.

Use the incident report template internally regardless of what the vendor commits to, it’s your record even when the root cause is on their side.

Procurement red flag summary

Any of the following means stop and escalate before signing: