Redefining Technology

Construction & InfrastructureRegulations, Compliance & Governance

AI governance for construction vendors: screening, contracting and verifying the AI your suppliers bring

AI vendor governance in construction is the discipline of controlling the AI systems suppliers bring onto your projects — from prequalification screening and subcontract AI schedules to site acceptance trials, in-service change notices and exit at practical completion. It matters because most AI on a construction site arrives through someone else's contract, not through your IT department.

Construction site office with supplier AI systems — progress cameras, drone survey and plant telematics — reviewed against a vendor register
Construction & Infrastructure · Regulations, Compliance & Governance

Key takeaways

  1. AI reaches a construction business by three routes — corporate procurement, project procurement and embedded arrival inside subcontract packages, plant hire and client-specified systems — and each route needs a different governance surface. Governing only the tools you bought directly leaves most of the estate unwatched.
  2. Govern vendors by the decision their AI touches and the route it arrived by, not by spend. A £900-a-month progress-vision subscription that feeds interim valuations carries more exposure than a seven-figure ERP module that never leaves head office.
  3. The enforcement surface already exists: the PQQ, the subcontract, the plant hire agreement and the tender scoresheet. Vendor governance that works is an AI schedule inside the procurement machinery a contractor already runs — not a new bureaucracy beside it.
  4. Never rely on a vendor's accuracy claim you have not tested on your own site. An acceptance trial against measured ground truth — one work section, agreed thresholds, before the output feeds a valuation or a safety decision — is the single highest-leverage control on this page.
  5. Practical completion is a vendor-governance event. Data return or deletion, licence continuity for the defects period, and the evidence pack for what the AI decided during the build all have to be contracted at signature, because at PC the leverage is gone.

Abbreviations used on this page

PQQ
Pre-qualification questionnaire (supplier screening stage)
NEC
New Engineering Contract (contract suite; option Z carries additional clauses)
JCT
Joint Contracts Tribunal (contract suite)
BIM
Building information modelling
CDE
Common data environment (the ISO 19650 project information store)
DPIA
Data protection impact assessment
PC
Practical completion
SAT
Site acceptance test (here: acceptance trial of a vendor's AI on live site data)
QS
Quantity surveyor
SLA
Service level agreement
LLM
Large language model
AIMS
AI management system (the ISO/IEC 42001 construct)

Free · 8 questions · ~3 minutes

Score how you govern the AI your suppliers bring

Eight questions, one at a time, about three minutes. Answer them and we build your personalised vendor-governance report — your stage on the ladder, your score on each of the four dimensions, and the specific gap between what your vendors have promised and what your contracts can enforce — and send it to your inbox.

0 of 8 answered

Question 1 of 8Procurement screening

When a package tender includes an AI-bearing system — progress cameras, drone survey, machine control — what does the tender ask about the AI?

Screening is cheapest before appointment: after signature, every question becomes a negotiation.

How the score maps to a stage
  • 05 — Stage 1, Unvetted. AI-bearing suppliers arrive through normal procurement with no AI-specific scrutiny — nobody can list which vendors run models on live projects, let alone what those models touch.
  • 611 — Stage 2, Screened. AI questions are asked before suppliers are appointed — a maintained register exists and tenders on sensitive packages carry an AI questionnaire — but nothing the vendor says becomes binding.
  • 1216 — Stage 3, Contracted. AI obligations are written into the paper vendors sign — data rights, model change notice, performance measures and exit — and flow-down clauses push the same obligations one tier below.
  • 1721 — Stage 4, Verified. Vendor claims are tested before reliance and watched in service — acceptance trials against site ground truth, in-service performance tracking, change notices that trigger re-verification, and verified flow-down.
  • 2224 — Stage 5, Portfolio-governed. Vendor governance is a corporate capability: an approved AI vendor list per category, framework agreements with pre-negotiated AI terms, performance history that prices tenders, and rehearsed exit plans.

What AI vendor governance means on a construction business

A definition, the three routes AI actually arrives by, and why the enforcement surface is the procurement machinery you already run.

AI vendor governance in construction is the set of controls a firm applies to AI systems it buys rather than builds — screening suppliers before appointment, binding them in contract, verifying their claims against the site, watching them in service and off-boarding them at practical completion. It is the outward-facing half of AI governance: the governance charter sets your own house rules, and this page is about the suppliers those rules must reach — because on most construction businesses, nearly all of the AI estate is someone else's product.

