⚖️ Built for EU AI Act Annex III deployers

Every AI vendor in your stack is a regulatory liability — unless you can prove otherwise in 10 minutes.

PartnerScope gives compliance, risk, and AI governance teams at DACH enterprises an audit-ready 10-dimension risk scorecard for every third-party AI vendor — in the time it takes to read this page.

GDPR-compliant DACH-focused Annex III-aligned DORA & NIS2 ready

Under Article 26, your AI vendors' risk is your risk.

If you deploy AI in credit scoring, claims, diagnostics, grid management, or safety-critical manufacturing — the accountability sits with you as deployer. Not the model vendor.

📋

Your internal AI register is clean. Your vendor chain isn't.

Most compliance teams have a mature inventory of their own AI. But ask them to produce audit-ready due diligence on every third-party model, data provider, and ML tooling vendor — and the answer is "give us a few weeks."

⏱️

An unannounced audit doesn't give you a few weeks.

Annex III requires continuous conformity. The question isn't "can we build a report?" — it's "can we produce audit-grade vendor evidence on demand, today, across 30+ suppliers?"

💸

One non-conforming vendor can invalidate your whole Annex III file.

Training data without documented lineage. A model supplier with no MLSecOps posture. A sub-processor outside the EEA. Any of these can downgrade your entire system's classification.

One PDF. Ten dimensions. Ten minutes.

Here's what you get back for every vendor you submit — a PDF you can attach directly to your Annex III risk register.

Vendor: ExampleVision AI GmbH
Computer-vision models for predictive maintenance · scorecard generated 2026-04-17
62
Composite risk score · medium
1. Data provenance
2. Model transparency
3. Cybersecurity / MLSecOps
4. Regulatory compliance
5. Operational resilience
6. Financial health
7. IP & license clarity
8. Sub-processor chain
9. Ethics & bias posture
10. Incident response
1

Submit a vendor

Vendor name + what they supply you (model, data, MLOps tool). 30 seconds.

2

We assess 10 dimensions

Our analysts + automated signals score the vendor against EU AI Act, DORA, and NIS2 criteria.

3

Get an audit-ready PDF

Scorecard + heat-map + red-flag summary + remediation checklist. Attachable to your Annex III file.

4

Re-run quarterly

Vendors drift. Scorecards re-run on demand or on a schedule — so your file stays current.

The 10 dimensions your auditor actually cares about.

Each one mapped to specific EU AI Act articles, DORA obligations, or NIS2 supply-chain clauses.

01

Data Provenance

Training-data legality, lineage, consent basis, and cross-border transfer history.

02

Model Transparency

Documentation, explainability techniques, known failure modes, and evaluation evidence.

03

Cybersecurity & MLSecOps

Model integrity, adversarial-robustness testing, secrets handling, SBOM.

04

Regulatory Compliance

AI Act, GDPR, DORA, NIS2, sector-specific (MDR, Solvency II, BaFin).

05

Operational Resilience

Uptime record, SLA bite, failover capability, incident MTTR.

06

Financial Health

Going-concern signals, runway, funding stability — no point signing a vendor that vanishes in 18 months.

07

IP & License Clarity

Clean-room provenance, training-data license chain, open-source license compatibility.

08

Sub-processor Chain

Every downstream party touching your data. Where they sit. What they re-share.

09

Ethics & Bias Posture

Published fairness testing, bias-remediation process, human-rights alignment.

10

Incident Response

Historical breaches, disclosure timeliness, your right to be notified and timelines.

Pricing that scales with your vendor inventory.

Start with a single vendor. Scale to your whole AI supply chain. Every tier includes audit-ready PDF output.

Pilot

One-off — see the output before you commit.

€499

one-time · 1 vendor

  • 1 full scorecard PDF
  • 10 risk dimensions
  • Red-flag summary
  • Remediation checklist
  • Delivery within 48h
Start a pilot

Enterprise

For regulated groups with large AI vendor inventories.

€2,500

/month · unlimited scans

  • Unlimited scorecards
  • SSO + DPA + AVV
  • Dedicated CSM
  • Custom dimensions
  • Regulatory mapping reports
Talk to us

Audit Partnership

White-glove engagement: your vendor inventory, assessed end-to-end.

€15,000

one-time · 50 vendors + compliance memo

  • 50 vendors assessed
  • Legal + technical memo
  • Board-ready briefing
  • Workshop with your team
  • 6-month re-scoring included
Scope the engagement

Frequently asked

Is a PartnerScope scorecard accepted as evidence under Annex III?

A scorecard is not a regulatory certification — it's structured due-diligence evidence. Customers attach it to their Annex III risk register as the "third-party vendor assessment" document their internal audit and external conformity assessors expect to see. It closes the same gap a written vendor questionnaire would close — but faster, more structured, and re-runnable.

How do you source the data you score vendors against?

Public filings, technical documentation, SBOMs, published security posture (SOC 2, ISO 27001, ISO 42001), court records, breach-disclosure databases, and — when the vendor cooperates — direct documentation they provide. When evidence is missing, we flag it as a gap rather than guessing.

Do vendors have to cooperate?

No. A cold scorecard (no vendor cooperation) still captures most observable signals. Vendor cooperation raises coverage and confidence. Some customers use the free pilot scorecard itself as the opener to request vendor documentation.

How is this different from internal vendor-risk questionnaires?

Questionnaires are self-attested and static. PartnerScope scorecards combine external signals (breach history, financial filings, sub-processor registries) with self-attestation, producing a score the vendor can't author themselves. And they re-run on a schedule — so a vendor that drifts triggers an alert.

GDPR / DPA / data residency?

We process vendor metadata, not your personal data. No training data or customer records leave your systems. A DPA / AVV is available on request for Team and above. All processing within the EEA.

Languages?

Scorecards delivered in English or German. DACH market is the current focus; customer-success communication in DE / EN / RU.

Get a free scorecard on one of your current AI vendors.

Pick a vendor. We deliver a full 10-dimension PDF within 48 hours. Zero commitment.

Request a free scorecard →