Skip to main content
Vendor Management
5 min readUpdated 2026-02-15

Vendor Attestations

Managing vendor attestations for EU AI Act compliance — requesting, tracking, and storing vendor statements about their AI systems' compliance posture.

Vendor Attestations

A vendor attestation is a formal statement from your AI vendor about their system's compliance posture. These are becoming increasingly important as the EU AI Act takes effect — they demonstrate that you've verified your vendor's claims.

What Attestations Cover

Attestation TypeWhat the Vendor Confirms
AI System DescriptionWhat the system does, how it works, known limitations
Risk ClassificationThe vendor's own assessment of their system's risk level
Transparency SupportHow they support deployer transparency obligations
Logging CapabilityWhat logs are generated, retained, and exportable
Incident NotificationTheir process for notifying deployers of issues
Data ProcessingWhere and how data is processed; security measures
GPAI ComplianceFor general-purpose AI: model card, training data transparency
No Prohibited PracticesConfirmation the system doesn't engage in Article 5 prohibited practices

Requesting Attestations

To request an attestation from a vendor:

  • Navigate to the vendor profile
  • Go to the Attestations tab
  • Click Request Attestation
  • Select the attestation type(s) needed
  • Klarvo generates a standardized request that you can send to the vendor
  • The request includes specific questions aligned to EU AI Act requirements
  • Recording Received Attestations

    When you receive a vendor attestation:

  • Navigate to the vendor profile → Attestations tab
  • Click Add Attestation
  • Select the type
  • Upload the vendor's response document
  • Record:
  • - Date received

    - Who provided it (vendor contact)

    - Validity period (typically 12 months)

    - Any caveats or limitations noted

  • Link to relevant AI systems and controls
  • Attestation vs. Certification

    AttestationCertification
    Who providesThe vendor themselvesIndependent third party (auditor)
    ReliabilitySelf-reported; lower assuranceIndependently verified; higher assurance
    CostFree / low costSignificant cost
    AvailabilityMost vendors can provideNot all vendors have certifications
    Audit valueGood; shows due diligenceExcellent; independent verification

    Both have value. Attestations are practical for SMEs who can't require every vendor to have third-party certification.

    Renewal Tracking

    Attestations have limited validity:

  • Set the expiration date when recording the attestation
  • Klarvo sends renewal reminders 30 days before expiry
  • A task is auto-created to request updated attestation
  • Expired attestations are flagged and no longer count toward due diligence completion
  • Best Practices

    📋 Request at procurement: Include attestation requirements in your vendor onboarding process
    📅 Set validity periods: Typically 12 months — align with contract renewal cycles
    📄 Use standardized formats: Consistent attestation requests make vendor responses more comparable
    🔗 Link to evidence: Attestations are evidence for VEN controls — link them accordingly
    ⚠️ Note limitations: If a vendor's attestation has caveats, record them clearly