Skip to main content
Notifications
You're all caught up.
View all notifications
Backsplice
  • Product
  • Watney AI
  • Why us
  • Pricing
  • Docs
  • Security
  • About
  • Log in
  • Start your demo
Log in Start your demo
← Docs
← All documentation

Vendors and AI due diligence

The vendor register is included in Premium and Enterprise, and it works during
the demo too. The data
processing agreement between your organization and us is separate from the
agreements you record here.

Most of the AI an organization uses is bought, not built: an AI product, a model behind an API, or an AI feature switched on inside software you already use. The Vendors area tracks each third party, what AI it supplies, whether it trains on your data, and the agreement you hold with it, so a gap does not slip past you.

A vendor record

Each vendor holds its services, data access (none / limited / full), a risk level (low → critical), a status (active / under review / terminated), and two AI due-diligence answers:

  • AI supplied: no AI, AI inside another product, an AI product, or a model.
  • Trains on your data?: does not, trains unless you opt out, trains on your data, or not yet known. Not yet known is where every vendor starts. For a vendor that supplies AI it is flagged until the vendor's terms or questionnaire answer it, because it is the question due diligence exists to settle.

It also records the agreement you hold with the vendor (a data processing or AI services agreement): whether one is signed, the signed date and the expiry date.

The list flags vendors with no agreement and agreements expiring within 30 days, and shows, for each AI vendor, whether its training practice is unknown or whether it trains on your data. You can filter by what AI a vendor supplies and by its training practice.

The AI systems a vendor supplies

When you register an AI system you bought, choose its vendor on the system's page. The vendor's page then lists the systems it supplies, and the system's Approval page shows the vendor's AI supplied, training practice and agreement status to anyone reviewing it. A vendor that supplies a system cannot be deleted while a system names it: change the vendor on the system first, or mark the vendor terminated.

AI due-diligence questionnaires

Questionnaires send a vendor a set of questions through a secure link that needs no account. Start from one of three AI templates:

  • AI Vendor Due Diligence, for any vendor whose product uses AI on your behalf.
  • Generative AI Provider Assessment, for providers of generative models, assistants or APIs, following the risks in NIST AI 600-1.
  • AI Features in SaaS Products, a short review for software that has added AI.

You can edit the questions before sending. The vendor's answers are scored against the answer you prefer for each question, and you review and note the result.

The link works for 30 days. While the questionnaire waits for an answer you can Resend it, which emails a fresh link (to the same or a corrected address) and stops the earlier one working, or Revoke the link, after which the vendor's page shows an invalid link and accepts nothing. A revoked questionnaire can be resent later.

The vendor's answers never change the vendor record by themselves. When a submitted answer settles one of the record's fields (today, whether the vendor trains on your data), the questionnaire shows the record's current value beside what the answer means, and you tick the answer and apply it to record it. An answer that does not settle the field (for example, "not excluded from training by default", which does not say whether you can opt out) is shown with a note, and you set the field by hand. The vendor's page lists its questionnaires, with their status and the date each was sent or submitted, and says when the latest answers differ from the record.

Security assessment

Assess records your own security review of a vendor: fifteen questions on access control, encryption, incident response, audit logging, business continuity and third-party audits. Answers are scored 0–100, and the score sets the vendor's risk level (80 and above low, 60 medium, 40 high, below that critical). Running an assessment stamps the vendor's last review date.

Reviews and reminders

Set a next review date to schedule the next look; the list flags overdue reviews, and the compliance calendar surfaces upcoming agreement and vendor review dates alongside your other deadlines.

Who can do what

Anyone can view vendors. Contributors and admins can add, edit, and assess them. Only org admins can send, resend or revoke questionnaires, apply their answers to a vendor record (and see them on the vendor's page), bulk-import vendors, or bulk-archive and delete them. Auditors are read-only.

Backsplice

Governance for the AI systems your organization builds, buys and runs.

NIST AI RMF 1.0 NIST AI 600-1 (Generative AI Profile)

View our security posture →

Product

  • Why Backsplice
  • Frameworks
  • Watney AI
  • Review & Approval
  • Governance Registers
  • Reporting
  • Integrations & API
  • Pricing

Company

  • About Us
  • Team
  • Mission
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Data Processing Agreement
  • Security

Resources

  • Documentation
  • Blog
  • Status Page

© 2026 Backsplice LLC. All rights reserved.

Backsplice provides tools to run an AI governance program; it does not confer compliance with any law or standard and does not constitute legal advice. Consult qualified legal counsel for specific compliance guidance.