← Back to Playbooks

Playbook 2 — Vendor & Procurement

Governing AI you buy — which is most of what an SMB actually uses

You’re Probably a Deployer, Not a Developer

Most SMB “AI governance” problems are really vendor-management problems. You’re not training models — you’re turning on an AI feature inside a CRM, using ChatGPT or Claude for content and support, or hiring a contractor whose tools include Copilot. Under the EU AI Act and under plain common sense, your obligations as a deployer are lighter than a developer’s, but they are not zero: you still have to know what you bought, what it does with your data, and what happens when it’s wrong.

Due Diligence Before You Sign — Checklist

Contract Clauses to Ask For

Red Flags — Walk Away or Escalate

STOP AND ASK MORE QUESTIONS IF:

The vendor can’t or won’t explain how the AI makes its decisions.

There’s no Data Processing Agreement available on request.

The tool has no way to review, correct, or override an automated output.

The sales rep’s answer to “what happens to our data” is “don’t worry about it.”

It’s being used for a High-tier use case (Playbook 1) and the vendor offers no bias or fairness documentation.

​

5 Questions for Any AI Vendor — Quick Reference

One line worth adding to any vendor questionnaire: ask about GDPR explicitly, and about NIS2 or the Cyber Resilience Act where your sector or the vendor’s position makes either relevant. A single AI vendor relationship can trigger a data processing agreement, a supplier assessment, and AI Act due diligence at once — see EU AI Regulation for SMBs for which of those actually apply to you.

Next Steps

Once a vendor passes this checklist, log the tool in the AI system inventory (Playbook 6) with the risk tier from Playbook 1. If it touches hiring, credit, pricing, or personal data, also run it through Playbook 3 before go-live.