THU, SEPTEMBER 10, 2026
Independent · In‑Depth · Practitioner‑Tested
Claude General

Vendor Diligence Prompts: 6 for Questions You Will Be Asked Later

Three US agencies issued a joint advisory on distillation this week, NVIDIA is buying the registry most open weights are distributed through, and a court has already ruled on how training data was acquired. None of that stops you shipping. It does mean somebody will eventually ask which models you depend on and where they came from. These six prompts are for having the answer ready. None of this is legal advice.

⌨️ 6 prompts 🕐 Updated Sep 10, 2026
💡 How to use these prompts: Replace everything in [BRACKETS] with your specific details before sending. Click Copy to copy any prompt to your clipboard instantly.
1
List what I actually depend on
Most stacks have a dependency nobody remembers adding. This finds it before someone else does.
Here is everything in my stack that touches a model: [DESCRIBE, INCLUDING FINE-TUNES, EMBEDDINGS AND ANYTHING A VENDOR RUNS FOR ME]

For each, tell me:
- Who built it and where they are based
- Whether I call it or host it
- What I would have to change if it became unavailable tomorrow
- How long that change would take

Rank by how badly I would be affected, not by how likely it is.
2
Answer the questionnaire before it arrives
Writing the hostile version yourself is cheaper than receiving it from a prospect.
Draft the AI section of a vendor security questionnaire the way a cautious enterprise buyer would write it.

Then, for each question, tell me what my honest answer would be given: [DESCRIBE YOUR STACK]

Flag every question where my answer would be weak, and what I would need to change to strengthen it.
3
Work out what a change in policy would cost me
The realistic number is usually longer than expected, which is the point of asking now.
Suppose a model I use becomes restricted, unavailable or commercially unusable: [NAME IT]

Walk me through:
- What breaks immediately
- What degrades gradually
- The closest substitute and how it differs
- What migration would actually take, in days

Do not reassure me. I want the realistic number.
4
Separate what I control from what I do not
The last instruction is what makes this useful. Most people assume contracted when they mean exposed.
For my AI stack: [DESCRIBE]

Sort every dependency into:
CONTROLLED - I host it, I have the weights, I could keep running it
CONTRACTED - a vendor provides it under terms I have read
EXPOSED - I depend on it and could lose it without warning

Be strict about the third category. Anything I have not read the terms for belongs there.
5
Draft the questions for a vendor
Indemnity is the clause that decides who carries the risk, and the one people forget to raise.
I am evaluating an AI vendor: [NAME OR DESCRIBE]

Draft the questions I should ask about model provenance, training data, indemnification and continuity.

For each, tell me what a reassuring answer sounds like and what an evasive one sounds like. Include what I should get in writing rather than in a call.
6
Write the one-page summary
A document that overstates your position is worse than none, because someone will check it.
Turn everything above into a single page I could hand to a lawyer, an auditor or a prospect.

Plain language. What we use, where it comes from, what we can establish, what we cannot, and what we would do if something changed.

Do not make it sound better than it is. The value is in it being accurate.