Buyers treat these as two points on one scale, where the audit means serious and the questionnaire means light touch, and then choose by how important the supplier feels. They are not on one scale. They answer different questions. Choosing by importance is how an organisation ends up paying audit fees to settle a question a document would have settled, while sending a form to the one supplier whose answers nobody can check.
The useful question is not which instrument is stronger. It is which one can tell you the thing you actually need to know about this supplier.
What each one is
A supplier questionnaire is a set of questions you write and the supplier answers. The evidence is the supplier's own account of itself. Its virtues are real: it scales across a portfolio, it costs almost nothing, the answers are comparable between suppliers, and, if you do the one thing most buyers skip, it produces a record of what the supplier told you at a date you can point to.
A second-party audit is an audit you commission, of your supplier, against criteria you set. Second party means neither of the two familiar cases. It is not the supplier auditing itself, and it is not a certification body auditing the supplier in order to issue a certificate. The auditor is engaged by you and reports to you, which changes what gets sampled and which follow-up questions get asked.
In one line: a questionnaire tells you what the supplier says is true. An audit tells you what an auditor was able to evidence.
The right you almost certainly hold already
If your AI supplier processes personal data on your behalf, and most of them do, the audit right is already in your contract. UK GDPR Article 28(3)(h) requires the processor contract to oblige the processor to:
[make] available to the controller all information necessary to demonstrate compliance with the obligations laid down in this Article and allow for and contribute to audits, including inspections, conducted by the controller or another auditor mandated by the controller.
That clause is the legal definition of a second-party audit, sitting in domestic law, reproduced in the data processing schedule of nearly every supplier agreement signed in the UK since 2018. The question was never whether you are allowed to audit. It is whether it is worth doing.
The Information Commissioner's Office is direct about the standing obligation this sits inside. Its guidance for controllers using a processor states that "Controllers should ensure a processor's compliance on an ongoing basis, in order for them to satisfy the accountability principle and demonstrate due diligence."
The ICO's accountability framework then says what that looks like in practice, and the wording repays attention. It expects that "Contracts include clauses to allow your organisation to conduct audits or checks, to confirm the processor is complying with all contractual terms and conditions", and that "You carry out routine compliance checks, proportionate to the processing risks, to test that processors are complying with contractual agreements."
Audits or checks. Proportionate to the processing risks. That is the regulator, in writing, declining to require an audit of every supplier.
Where a form stops being enough
The ICO's AI and data protection audit framework toolkit is more demanding, and it is specifically about AI. Its expectation for procurement is that "Before procuring AI systems, datasets or coding, there has been appropriate due diligence undertaken on accuracy, bias and the trade-offs that have been considered in the design." Among the ways it lists of meeting that expectation:
- "Request comprehensive documentation from the model developer, including information on the training process, feature selection, hyperparameter tuning, and any constraints imposed on the model."
- "Obtain evidence of fairness assessments conducted during the model development."
- "Conduct an independent evaluation of any trade-offs as part of the due diligence process."
- "Engage independent third-party organisations or experts to conduct audits on your AI system."
Read those together and the shape of the problem appears. Accuracy, bias, trade-offs, training process, fairness assessments. Every one is a claim about work done inside the supplier before you arrived, and none of them is a control you can watch operating today.
This is why AI supplier assurance breaks a questionnaire in a way that ordinary security assurance does not. Ask "do you have multi-factor authentication on administrative accounts" and a yes is worth something, because it is a control that either runs or does not, and the supplier knows you can ask for a screenshot. Ask "have you assessed your model for bias" and a yes is worth very little. It is probably true. It is also compatible with a single assessment, run once, against two protected characteristics, on the developer's own evaluation set, eighteen months ago, on a model version that has since been retrained. The interesting information is entirely in the detail the form cannot reach.