What makes the construction version of this problem distinctive is how AI arrives. It comes by three routes: corporate procurement (design and estimating tools licensed once, centrally), project procurement (progress vision, drone survey and monitoring systems bought per project, package by package), and embedded arrival — AI that turns up inside things you procured for other reasons: machine control on hired plant, a subcontractor's own tools, a monitoring system the client specified in the employer's requirements. Each route crosses a different desk, so no single function ever sees the whole estate — and the governance thesis of this page follows directly: govern vendors by the decision their AI touches and the route it arrived by, and enforce through the artefacts each route already produces — the PQQ, the subcontract, the plant hire agreement, the tender scoresheet.

Three routes an AI vendor takes onto a construction business

The governance surface is different on each route. Corporate procurement has a gate but covers the smallest share of the estate; project procurement is where most AI arrives and where the AI schedule does its work; embedded arrival has no purchase event at all — its controls are site rules, flow-down and the register.

  • Human in the loop
  • System-of-record action
  • Data & feeds
  • AI / model
  • Where value leaks

The process, in words

  • Corporate procurement is the governed route: design copilots and estimating tools pass an IT and legal review, master terms are negotiated once, and every project inherits them. It is also the smallest route — the corporate list is the estate most firms think they have.
  • Project procurement is where most AI actually arrives: progress vision, drone survey and monitoring systems bought package by package. The governance surface is the procurement lifecycle itself — an AI questionnaire scored at tender, an AI schedule appended to the subcontract, a site acceptance trial before the output feeds a decision, in-service monitoring against the contracted measure, and a contracted offboarding at practical completion.
  • Embedded arrival has no purchase event to govern: machine control arrives with the hired excavator, the subcontractor brings its own tools, the client specifies a monitoring platform in the employer's requirements. Its controls are declarative and contractual — a site-rules declaration at induction, flow-down clauses that survive the tiers, and entry onto the same register at the same tiers as everything bought directly.
Step-by-step insights
Why the corporate route misleads more than it protects
The corporate route works — that is exactly the problem. Because design and estimating tools pass a real gate, the firm's institutional memory says 'we govern our AI vendors', and the confidence generalises to an estate the gate never saw. On a typical contractor the corporate list is a minority of AI-bearing suppliers; the majority arrived through projects and packages. The first deliverable of any vendor-governance effort is therefore not a policy but a census: the corporate list, plus a trawl of live projects' subscriptions, plant and subcontractor systems, on one register with one owner.
The package tender is the highest-leverage moment on the page
Everything is negotiable before award and almost nothing after. The AI questionnaire costs the bidder an afternoon and costs you nothing; the same questions asked post-signature become change requests with prices attached. The mechanics matter: the questionnaire must be scored — visibly part of tender evaluation, so bidders take it seriously — and the winning answers must be annexed to the subcontract as warranted statements, or they evaporate the day the ink dries. That single administrative habit, answers-into-annex, is the cheapest control in this entire discipline.
The AI schedule — one artefact, many contracts
The schedule is a standard set of AI obligations drafted once and appended to whatever paper the route produces: an option Z clause set on an NEC subcontract, a supplemental schedule on a JCT form, an addendum to the plant hire agreement, a rider on a SaaS subscription. Drafting it per-deal is how legal teams drown; maintaining one tiered schedule — full depth for systems that feed valuations and safety decisions, light for advisory tools — is how coverage reaches the whole estate at a cost the business tolerates.
The acceptance trial is construction's own idea, applied to AI
Construction already refuses to energise a switchboard on the manufacturer's word — it runs a SAT. The acceptance trial applies the same instinct to a vendor's model: three weeks on one work section, output reconciled against ground truth the firm produced itself (the QS's measure, the setting-out survey, the supervisor's log), thresholds and a decision rule agreed before the trial starts. The trial's job is not to catch bad vendors — mostly it doesn't — it is to convert marketing accuracy into measured, site-specific accuracy, which is the number every later reliance decision should rest on.
Embedded arrival — governing purchases you never made
The embedded route cannot be governed at purchase because you were not the purchaser. Three controls substitute. Site rules: mobilisation and induction paperwork requires declaration of AI-bearing systems a subcontractor or hire firm brings, the same way lifting equipment is declared. Flow-down: your subcontract obliges the subcontractor to impose equivalent AI terms on its own chain, with evidence on request. The register: declared systems join the same register at the same tiers, so an excavator's machine control and your own progress cameras are visible to the same review. None of this is exotic — it is the plant-and-temporary-works pattern construction already runs, aimed at models instead of cranes.
Practical completion is a data event as well as a commercial one
At PC the vendor's commercial interest in your project ends, and with it your leverage. Three questions must already be answered in the contract: where does the captured data go (returned, deleted with certificate, or retained under what licence); what happens to the decision evidence — the outputs, alerts and audit logs a client or regulator may later ask about, which belong archived in the CDE with the rest of the project record; and what survives for the defects period, when the progress archive is often the cheapest way to establish what was built when. Firms that first think about this at handover discover the vendor's standard terms answered all three questions years earlier, in the vendor's favour.

