Suppliers: the value chain, agreements and the IFU handoff
The register of the third parties behind your AI systems, the written agreements Art. 25(4) and GDPR Art. 28 expect, the six-question supplier assessment, and how the Art. 13 instructions for use hand off along the chain.
AI systems rarely live with one party. The EU AI Act sets out a chain of responsibility — provider → importer → distributor → deployer — with obligations handing off along it, and Art. 25(4) expects a provider of a high-risk system and the third parties supplying it with tools, components or services to agree in writing the information, capabilities, access and support the provider needs to meet its own obligations. Suppliers (under Do the work) is the register of those third parties.
The register
One row per supplier — model providers, processors, hosts — with its kind, where the processing happens, whether a written agreement is on file, its status (Active · Under review · Offboarded) and its next review date. The header counts how many suppliers have no written agreement, because that is the gap Art. 25(4) and GDPR Art. 28 both name. New supplier opens the form: name, kind, what you use them for, where the processing happens (this feeds the transfer question), the agreement link, contact and review date.
Three regimes read this one register: Art. 25(4), GDPR Art. 28 (the processor contract) and, if you run the ISO/IEC 42001 programme, its supplier controls. A supplier is entered once.
The supplier record and its assessment
Opening a supplier shows the facts, the systems that depend on it, the controls that satisfy the supplier duties, and an append-only list of assessments. An assessment is six questions, each citing what it answers: the written agreement (Art. 25(4)); whether processing stays in the EU/EEA or a transfer mechanism is in place (GDPR Art. 44); the sub-processor list and change notice (GDPR Art. 28(2)); documented and reviewed security measures (GDPR Art. 32); agreed incident and breach notification terms (Art. 73 and GDPR Art. 33); and whether the supplier's use of your data for its own model training is excluded or governed (Art. 10). The outcome — Approved · Conditional · Rejected — is recorded with a summary and a next-review date, and the record is never edited afterwards.
Article 13 — instructions for use (IFU)
Providers of high-risk systems must give deployers instructions for use: what the system does, its capabilities and limitations, the human oversight it expects, its accuracy and known risks, and how to keep it running safely. The IFU is the operating manual the deployer relies on to use the system lawfully — and, under Art. 26(9), the information a deployer shall use when carrying out its GDPR data-protection impact assessment.
- If you are the provider — work the Art. 13 obligation in the drawer; it links to the printable Art. 13 IFU package, which lays out provider identity, intended purpose and the Art. 13(3) elements as a clean A4 document (Cmd/Ctrl+P). Hand it to your deployers; the same package appears on Documents as the Instructions for use row.
- If you are the deployer — the engine gives you the receiving obligations (Art. 26(1): use the system in accordance with its instructions) and, where you are running a GDPR DPIA, the drawer's reuse card reminds you that Art. 26(9) tells you to draw on those instructions.
Article 23 — importers
If you bring a non-EU provider's high-risk system into the EU market, Art. 23 makes you verify, before placing it, that the provider has carried out the conformity assessment (Art. 43), drawn up the technical documentation (Art. 11), affixed the CE marking (Art. 48), issued the EU declaration of conformity (Art. 47) and appointed an authorised representative (Art. 22). The engine generates each check as its own obligation on the importer's record, with a structured form for the provider's details, the authorised representative, the CE marking date, the declaration reference and the market-placement date.
Article 24 — distributors
Distributors must check the CE marking, the declaration of conformity and the instructions for use are present before making a high-risk system available, and must not make one available they have reason to think is non-conformant. The checks appear automatically as obligations when your role is distributor — no configuration needed.