Skip to content
Aegis Firma Feature

AI Vendor Risk Assessment

Score every AI vendor in your stack against GDPR, EU AI Act, and security requirements.

The Problem

Your AI vendors handle your customers' data. A data breach or privacy violation at one of your AI vendors makes you liable under GDPR and EU AI Act. Most businesses have no formal vendor assessment process — they adopt AI tools without reviewing privacy policies, DPAs, or data handling practices.

How Aegis Firma Solves It

Aegis Firma provides a structured AI vendor risk assessment framework: 50-question questionnaire covering data handling, privacy policy quality, security certifications, EU AI Act disclosures, and incident response. Each vendor gets a composite risk score and red flag summary.

How It Works

1

Add vendors to your registry

Add each AI vendor you use or are considering.

2

Complete vendor assessment

Work through the 50-question vendor risk questionnaire for each vendor.

3

Review risk scores

Each vendor gets a composite risk score (0–100) with colour-coded red flags.

4

Remediate high-risk vendors

For high-risk vendors: request additional information, negotiate DPA terms, or replace with lower-risk alternatives.

Key Features

50-question AI vendor risk questionnaire
Data handling category assessment
GDPR DPA availability check
Security certification review (SOC 2, ISO 27001)
Composite risk score with red flag summary
Contract renewal date monitoring

Start your compliance programme today

No credit card · No sales call · Live in 30 minutes

Start free

From $79/month · 169 jurisdictions

Related Use Cases