The five stages: from Unvetted to Portfolio-governed

For each stage: what it looks like on a real contractor, the signals a reviewer can check in an afternoon, the anti-pattern that traps firms there, and what leaving costs.

The ladder below tracks one thing: how far the firm's control over supplier AI has travelled from visibility to enforceability to evidence. Stage 1 cannot see the estate; stage 2 can see it but not bind it; stage 3 binds conduct on paper; stage 4 verifies performance against the site; stage 5 pools the evidence into a portfolio capability. Each stage's detail is written for the people who run procurement and digital on a contracting business, not for a conference slide.

Defensible reliance on vendor AI, against position on the ladder

The curve inflects at stage 3–4: reliance a firm can defend to a client, an auditor or an insurer barely rises while knowledge stays contractually toothless, then climbs steeply once obligations are signed and claims are tested on site. The far end flattens — stage 5 adds speed and resilience more than new defensibility.

Reliance you can defend by stage

  • Stage 1 · Unvetted — 31% of operators. AI-bearing suppliers arrive through normal procurement with no AI-specific scrutiny — nobody can list which vendors run models on live projects, let alone what those models touch.
  • Stage 2 · Screened — 33% of operators. AI questions are asked before suppliers are appointed — a maintained register exists and tenders on sensitive packages carry an AI questionnaire — but nothing the vendor says becomes binding.
  • Stage 3 · Contracted — 21% of operators. AI obligations are written into the paper vendors sign — data rights, model change notice, performance measures and exit — and flow-down clauses push the same obligations one tier below.
  • Stage 4 · Verified — 11% of operators. Vendor claims are tested before reliance and watched in service — acceptance trials against site ground truth, in-service performance tracking, change notices that trigger re-verification, and verified flow-down.
  • Stage 5 · Portfolio-governed — 4% of operators. Vendor governance is a corporate capability: an approved AI vendor list per category, framework agreements with pre-negotiated AI terms, performance history that prices tenders, and rehearsed exit plans.

Curve shape: logistic, plotted from the stage data above. Distribution: Framing consistent with NIST AI Risk Management Framework third-party guidance.

Select a stage

Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.

Stage 1

Unvetted

31% of operators sit here

AI-bearing suppliers arrive through normal procurement with no AI-specific scrutiny — nobody can list which vendors run models on live projects, let alone what those models touch.

Stage 1 is not a decision anyone took; it is the default produced by how construction buys. AI does not arrive at a contractor the way it arrives at a bank — through an IT procurement gate — it arrives inside packages: a progress-monitoring subscription bought by a project team, machine control that came with the hired excavator, a drone survey sub-let two tiers down. Each purchase was individually reasonable, and nobody is positioned to see the whole.

The tell is the register question. Ask who could list, today, every supplier whose system runs a model on live projects — including the plant fleet and the subcontractors' own tools — and at stage 1 the honest answer is nobody. The corporate IT list exists, but it covers the smallest of the three arrival routes. The exposure is not hypothetical: the firm is already relying on model output in valuations, programme reviews and safety conversations without knowing it has done so.

What makes stage 1 expensive is that every commercial event happens on the vendor's paper. The click-through terms that came with the subscription typically grant the vendor broad rights over uploaded site data, disclaim accuracy entirely, and permit model changes without notice. None of that was negotiated, because nobody knew a negotiation was happening.

