Study the lesson
Work through every section at your own pace, from start to finish.
Every week, somewhere in a boardroom or procurement meeting, a leader approves an AI vendor on the strength of a confident sales deck, an impressive demo, and a reassuring set of certifications. Six months later, that same leader discovers the tool does not perform as expected on their actual data, that customer information has been used to train a model they do not control, and that switching would cost more in time and disruption than they would care to admit. The problem here is rarely a bad vendor. It is a due diligence process that has not caught up with the technology it is meant to evaluate. AI procurement is genuinely different from buying conventional software. The quality of an AI system is not fixed at the point of delivery; it can degrade silently over time. The data you feed it may have consequences you did not anticipate. The vendor's product may be a thin wrapper over a third-party foundation model, a large general-purpose AI system trained on broad datasets, that introduces its own risks and limitations. And as of 2026, the regulatory environment places increasing accountability on the organisations that deploy these tools, not just the companies that build them. This lesson gives you a structured checklist: three categories of scrutiny that separate good due diligence from the superficial kind.
Unlock the full lesson, the quiz, and your verifiable completion.
Continue with GoogleBy continuing you agree to the Institute of AI terms of use and privacy policy.
It is explained in plain English and assumes no technical background. Anyone can start it today.
Section one is open to everyone. Create a free account to work through the rest and take the quiz.
The first task in any AI vendor evaluation is understanding what you are actually buying. This sounds obvious, but it is routinely skipped. Many commercial AI products are built on top of foundation models provided by a small number of large technology companies. The vendor's contribution may be a user interface, a domain-specific prompt configuration, or a fine-tuned layer trained on specialist data. That is entirely legitimate, but it means you need to ask two separate questions: what is the vendor's product, and what does it sit on top of? This is the question of model provenance: the origin and lineage of the model your product depends on. This matters because if the underlying model changes, your system's behaviour may change without warning. If the foundation model provider updates their terms of service, your vendor's ability to serve you may be affected. And if something goes wrong, attributing responsibility across that chain requires you to understand it first. Worth asking: is this product built on a third-party foundation model, and if so which one and what version? How are updates to the underlying model communicated, and what is the process for regression testing before they reach your environment? What is the vendor's own contribution to the product? The second layer of scrutiny concerns performance claims. Benchmarks in sales materials reflect best-case conditions: curated test sets, favourable configurations, and tasks the model was likely exposed to during training. They are not a substitute for testing the tool against your own data and use cases. Think of it like a credit agreement versus a bond rating: the borrower's contractual promises must be read alongside independent evidence of their creditworthiness. Ask for results on tasks comparable to your use case, run on data similar in type and quality to your own. If the vendor cannot provide this, run the pilot yourself before committing. ISO 27001, an international standard for information security management, and SOC 2, a framework for assessing service organisations' controls, are worth having, but understand what they cover: infrastructure and data-handling controls, not AI accuracy, fairness, or reliability. A vendor can hold an ISO 27001 certificate and a clean SOC 2 report and still produce an AI system that performs poorly on your specific tasks.
Work through every section at your own pace, from start to finish.
A short set of questions on what you have just covered.
Every completion has a certificate that you can share publicly for anyone to verify.
Pass the quiz and the Institute of AI issues you a record of completion with your score. Every completion has its own public verification page, so the link you put on your CV or LinkedIn profile can be checked by anyone, at any time.
Free lessons, a quiz to test what you have learned, and a completion you can verify publicly. All from the UK's professional body for artificial intelligence.
Every AI lesson is free to start, free to finish, and ends in a completion you can verify publicly.