MP Muchangi Patrick& Associates Advocates
Talk to an Expert
Practice Areas Case Digest Knowledge Centre Insights About Contact Talk to an Expert
Compliance Toolkit/AI Procurement Checklist
KPLR/CHK/004/2026 Standalone Checklist AI Governance
Compliance Toolkit · Standalone Checklist

AI Procurement Checklist

A Practical Vendor & Governance Assessment Guide

Prepared by
Muchangi Patrick & Co. Advocates
Published
July 2026
Format
26 items · Fillable PDF
Version
1.0
Editorial Status
Published
Language
English
Abstract

A board-level, self-assessment instrument prepared by Muchangi Patrick & Associates Advocates — 26 scored requirements, a compliance score band, and a priority action plan.

How to Use This Checklist

For each requirement below, record one of four ratings: YES — fully compliant; PARTIAL — a defined gap remains; NO — the requirement is unmet; N/A — not applicable to the organisation's operations. Download the fillable PDF to complete and retain your assessment.

Executive Summary

Organisations increasingly procure AI-enabled tools and services --- from chatbots and analytics platforms to HR screening and credit-scoring systems. Responsible procurement requires data protection, AI governance and cybersecurity due diligence to be embedded before any contract is signed, informed by the Data Protection Act, 2019, sectoral guidance, and emerging frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework. This checklist has been prepared by Muchangi Patrick & Associates Advocates to guide procurement, legal and technology teams through vendor due diligence, contractual safeguards and internal governance approval for AI system acquisitions.

How to Use This Checklist

This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes.

Ai Procurement Assessment

No.RequirementYesPartialNoN/A
01Business case and use case for the AI system clearly defined☐☐☐☐
02AI system classified by risk level (e.g. minimal, limited, high risk)☐☐☐☐
03Data Protection Impact Assessment conducted where required☐☐☐☐
04Vendor\'s data protection compliance status verified☐☐☐☐
05Vendor\'s registration or accreditation status verified (where applicable)☐☐☐☐
06Training data sources and provenance disclosed by the vendor☐☐☐☐
07Vendor confirms lawful basis for any personal data used to train the model☐☐☐☐
08Data flows between the organisation and the vendor mapped☐☐☐☐
09Cross-border data transfer arrangements assessed☐☐☐☐
10Contractual data processing terms included in the procurement agreement☐☐☐☐
11Vendor\'s security certifications and controls reviewed☐☐☐☐
12Vendor\'s incident and breach notification obligations defined in the contract☐☐☐☐
13Model accuracy, bias and fairness testing evidence requested☐☐☐☐
14Explainability and transparency of AI outputs assessed☐☐☐☐
15Human oversight and override mechanisms confirmed☐☐☐☐
16Right to human review of automated decisions provided to data subjects☐☐☐☐
17Intellectual property and data ownership terms clarified☐☐☐☐
18Sub-processor and fourth-party AI vendor arrangements disclosed☐☐☐☐
19Vendor\'s data retention and deletion practices confirmed☐☐☐☐
20Exit strategy and data portability provisions included in the contract☐☐☐☐
21Ongoing monitoring and audit rights secured in the contract☐☐☐☐
22Internal AI governance policy applied to the procurement decision☐☐☐☐
23Employees and users trained on appropriate use of the AI system☐☐☐☐
24Vendor liability and indemnity provisions reviewed☐☐☐☐
25Regulatory or sectoral approval obtained where required☐☐☐☐
26Procurement decision approved by the appropriate governance or board committee☐☐☐☐

Compliance Score

Aggregate the ratings above to determine the organisation's overall compliance posture:

ScoreAssessment
23 – 26Excellent
18 – 22Good
11 – 17Fair
0 – 10Immediate Remediation Required

Priority Action Plan

Corrective actions identified during the assessment should be recorded and tracked to closure, assigned by priority (High / Medium / Low) to a named responsible officer with a target date — see the fillable PDF for a ready-made tracking table.

Overall Assessment

Record an overall rating of Excellent, Good, Moderate/Fair or Poor, together with the auditor's notes, in the space provided in the fillable PDF.

Disclaimer: This checklist is a diagnostic tool, not a substitute for legal advice. Organisations identifying material gaps should seek a full compliance audit before relying on the results for governance or regulatory reporting purposes. Reading this publication does not create an advocate-client relationship with Muchangi Patrick & Associates Advocates. For advice on a specific matter, please book a consultation.
PM

Patrick Muchangi

Advocate of the High Court of Kenya · Founder, Muchangi Patrick & Associates Advocates

Patrick Muchangi is an Advocate of the High Court of Kenya and founder of Muchangi Patrick & Associates Advocates, a Nairobi practice specialising in data protection, privacy, AI governance and technology law, and editor of the Kenya Privacy Law Review.