In practice

The subscription three people knew about

A regional contractor's commercial director, asked by a client's auditor which AI systems had touched the project, commissioned a one-week internal trawl. It found eleven: two corporate tools, four project-level subscriptions bought on purchasing cards, machine control on three items of hired plant, and two subcontractor-operated vision systems the firm had never seen terms for. The auditor's question could not be answered from any list the firm held — it was answered by asking site teams one by one.

What it looks like

  • No register of AI-bearing suppliers across projects
  • Tenders and PQQs ask about insurance and safety, never about models or training data
  • Vendor click-through terms are accepted unread at the point of subscription
  • Plant and subcontractor kit with embedded AI is invisible to the firm entirely

Diagnostic signals you can check this week

  • Ask three project teams which AI-bearing systems run on their site and compare the answers with the corporate supplier list
  • Pull the purchasing-card statements for one project and count the software subscriptions nobody in IT recognises
  • Check one hired excavator's spec sheet for machine-control and payload-estimation features nobody assessed
  • Find the signed terms for the progress-camera subscription — at stage 1 nobody can produce them

Anti-pattern · Sending every supplier a 40-page questionnaire

The instinctive fix is a blanket AI questionnaire to the whole supply chain — hundreds of suppliers, forty questions each. Most recipients do not run any AI, the ones that do answer defensively, and the returned paper is never read. The register dies of its own weight within a quarter. Inventory the estate first — one afternoon per live project — then aim questions only at the suppliers whose systems actually touch a decision, scaled to what the decision is worth.

What holds you here

Nobody can see the estate, so there is nothing to govern — every control downstream of a register does not exist yet.

Highest-leverage next move

Trawl three live projects for AI-bearing suppliers — including plant and subcontractor kit — and build the register with a named owner and renewal dates.

Cost of leaving

Effort
4–8 weeks
Team
One commercial manager and one digital/IT lead, part-time, with each project's senior team for an afternoon
Risk
Low — the work is a stocktake; nothing contractual changes yet
To next stage
1–2 months

If this is you, the next step is

A short engagement: three live projects trawled, the register built, the tiering applied.

Build your AI vendor register

Stage 2

Screened

33% of operators sit here

AI questions are asked before suppliers are appointed — a maintained register exists and tenders on sensitive packages carry an AI questionnaire — but nothing the vendor says becomes binding.

Stage 2 firms have solved visibility and mistaken it for control. The register is real and the tender questions are good ones — where does our site data go, is it used for training, who are your sub-suppliers, what accuracy do you claim and on what evidence. What is missing is consequence: the vendor's answers live in a tender file, and the contract that follows is the standard subcontract or the vendor's own terms, which say none of it.

This gap is invisible until it is tested. The vendor that answered 'your data is never used for cross-customer training' at tender is bound by the master subscription terms it signed, which say the opposite. Tender answers are representations at best; recovering anything on them is a litigation exercise, not a contract-management one. The practical result is that a stage-2 firm has excellent documentation of promises nobody has to keep.

Stage 2 is also where screening quality matters most, because it sets what stage 3 can bind. A questionnaire built from a generic IT-security template misses the questions construction actually needs answered: whether the model was trained on projects like yours, what happens to accuracy in rain and low light, whether the vendor's own drone sub-processor sees your site imagery, and what notice you get when the model changes. The frameworks to borrow from are published — the NIST AI Risk Management Framework for the risk vocabulary, ISO/IEC 42001 for what a vendor's management system should be able to evidence — but the questions must be translated into site terms or the answers will be marketing.

In practice

The tender answer that evaporated at renewal

A main contractor tendering a progress-monitoring package scored three bidders on an AI questionnaire. The winner's answers were exemplary — UK data residency, no training on customer imagery, named sub-processors. Eighteen months later, at renewal, the vendor's new master terms consolidated all customer data into a US-hosted training pool. Because the tender answers had never been annexed to the subscription agreement, nothing had been breached. The firm's only lever was to threaten non-renewal — mid-project, with eight sites live on the platform.

