ASSURE
Audit the AI supplier, not just the questionnaire.
A buyer-side audit of a supplier's AI governance against ISO 42001, NIST AI RMF, and your own supplier requirements. For organisations whose AI risk now sits substantially in someone else's model.
From £4,500 + VAT per supplier
THE ENGAGEMENT
Assurance, rather than a supplier's account of itself.
Most organisations assess AI suppliers through a questionnaire the supplier completes about itself. Where the supplier's model materially affects decisions the buying organisation is accountable for, a self-assessment is not assurance. It is a statement of intent, written by the party with the least interest in finding a problem.
A second-party audit means the buyer commissions an independent audit of the supplier, against criteria the buyer sets. It is standard practice in other supply chain domains, from manufacturing quality to food safety to defence, and it is arriving in AI for the same reason it arrived everywhere else: the risk moved into the supply chain faster than the assurance did.
The pressure is specific. ISO 42001 Annex A includes controls on third-party and customer relationships. The EU AI Act places obligations on deployers as well as providers, so relying on a supplier's system does not transfer accountability. And enterprise buyers are increasingly asked by their own boards how they assure suppliers whose AI they rely on, which is a question a completed questionnaire does not answer.
INDEPENDENCE
Whose question we are answering.
The audit is commissioned by you and reported to you. The supplier receives what is needed to conduct the fieldwork and, where you choose, a findings summary. The full report, the risk rating, and the recommendation belong to your procurement and risk functions.
Goldline does not audit the AI governance of suppliers whose AI Management System Goldline implemented. Where that overlap exists we will disclose it before scoping and step aside, because a report on our own work has no assurance value to you.
DELIVERABLES
What you receive.
Scope agreed with you and with the supplier before fieldwork
Audit against ISO 42001 Annex A controls relevant to the supplier relationship
Assessment against NIST AI RMF where the supplier's own governance references it
Assessment against your specific supplier requirements, contractual terms, and risk appetite
Findings report written for your procurement and risk functions, not for the supplier
Risk rating and a recommendation: proceed, proceed with conditions, or do not proceed
Remediation tracking where conditions apply
FIT
Who this is for.
- You rely on a third-party AI system for a material decision or process.
- You carry EU AI Act deployer obligations for a supplier's high-risk system.
- You are regulated and your supervisory expectations extend to supply chain AI.
- Your existing supplier assessment is a questionnaire and your board has started asking whether that is enough.
This is not for routine low-risk software procurement. Where an AI feature does not carry a material decision, a questionnaire and sound contractual terms are proportionate, and commissioning an audit is a waste of your budget. We will say so plainly at scoping.
WHAT COMES NEXT
Where organisations go from here.
Supplier assurance is usually one part of a wider AI governance position. Where your own estate has not been assessed, that is the place to start. Where the accountability for AI governance has no owner, the fractional role takes it.
DIAGNOSE
AI Governance Readiness Assessment
A fixed-scope diagnostic covering your AI estate, your governance gaps, and your EU AI Act exposure, with a board-ready report and roadmap.
Explore the assessmentLEAD
Fractional AI Governance Lead
A named accountable owner for the AI Management System, the AI inventory, risk classification, and the impact assessments the board is asked about.
Explore the roleQUESTIONS
Common questions.
How do you assure the AI you buy?
A 45 minute scoping call establishes which supplier relationships carry material risk, what the audit criteria should be, and whether a questionnaire is genuinely enough. No sales pitch, and for low-risk procurement the answer is frequently no audit.
Prefer email? Write to info@goldlineconsultancy.co.uk.
