All insights

Governance

A due-diligence checklist for evaluating an agentic AI partner

4 min read

Most agentic AI vendor pitches look similar on the surface — impressive demo, confident roadmap, a handful of logos. The differences that actually matter usually only show up if you ask directly. Here's the list worth working through before you sign anything.

Architecture

  • If we need a new use case in six months, does it require a new integration, or does it plug into what already exists?
  • Is the system built on open protocols (MCP, A2A) or a proprietary stack we'd be locked into?
  • Can you show the architecture, not just the demo?

Governance

  • Who owns an agent once it's live — and what does that role actually do day to day?
  • What happens when the agent is wrong? Walk me through the incident, not the happy path.
  • Can you produce an explanation for any single decision the system has made, on demand?
  • Which regulatory frameworks does the architecture already map to (NIST AI RMF, ISO 42001, sector-specific rules)?

Delivery

  • What do we see in week two — and is it working software, or a slide?
  • Who's actually on the team day to day, and are they the people in this meeting?
  • What's the plan for our team to run this without you? Is it in the contract, or a vague promise?

Proof

  • Is this platform running anything in production today — including the vendor's own product, if they have one?
  • Can they describe a real deployment in enough detail to be credible, even if the client name is confidential?

A vendor who answers these directly, with specifics, is telling you more than any case study could. A vendor who redirects to the roadmap is telling you something too.

Not sure where your use case fits?

Take the five-minute Agentic Readiness Assessment for a tailored starting point.