PARTLY

As of 13 August 2026, AI can only partly assess the risk of using a supplier.

This still needs a person who signs their name to it.

Can you do it?

15 minutesto a draft.

1 hourto something you’d act on.

Cost, all in£0

Skill neededchat-fluent

Who has to check ita colleague

What the alternative costsThe available tool data gives no price for a human supplier-risk assessment.

If this goes wrong, you approve a supplier that later fails, breaches an obligation or cannot deliver, and your organisation carries the operational and financial consequences.

What to actually do

  1. Hand it to a person

    The route this page recommends

    A person who owns the outcome does this end to end, worth it when the failure is dear.

  2. Use a tool built for this

    Second choice
  3. Do it yourself

    The distant third

    A chat interface, chat-fluent skill, and roughly 1 hour until you can act on the result.

    How to actually do it

    1. Open your procurement brief and write down the supplier's service, contract value, criticality, access to data or systems, required start date and the risk criteria your organisation uses.
    2. Gather the supplier questionnaire, proposed contract, latest available accounts, insurance details, relevant certifications, policies, business continuity information, references and any public company information.
    3. Remove unrelated personal data and mark each document with its source, publication date and version before attaching or pasting it into the chatbot.
    4. Paste the prompt with the procurement brief and supplier material, then ask the chatbot to produce the cited risk register, missing-evidence list and provisional recommendation.
    5. Open each cited source and compare the risk register's factual claims, dates and page references with the original documents, correcting any unsupported or misquoted entry.
    6. Send the missing-evidence and clarification questions to the supplier, then add the replies and replacement documents to the chatbot for a revised assessment.
    7. Ask the procurement owner and the relevant finance, information security or legal specialist to check the high-impact risks, then record the human decision, controls, owner and review date in your procurement file.

    Prompt

    Assess the risk of using the supplier described in the material below. This is a UK business procurement decision. Do not invent facts, infer compliance from silence, or treat a supplier claim as verified unless the supplied evidence supports it.
    
    Produce:
    1. An executive summary with a provisional risk rating of low, medium or high, clearly labelled as provisional.
    2. A table of risks with these columns: risk area, evidence, source and page or section, what is missing, likelihood, impact, proposed mitigation, owner, and confidence.
    3. Separate factual findings from judgement and assumptions.
    4. Identify contradictions, expired documents, vague claims and evidence that needs independent confirmation.
    5. List the most important questions to send to the supplier.
    6. State what evidence would change the provisional rating.
    7. Recommend one of: proceed, proceed only with controls, request more information, or do not proceed. Give reasons and do not present the recommendation as professional advice.
    
    Use only the supplied material and clearly labelled public information. Quote or cite the relevant source for every material factual claim. If the evidence is insufficient, say so. Do not assign a risk rating solely because a document is missing. Do not make legal, financial, cyber-security or technical compliance conclusions beyond what the evidence supports.
    
    Supplier and contract context:
    [PASTE THE PROCUREMENT REQUIREMENTS, CONTRACT VALUE, SERVICE CRITICALITY, DATA ACCESS, DEADLINES AND INTERNAL RISK CRITERIA]
    
    Supplier material:
    [PASTE OR ATTACH THE SUPPLIER QUESTIONNAIRE, CONTRACT, ACCOUNTS, CERTIFICATES, POLICIES, REFERENCES AND OTHER EVIDENCE]

    Open it prefilled in ChatGPT or Claude, or copy it into Gemini, which takes no prefill link.

What it gets wrong

What caps this at PARTLY: judgement under ambiguity, verification cost and stakes of error.

How we scored this

Five axes, each scored nought to two by hand: ten means AI carries the task cleanly, and the thresholds that turn a total into YES, PARTLY or NO are published in the methodology. Each axis name links to its definition.

AxisScore (0–2)
Output2
Inputs1
Verification1
Liability1
Effort delta2
Total7 / 10

FAQ

Can ChatGPT assess supplier risk?
Partly. It can compare supplier documents, extract evidence, identify gaps and draft a provisional risk register, but it cannot verify every claim or make the accountable procurement decision for you.
What information does AI need to assess a supplier?
Give it the procurement requirements, service criticality, contract context, risk criteria and the supplier's supporting evidence. Useful material includes the proposed contract, questionnaire, accounts, insurance, certifications, continuity plans, policies and references.
Can AI tell me whether I should use a supplier?
It can give you a structured, provisional recommendation based on the evidence you provide. You still need to check the sources, obtain missing evidence and have the appropriate procurement and specialist owners approve the decision.
Is AI supplier due diligence reliable?
It is useful for organising and comparing evidence, but it is not reliable as the only due-diligence process. It can miss context, accept unsupported supplier claims or overlook a risk that requires specialist judgement, so material findings need human verification.

Nearby answers

Assessed by gpt-5.6-luna (gpt-5.6-luna) on 2026-08-13, second-checked by an independent model. Wrong somewhere? Email [email protected] and it gets re-checked.

The newsletter

AI news, new answers and product picks, straight to your inbox.