What it looks like

  • A maintained register of AI-bearing suppliers with named owner and renewal dates
  • An AI questionnaire runs at PQQ or tender stage on camera, survey and monitoring packages
  • Questionnaire answers influence selection but are not annexed to any contract
  • Plant hire and subcontractor-embedded AI is on the register but under no obligations

Diagnostic signals you can check this week

  • Take one AI questionnaire response and find the contract clause that makes any answer in it binding — at stage 2 there is none
  • Check whether the register records what each system's output feeds — a valuation, a programme, a safety decision — or just the vendor's name
  • Ask the QS on a live project whether the AI questionnaire result changed any tender score, or was filed unread
  • Compare the vendor's tender claim on data use with the signed subscription terms, line by line

Anti-pattern · Perfecting the questionnaire instead of the contract

Stage-2 firms iterate the questionnaire — more questions, sharper scoring, a prettier template — because the questionnaire is fully inside their control and the contract is not. A 60-question PQQ annexed to nothing is worth less than six questions whose answers are appended to the subcontract as warranted statements. Stop improving the asking; start making the answers survive into the paper the vendor actually signs.

What holds you here

Everything the firm knows about its vendors is a representation, not an obligation — the knowledge has no contractual teeth.

Highest-leverage next move

Draft a standard AI schedule and append it to the next subcontract or subscription on a sensitive package, with the tender answers annexed as warranted statements.

Cost of leaving

Effort
3–6 months
Team
Commercial/legal lead to draft the AI schedule, QS input on NEC/JCT mechanics, digital lead for the technical clauses
Risk
Medium — the first vendors asked to sign an AI schedule will push back, and some prices will move
To next stage
3–6 months

If this is you, the next step is

We draft the AI schedule against your standard subcontract and walk it through your first live negotiation.

Turn tender answers into contract terms

Stage 3

Contracted

21% of operators sit here

AI obligations are written into the paper vendors sign — data rights, model change notice, performance measures and exit — and flow-down clauses push the same obligations one tier below.

Stage 3 is where governance crosses the company boundary and becomes enforceable. The instrument is unglamorous: a schedule of AI obligations appended to documents the industry already executes — an NEC option Z clause set, a JCT supplemental schedule, an addendum to the plant hire agreement. It does not rewrite the contract; it adds the eight or so obligations the standard forms were never drafted to carry: who owns site data and derived outputs, whether the vendor may train on them, what notice a model change requires, what accuracy is warranted and what a miss entitles you to, which decisions require a human, what happens at exit.

The character of vendor conversations changes here. At stage 2 the firm asks and hopes; at stage 3 it trades. Vendors — especially venture-backed ones whose product roadmap depends on training data — will resist the training-use bar and the change-notice clause, and the negotiation reveals more about the vendor than any questionnaire: the vendor that cannot say who its model provider is has just answered a different question. Some pushback is legitimate and priced; wholesale refusal on a tier-1 package is a selection result.

The limit of stage 3 is that paper binds conduct, not performance. A signed accuracy warranty does not make the model accurate on your site, in your weather, on your trades. The firm has obligations it has never tested and flow-down clauses it has never verified below tier one — which is why the move to stage 4 is about evidence, not more drafting.

In practice

The plant hire addendum that took one page

An infrastructure contractor hiring GPS machine-control excavators added a one-page AI addendum to its standard plant hire terms: the hirer warrants the machine-control model version at mobilisation, notifies version changes during the hire, confirms telemetry from the contractor's sites is not used to train third-party models without consent, and provides the design-surface audit log on request. Two of the three hire firms signed unchanged. The third revealed it could not produce version information at all — which moved a safety-critical earthworks package to the firms that could.

What it looks like

  • A standard AI schedule exists and is appended to subcontracts, subscriptions and plant hire terms
  • Site data rights and a training-use bar are explicit, not inherited from vendor click-through terms
  • Vendors owe notice of model changes and disclosure of sub-suppliers and model providers
  • Flow-down is required in subcontracts, though rarely verified below the first tier

Diagnostic signals you can check this week

  • Pull the three most recent AI-bearing contracts and check for the schedule — coverage of new signings is the stage-3 metric
  • Find the training-use clause in the progress-vision subscription; at stage 3 it is yours, not the vendor's default
  • Ask what notice the firm received before the last model update on any vendor system — silence means the clause is absent or dead
  • Check whether the drone survey subcontractor's own operator agreement carries the flow-down — usually it does not, yet

Anti-pattern · Drafting for the worst vendor and losing the best ones

Legal teams new to AI schedules draft maximalist terms — unlimited liability for model error, source-code escrow, audit rights on the vendor's training pipeline. Sensible vendors walk away and the projects quietly revert to click-through terms, which is a net governance loss. Tier the schedule: the full set for systems feeding valuations and safety decisions, a light set for advisory tools. The objective is coverage of the estate, and an 80% schedule signed beats a 100% schedule refused.