Set against each other
| Supplier questionnaire | Second-party audit | |
|---|---|---|
| Who supplies the evidence | The supplier | The supplier, tested by your auditor |
| What it produces | A dated record of assertions | An opinion supported by sampled evidence |
| Cost and effort | Low, and it scales | Material, and per supplier |
| Comparable across a portfolio | Yes, by design | Only if the criteria are set once and reused |
| Needs supplier cooperation | Minimal | Substantial, and a refusal is itself a finding |
| Good at | Coverage, triage, contract evidence | Depth on a small number of specific questions |
| Poor at | Anything requiring a follow-up question | Breadth, speed and cost |
The position: send the questionnaire
Most organisations should send the questionnaire and stop there, and the ones that should go further are usually not the ones currently doing so.
The test in common use is criticality, or contract value, or both. It does not work. Criticality predicts how bad it will be if the supplier is wrong. It says nothing about whether an audit will find out. Plenty of high-spend, high-criticality suppliers have a straightforward assurance position that a document settles, and plenty of small ones sit on a question no document answers.
Three tests that do work, applied in order:
- Can the answer be evidenced by something the supplier could send you? A model card, an impact assessment, a monitoring report, a certificate with its scope statement, the fairness assessment the ICO toolkit asks for. If yes, ask for the artefact. An audit that ends in you reading a document the supplier would have emailed you is an expensive way to open an attachment.
- Does your risk sit outside what any certificate the supplier holds actually covers? Scope statements are published and specific. A certificate covering the supplier's management system for its core platform tells you very little about the model doing inference on your population.
- Will you behave differently depending on the answer? If the contract is signed, the system is embedded, and there is no realistic exit or renegotiation, an audit buys knowledge with no lever attached to it. Knowledge is not worthless. It is just worth less than the invoice.
Where all three point the same way, the audit earns its cost. That is a considerably smaller population of suppliers than the one being audited today, and saying so argues against this practice's own second-party audit work. It is still the right answer. Selling an audit to a buyer whose question a document would have answered is the quickest way to teach them that audits are theatre, and that lesson is expensive for everybody who comes after.
The step almost nobody takes
Article 28(1) requires a controller to use only a processor providing sufficient guarantees, and the ICO glosses that as guarantees "in particular in terms of its expert knowledge, resources and reliability".
A completed questionnaire sitting in a shared drive is not a guarantee of anything. It is a set of statements made by a party with no contractual exposure if they turn out to be wrong. The same answers, written into the agreement as representations, with an obligation to notify you if they cease to be accurate and a consequence if they do, are much closer to the thing the law is asking for.
Which produces a claim a practitioner can reasonably reject: for most AI suppliers, a questionnaire whose answers are contractual is worth more than an audit report filed alongside an unamended contract. The report is an opinion about one moment. The representation is a remedy. The two are usually bought by different functions, at different times, and never compared, which is why the choice rarely gets made on the merits.
The counter-argument is fair and worth stating. Warranties only help if you are prepared to enforce them, most buyers never will, and a supplier who is comfortable signing an inaccurate representation was never going to be caught by a form either. Where that describes your supplier relationship, test two above is doing the work, and the audit is the right purchase.
What changed this year, and why the audit's window is narrowing
For most of the time ISO/IEC 42001 has existed, a buyer wanting independent assurance of a supplier's AI management system had exactly one instrument available, because the third-party route was not yet operating. That has now changed, and the chain of dates is public.
ISO/IEC 42006:2025, the first edition of the standard setting requirements for bodies providing audit and certification of AI management systems, was published in July 2025 and runs to 31 pages. It is the rulebook the certification bodies themselves are assessed against. UKAS announced on 15 January 2026 that it "has granted BSI the first accreditation for certification of artificial intelligence (AI) management systems to ISO/IEC 42001:2023."
So the answer to "is anybody independently checking this supplier" now has a route that did not exist eighteen months ago. Where a supplier is inside an accredited certification process, the buyer's most useful question is whether the specific system creating your risk falls inside the certificate scope, and that is a question a form can carry.
