A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 26 scored requirements, a compliance score band, and a priority action plan.
For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.
Executive Summary
Organisations increasingly procure AI-enabled tools and services --- from chatbots and analytics platforms to HR screening and credit-scoring systems. Responsible procurement requires data protection, AI governance and cybersecurity due diligence to be embedded before any contract is signed, informed by the Data Protection Act, 2019, sectoral guidance, and emerging frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide procurement, legal and technology teams through vendor due diligence, contractual safeguards and internal governance approval for AI system acquisitions.
How to Use This Checklist
This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.
Ai Procurement Assessment
| No. | Requirement | Yes | Partial | No | N/A |
|---|---|---|---|---|---|
| 01 | Business case and use case for the AI system clearly defined | ☐ | ☐ | ☐ | ☐ |
| 02 | AI system classified by risk level (e.g. minimal, limited, high risk) | ☐ | ☐ | ☐ | ☐ |
| 03 | Data Protection Impact Assessment conducted where required | ☐ | ☐ | ☐ | ☐ |
| 04 | Vendor\'s data protection compliance status verified | ☐ | ☐ | ☐ | ☐ |
| 05 | Vendor\'s registration or accreditation status verified (where applicable) | ☐ | ☐ | ☐ | ☐ |
| 06 | Training data sources and provenance disclosed by the vendor | ☐ | ☐ | ☐ | ☐ |
| 07 | Vendor confirms lawful basis for any personal data used to train the model | ☐ | ☐ | ☐ | ☐ |
| 08 | Data flows between the organisation and the vendor mapped | ☐ | ☐ | ☐ | ☐ |
| 09 | Cross-border data transfer arrangements assessed | ☐ | ☐ | ☐ | ☐ |
| 10 | Contractual data processing terms included in the procurement agreement | ☐ | ☐ | ☐ | ☐ |
| 11 | Vendor\'s security certifications and controls reviewed | ☐ | ☐ | ☐ | ☐ |
| 12 | Vendor\'s incident and breach notification obligations defined in the contract | ☐ | ☐ | ☐ | ☐ |
| 13 | Model accuracy, bias and fairness testing evidence requested | ☐ | ☐ | ☐ | ☐ |
| 14 | Explainability and transparency of AI outputs assessed | ☐ | ☐ | ☐ | ☐ |
| 15 | Human oversight and override mechanisms confirmed | ☐ | ☐ | ☐ | ☐ |
| 16 | Right to human review of automated decisions provided to data subjects | ☐ | ☐ | ☐ | ☐ |
| 17 | Intellectual property and data ownership terms clarified | ☐ | ☐ | ☐ | ☐ |
| 18 | Sub-processor and fourth-party AI vendor arrangements disclosed | ☐ | ☐ | ☐ | ☐ |
| 19 | Vendor\'s data retention and deletion practices confirmed | ☐ | ☐ | ☐ | ☐ |
| 20 | Exit strategy and data portability provisions included in the contract | ☐ | ☐ | ☐ | ☐ |
| 21 | Ongoing monitoring and audit rights secured in the contract | ☐ | ☐ | ☐ | ☐ |
| 22 | Internal AI governance policy applied to the procurement decision | ☐ | ☐ | ☐ | ☐ |
| 23 | Employees and users trained on appropriate use of the AI system | ☐ | ☐ | ☐ | ☐ |
| 24 | Vendor liability and indemnity provisions reviewed | ☐ | ☐ | ☐ | ☐ |
| 25 | Regulatory or sectoral approval obtained where required | ☐ | ☐ | ☐ | ☐ |
| 26 | Procurement decision approved by the appropriate governance or board committee | ☐ | ☐ | ☐ | ☐ |
Compliance Score
Aggregate the ratings above to determine the organisation's overall compliance posture:
| Score | Assessment |
|---|---|
| 23 – 26 | Excellent |
| 18 – 22 | Good |
| 11 – 17 | Fair |
| 0 – 10 | Immediate Remediation Required |
Priority Action Plan
Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.
Overall Assessment
Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.