What holds you here

The contract asserts performance nobody has measured — obligations exist on paper that have never been tested against the site.

Highest-leverage next move

Run a site acceptance trial on one contracted system — vendor output against measured ground truth on a defined work section — before its output feeds another valuation.

Cost of leaving

Effort
6–12 months to cover the estate as contracts renew
Team
Commercial lead owning the schedule, project QSs applying it, digital lead running verification design for stage 4
Risk
Medium — renewal cycles pace the rollout, and legacy signings stay on old terms until renegotiated
To next stage
6–12 months

If this is you, the next step is

We design the trial protocol — ground truth, thresholds, decision rule — for one contracted vendor system.

Design an acceptance trial

Stage 4

Verified

11% of operators sit here

Vendor claims are tested before reliance and watched in service — acceptance trials against site ground truth, in-service performance tracking, change notices that trigger re-verification, and verified flow-down.

Stage 4 replaces trust with measurement. The core instrument is the acceptance trial — construction already knows it as the SAT, and applying it to AI is a small conceptual step: before the progress-vision system's output enters a valuation, it runs for three weeks on one work section alongside the QS's measured quantities; before the safety-analytics alerts drive supervision, a month of alerts is reconciled against what supervisors actually found. The trial converts the vendor's warranted accuracy from a contract clause into a measured number on your site, your weather, your trades — and it is astonishing how often the two differ.

In-service oversight is the second half. Models change under commercial pressure: vendors retrain, swap model providers, ship new versions — and construction sites change too, from groundworks to fit-out, summer to winter. A system verified in April against a concrete frame may be materially worse in November against internal finishes. Stage-4 firms treat the contracted change notice as a trigger: notice arrives, a re-verification runs on the affected decision, and the result is logged where a client's auditor can find it. The evidence pack this produces — trial results, performance history, change log — is precisely what a stage-5 tender scoresheet consumes.

The discipline that keeps stage 4 affordable is proportionality. Not every vendor earns a trial: the tier the vendor was assigned at screening decides the depth — full trial and quarterly reconciliation for systems feeding valuations and safety, an annual spot-check for advisory tools. Firms that try to verify everything verify nothing within two quarters; the register's tiers are what make the workload survivable.

In practice

The trial that repriced the package

A contractor trialled a progress-vision vendor on one floor of a commercial frame for three weeks: the system's installed-quantity estimates against the QS's own measure, threshold agreed in advance at ±8% on the trades in scope. The vendor's marketing claimed 95% capture; the trial measured well outside the threshold on two of five trades — mechanical services in ceiling voids and in-wall first fix, both poorly lit and partially occluded. The outcome was not termination: the schedule's remedy clause converted the miss into a fee reduction and a scope carve-out — those two trades stayed on manual measure, the other three went live, and re-trial was set for the next floor cycle.

What it looks like

  • New AI systems pass a site acceptance trial before their output feeds a decision
  • In-service performance is tracked against the contracted measures, per project
  • A vendor model change triggers notified re-verification, not silent adoption
  • Flow-down is evidenced below tier one — the drone operator's terms have been read

Diagnostic signals you can check this week

  • Ask for the last acceptance-trial report and check it names ground truth, thresholds and a decision rule agreed before the trial
  • Check whether any vendor system's live performance is tracked against the contracted measure, or only complained about
  • Find the last model-change notice received and the re-verification it triggered — the pair is the stage-4 signature
  • Ask who has read the drone operator's terms two tiers down, and what evidence of flow-down exists in the file

Anti-pattern · Trialling against the vendor's own baseline

The failure mode is letting the vendor supply the ground truth — trials scored against the vendor's annotated imagery, or accuracy measured on the vendor's demonstration section. The trial then verifies the marketing, not the model. Ground truth must be yours: the QS's measure, the setting-out engineer's survey, the supervisor's incident log. If producing independent ground truth for a trial is too expensive, that is a signal the output was never independently checkable in service either — which is itself a governance finding.

