AI Vendor Risk Assessment
Score every AI vendor in your stack against GDPR, EU AI Act, and security requirements.
The Problem
Your AI vendors handle your customers' data. A data breach or privacy violation at one of your AI vendors makes you liable under GDPR and EU AI Act. Most businesses have no formal vendor assessment process — they adopt AI tools without reviewing privacy policies, DPAs, or data handling practices.
How Aegis Firma Solves It
Aegis Firma provides a structured AI vendor risk assessment framework: 50-question questionnaire covering data handling, privacy policy quality, security certifications, EU AI Act disclosures, and incident response. Each vendor gets a composite risk score and red flag summary.
How It Works
Add vendors to your registry
Add each AI vendor you use or are considering.
Complete vendor assessment
Work through the 50-question vendor risk questionnaire for each vendor.
Review risk scores
Each vendor gets a composite risk score (0–100) with colour-coded red flags.
Remediate high-risk vendors
For high-risk vendors: request additional information, negotiate DPA terms, or replace with lower-risk alternatives.
Key Features
Start your compliance programme today
No credit card · No sales call · Live in 30 minutes
Start freeFrom $79/month · 169 jurisdictions