What the second-party audit retains is the residual, and the residual is not small. A management system certificate is an opinion about a system of management. It is not an opinion about how one model behaves on your population, which is most of the accuracy, bias and trade-off ground the ICO toolkit asks buyers to cover. That ground has no certificate and will not acquire one soon.
What it is not
A second-party audit produces a report and a recommendation, not a certificate. Goldline is not a certification body and does not issue certificates of any kind. It does not transfer liability either: the Article 28(1) obligation to use only a processor providing sufficient guarantees stays where it was, with you. And it is not a model evaluation. Auditing a supplier's governance of a model and testing the model's outputs are separate exercises with separate skills, and buying one while believing you bought the other is a common and costly confusion.
What to do
- Find the audit clause in your existing agreement. It is almost certainly there, in the data processing schedule.
- Send a questionnaire proportionate to the risk, as the ICO's own framework describes, and use it for triage rather than for comfort.
- Turn the answers that matter into contractual representations with a notification obligation. This is the cheapest step available and the one most often skipped.
- Reserve the audit for the residual: what the supplier cannot evidence on paper, what falls outside any certificate scope, and where you retain a lever worth pulling.
If you are on the other side of this and answering these questionnaires rather than sending them, what the AI section actually asks for and why ISO 42001 certification does not close the gap cover the same ground from the supplier's chair. On the independence point underneath all of this, whether the firm that built a management system can audit it is the same argument applied inside one organisation.
Goldline conducts second-party audits of AI suppliers and ISO 42001 internal audits, and does not conduct internal audits of management systems it implemented.
Sources
- UK General Data Protection Regulation, Article 28, legislation.gov.uk, read 9 September 2026. Source for the quoted text of Article 28(3)(h) and for the Article 28(1) obligation to use only a processor providing sufficient guarantees. The page carries a note of outstanding amendments not yet applied to the text.
- Information Commissioner's Office, "What responsibilities and liabilities do controllers have when using a processor?", read 9 September 2026. Source for the quoted sentence on ensuring a processor's compliance on an ongoing basis, and for the gloss on sufficient guarantees in terms of expert knowledge, resources and reliability.
- Information Commissioner's Office, accountability framework, "Processor compliance reviews", read 9 September 2026. Source for both quoted expectations on audit clauses and on routine compliance checks proportionate to the processing risks.
- Information Commissioner's Office, AI and data protection audit framework toolkit, "Contracts and third parties", read 9 September 2026. Source for the procurement due diligence expectation and for the four quoted ways of meeting it. These are the ICO's published expectations within its audit framework, not statutory requirements, and they are quoted here as such.
- ISO catalogue entry for ISO/IEC 42006:2025, information technology, artificial intelligence, requirements for bodies providing audit and certification of artificial intelligence management systems, read 9 September 2026. Source for the first edition, the July 2025 publication and the 31 page length.
- UKAS, "UKAS grants first accreditation for ISO/IEC 42001", news item dated 15 January 2026, read 9 September 2026. Source for the quoted sentence. UKAS does not state the date on which the accreditation was granted and no such date is asserted here.
Not read, and therefore not claimed. ISO/IEC 42001:2023, ISO/IEC 42006:2025 and ISO 19011:2026 are paywalled and the ISO Online Browsing Platform returns no clause text without a subscription. Nothing above quotes or paraphrases the contents of any ISO standard, and the references to ISO/IEC 42006 rest on the title and publication data ISO publishes in its own catalogue. The formal conformity assessment definitions of first, second and third party activity were not accessible at source on the date of writing, so the description of a second-party audit above is given in plain terms rather than as a definition from a standard. The EU AI Act provisions on deployer obligations were reviewed for relevance but the article text could not be retrieved at source on the date of writing and is therefore not cited or relied on. Where your own contract is concerned, the clause in your contract governs, not this page.
