AI due diligence for surveying firms: the six things to ask suppliers in writing
Before relying on an AI system with material impact, RICS firms must carry out detailed written due diligence. The six minimum information requests, the testing record, and what to do when vendors won't answer.
Section 4.1 of the RICS AI standard requires detailed due diligence before procuring any third-party AI system — embedded or standalone — that will have a material impact on delivery of surveying services. Not a gut feel about a demo: written requests, recorded answers, and a record of the practical testing you did.
The process the standard prescribes
- Request information from the supplier in writing (and chase in writing as needed).
- Record what comes back and assess it — feeding procurement decisions and the risk register.
- Keep a record of fitness-for-purpose testing — how far you actually tested the tool on your kind of work.
- Where information is missing, identify the risks the gap creates and record them in the risk register.
The six minimum written requests
The standard names the information that must, as a minimum, be requested in writing:
- the environmental impact of the AI system,
- the stakeholders involved in its development,
- compliance with applicable data and confidentiality laws,
- permissions obtained where data and content relating to individuals were used,
- the accuracy, relevance and diversity of the training datasets, including known gaps and known bias risks, and
- the type and extent of the supplier's liability.
Silence is itself an answer: if a supplier provides no or limited information, the standard doesn't block you from proceeding — it requires the resulting risks to be identified and recorded. Which is more honest than pretending an unanswered question was fine, and it keeps the decision defensible either way.
Making it manageable
This reads heavier than it is. One template letter covering the six items, sent per tool as it comes up for adoption or review; answers filed against the tool's entry in your systems register; gaps dropped into the risk register with a RAG rating. The testing record can be a paragraph: what you ran it on, what you compared it against, what you found. What examiners of any kind respond to is the same thing clients do — evidence the question was asked before the tool was trusted, by the person accountable. It also feeds directly into what you must be able to explain later: see explainability on request.
Does due diligence apply to free tools?
The duty attaches to procuring systems with material impact — the trigger is impact, not price. A free tool used materially deserves the same written questions; if anything, free tools answer fewer of them, which belongs in the risk register.
What about AI embedded in software we already own?
Explicitly in scope — the standard covers systems 'whether embedded in a broader technological solution or not'. Vendor AI features switched on inside estimating or document platforms trigger the same process where use is material.
ComplyQS tracks due-diligence status per tool — requests sent, answers received, gaps carried to the risk register — so the paper trail builds itself. Walkthrough: the due-diligence guide.
Try it on your tools, freeThis article is general information, not legal or professional advice. ComplyQS is not affiliated with or endorsed by RICS. Related guide: /guides/due-diligence/.