Compliance Toolkit/AI Procurement Checklist
KPLR/CHK/004/2026 Standalone Checklist AI Governance
Compliance Toolkit · Standalone Checklist

AI Procurement Checklist

A Practical Vendor & Governance Assessment Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
26 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 26 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Organisations increasingly procure AI-enabled tools and services --- from chatbots and analytics platforms to HR screening and credit-scoring systems. Responsible procurement requires data protection, AI governance and cybersecurity due diligence to be embedded before any contract is signed, informed by the Data Protection Act, 2019, sectoral guidance, and emerging frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide procurement, legal and technology teams through vendor due diligence, contractual safeguards and internal governance approval for AI system acquisitions.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Ai Procurement Assessment

No.RequirementYesPartialNoN/A
01Business case and use case for the AI system clearly defined
02AI system classified by risk level (e.g. minimal, limited, high risk)
03Data Protection Impact Assessment conducted where required
04Vendor\'s data protection compliance status verified
05Vendor\'s registration or accreditation status verified (where applicable)
06Training data sources and provenance disclosed by the vendor
07Vendor confirms lawful basis for any personal data used to train the model
08Data flows between the organisation and the vendor mapped
09Cross-border data transfer arrangements assessed
10Contractual data processing terms included in the procurement agreement
11Vendor\'s security certifications and controls reviewed
12Vendor\'s incident and breach notification obligations defined in the contract
13Model accuracy, bias and fairness testing evidence requested
14Explainability and transparency of AI outputs assessed
15Human oversight and override mechanisms confirmed
16Right to human review of automated decisions provided to data subjects
17Intellectual property and data ownership terms clarified
18Sub-processor and fourth-party AI vendor arrangements disclosed
19Vendor\'s data retention and deletion practices confirmed
20Exit strategy and data portability provisions included in the contract
21Ongoing monitoring and audit rights secured in the contract
22Internal AI governance policy applied to the procurement decision
23Employees and users trained on appropriate use of the AI system
24Vendor liability and indemnity provisions reviewed
25Regulatory or sectoral approval obtained where required
26Procurement decision approved by the appropriate governance or board committee

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
23 – 26Excellent
18 – 22Good
11 – 17Fair
0 – 10Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.