Pass Enterprise AI Vendor Due Diligence · Triodian

B2B AI & agent vendors

The questionnaire has 150 questions.
Your deal has a deadline.

A regulated enterprise wants to buy your product. Then procurement sends the AI risk, model lineage and drift-governance questionnaire, and a US$50k–250k contract goes quiet. The contract moves again when their reviewer receives answers they can check for themselves, rather than assurances they have to take on trust.

A$7,500  ·  US$5,000 fixed  ·  no data access  ·  report in 7–14 days
Book the Readiness Assessment → Why this passes review ↓

The forcing function

Procurement is now the regulator you actually face.

Healthcare, finance and legal buyers push their own compliance obligations down the vendor chain. Their third-party-risk teams ask how chained models, prompts and API calls are prevented from compounding errors, what your agent can never do and what enforces that, and how you would detect drift before their users do. General assurances about monitoring score poorly on these questionnaires.

The gate is also hardening. ISO 42001 is appearing as a named requirement in enterprise questionnaires in much the way SOC 2 did a decade ago, and since 2 August 2026 the EU AI Act's transparency and general-purpose-AI provisions apply to vendors whose output reaches the EU. Reviewers are rewarded for caution, so incomplete answers tend to default to a no.

Each week the questionnaire sits unanswered, your internal champion loses momentum and competitors with stronger compliance material get the next meeting.

The twenty questions that stall deals

What the reviewer is actually scoring.

Model lineage & versioning

Which models, prompts and parameters produce each output, what changed, when, and under whose sign-off. A versioned, signed release history answers this; a general description of your model provider does not.

Chained-pipeline controls

How errors compound across model, prompt and API stages, and what bounds them. Reviewers look for an enforcement mechanism here, not a monitoring plan.

Runtime guardrails

What your agent categorically cannot emit or execute, and whether that is enforced below the application or only requested of the model through a system prompt.

Drift governance

How you would know the system's aggregate behaviour has moved, at what threshold, and who is notified, before the customer's own audit finds it.

Why this passes review

Give them something they can check, not something they must believe.

A report from an unfamiliar vendor is a career risk for whoever accepts it. Triodian removes the dependence on reputation: every output a governed system emits carries a signed conformance record bound to a versioned rule set, and your buyer's procurement or TPRM reviewer can check that record independently, without dashboard access and without contacting us.

The capabilities behind it are shipped and badged deliverable now on this site: Structured Output Assurance, Bounded Command Governance, the Certifiable Conformance Pack, the Aggregate Drift Service and the Certified Miss-Rate.

Production proof: the governed-reasoning engine and provenance ledger behind these artefacts already run pinpole.cloud, a live commercial platform, at scale.

The first step

The Procurement Readiness Assessment.

What happens

A 90-minute structured interview with your risk and engineering leads. The assessment requires no system access, log export or InfoSec review, so nothing about it needs your security team's approval.

Within 7–14 days you receive a Diagnostic Gap Report covering model architecture, data provenance, evaluation pipeline, runtime controls and aggregate-drift exposure, mapped question by question to the questionnaire your buyer sent. It identifies the gaps their reviewer is most likely to raise, so you can close them before the review begins.

The terms

FeeA$7,500 / US$5,000, fixed
Cycle7–14 days, interview to report
AccessNone (interview only)
Credit50% creditable against the Evidence Pack within 45 days

The assessment fee is shown in both AUD and USD. Later stages are shown in AUD; US engagements are quoted from the USD price book.

Where it leads

Two follow-ons, depending on what your buyer wants to see.

Software only · self-onboarded

Certifiable Conformance Subscription

A$2,000/mo · 12-month minimum

A Rules-tier SDK or lightweight proxy your team onboards itself: out-of-set commands become unemittable, and every output ships with a signed conformance record you hand straight to the reviewer. A live control rather than a one-off report, reusable across every deal.

The Certifiable Conformance Pack →
Two-week turnaround · offline

Compliance & Procurement Evidence Pack

A$25,000 single pipeline

For buyers who want a dossier: an audit-grade model risk, lineage and aggregate-drift Evidence Pack addressed to their procurement team, built from historical log exports through an encrypted bucket. No firewall change and no InfoSec review on your side.

The Certified Miss-Rate →

Book your Readiness Assessment