AI Procurement Due Diligence — Vendor Assessment Playbook
Your agency is evaluating three competing AI vendors for a contract that will support adjudication decisions affecting benefits eligibility for 340,000 applicants annually. OMB M-24-10 requires a pre-procurement AI impact assessment. One vendor has declined to provide model documentation; a second has disclosed a prior FTC consent decree; the third is a small business with no federal past performance.
When to use this playbook
- Use this playbook when the decision looks like the situation above: Your agency is evaluating three competing AI vendors for a contract that will support adjudication decisions affecting benefits eligibility for 340,000 applicants annually.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Procurement Due Diligence — Vendor Assessment".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- Vendor technical responses and model documentation (all three vendors) - FTC consent decree for Vendor B - OMB M-24-10 AI impact assessment checklist - Draft performance work statement and evaluation criteria
Attachments: Documents (Documents)
The Prompt
You are a federal AI procurement officer conducting a pre-award AI impact assessment and vendor due diligence review under OMB M-24-10. I am attaching: - Vendor technical responses and model documentation (all three vendors) - FTC consent decree for Vendor B - OMB M-24-10 AI impact assessment checklist - Draft performance work statement and evaluation criteria Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Assess each vendor's model documentation against OMB M-24-10 minimum transparency requirements — for the vendor that declined to provide documentation, assess the procurement risk of proceeding without it. 2. Review the FTC consent decree for Vendor B and determine whether the underlying conduct — algorithmic bias, deceptive practices, or data misuse — is relevant to the intended use case and constitutes a responsibility determination factor under FAR Subpart 9.1. 3. Evaluate the PWS and evaluation criteria for alignment with OMB M-24-10 requirements for high-impact AI — specifically, human review requirements, audit rights, and model performance monitoring obligations. 4. Assess the small business vendor's technical response for capability evidence that compensates for the absence of federal past performance — and identify specific past performance evaluation approaches appropriate for non-traditional vendors. 5. Produce a pre-award AI impact assessment report and a source selection risk register ranking each vendor's AI-specific risk profile. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- Multi-model consensus on vendor AI risk classification
- OMB M-24-10 documentation compliance matrix per vendor
- FTC consent decree relevance analysis and FAR 9.1 responsibility flag
- PWS gap analysis for high-impact AI requirements
- Pre-award AI impact assessment report with model-agreement score
Review before you act
- Validate this output against source files before relying on it: Assess each vendor's model documentation against OMB M-24-10 minimum transparency requirements — for the vendor that declined to provide documentation, assess the procurement risk of proceeding without it.
- Validate this output against source files before relying on it: Review the FTC consent decree for Vendor B and determine whether the underlying conduct — algorithmic bias, deceptive practices, or data misuse — is relevant to the intended use case and constitutes a responsibility determination factor under FAR Subpart 9.1.
- Validate this output against source files before relying on it: Evaluate the PWS and evaluation criteria for alignment with OMB M-24-10 requirements for high-impact AI — specifically, human review requirements, audit rights, and model performance monitoring obligations.
- Validate this output against source files before relying on it: Assess the small business vendor's technical response for capability evidence that compensates for the absence of federal past performance — and identify specific past performance evaluation approaches appropriate for non-traditional vendors.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For Procurement Due Diligence — Vendor Assessment, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface multi-model consensus on vendor ai risk classification; omb m-24-10 documentation compliance matrix per vendor; ftc consent decree relevance analysis and far 9.1 responsibility flag; pws gap analysis for high-impact ai requirements. Those are comparison artifacts — they only exist if more than one model runs. Threshold-splitting, sanctions hits, and exam-readiness calls are exactly where models diverge. Record the split and the human resolution.
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