What holds you here

Verification lives project by project — each project re-fights the same vendor battles, and nothing learned on one site prices the next tender.

Highest-leverage next move

Pool the evidence: an approved AI vendor list per category, with trial results and performance history feeding tender scoring across the portfolio.

Cost of leaving

Effort
12–18 months to make verification routine across tiers
Team
Digital lead owning trial protocols, QS and engineering time for ground truth, commercial lead wiring results to remedies
Risk
Medium — trials cost real site time, and a failed trial on a system already in use forces an uncomfortable decision
To next stage
12–18 months

If this is you, the next step is

We help you turn per-project verification into an approved-vendor capability the whole portfolio reuses.

Stand up portfolio governance

Stage 5

Portfolio-governed

4% of operators sit here

Vendor governance is a corporate capability: an approved AI vendor list per category, framework agreements with pre-negotiated AI terms, performance history that prices tenders, and rehearsed exit plans.

Stage 5 moves the unit of governance from the project to the portfolio. The instruments are familiar corporate ones: framework agreements with the AI schedule pre-negotiated, so a project calls off a progress-vision deployment the way it calls off scaffolding; an approved list per category — vision, survey, safety analytics, machine control, document AI — with entry earned by trial evidence and exit triggered by performance; and a vendor performance record that follows the vendor across projects, so the firm's own measured history, not the vendor's references, prices the next award.

What stage 5 buys is speed with control, and it is worth being precise about the mechanism. At stage 4 every project pays the governance cost locally — its own negotiation, its own trial design. At stage 5 the marginal project inherits the framework terms, the trial protocol per category, and the vendor's accumulated record; deploying a governed system on a new site becomes a two-week call-off instead of a two-quarter negotiation. Governance stops being the reason digital adoption is slow, which is the political result that keeps it funded.

The standing risks at stage 5 are concentration and staleness. An approved list hardens into a moat: the incumbent's record advantages it, challengers stop being trialled, and the firm wakes up dependent on one vendor for a decision class across the whole portfolio — which is why the exit plan is a stage-5 artefact, not a stage-3 one, and why it needs rehearsing against a live scenario: vendor acquired, vendor insolvent, model degraded and disputed. A list nobody has exited in two years is a list, not governance.

In practice

The acquisition that tested the exit plan

A tier-1 progress-vision vendor on a contractor's approved list was acquired by a larger platform company, which announced migration to new terms — different data residency, a broader training licence — at the next renewal. Because the framework agreement carried assignment-notice and data-return clauses, and because the approved list held a second verified vendor in the category, the firm executed its exit plan on four of nine live projects and renegotiated the remainder from a position the acquirer could see. Elapsed time from announcement to stable position: seven weeks, with no project losing its progress record.

What it looks like

  • An approved AI vendor list per category, maintained from portfolio-wide performance evidence
  • Framework agreements carry the AI schedule once, so projects call off rather than renegotiate
  • Vendor performance history feeds tender scoring and renewal decisions
  • Exit and substitution plans exist for every tier-1 system, and one has been rehearsed

Diagnostic signals you can check this week

  • Ask for the approved AI vendor list and the evidence behind the most recent addition and the most recent removal
  • Check whether any framework agreement carries the AI schedule, or whether every project still negotiates alone
  • Ask how the last tender in an AI-bearing category used the firm's own performance history in scoring
  • Ask when an exit or substitution was last rehearsed, and against which scenario

Anti-pattern · Letting the approved list become the ceiling

Once the list exists, procurement convenience favours incumbents forever: call-offs are easy, trials are effort, and the challenger vendor with a better model never gets measured. Within three years the list is a snapshot of the market as it was, defended by the process that built it. Reserve one trial slot per category per year for a challenger, and make list membership expire without fresh evidence — the list must be a live ranking, not a hall of fame.

What holds you here

Sustaining stage 5 is a renewal discipline — evidence goes stale, incumbents entrench, and the exit plans rot unless exercised.

Highest-leverage next move

Make list membership expire: fresh trial evidence per category per year, one challenger slot funded, one exit rehearsal on the calendar.

Cost of leaving

Effort
Continuous
Team
A small central function — commercial, digital, legal — plus category owners; projects consume, the centre maintains
Risk
Concentrated — the failure modes are portfolio-wide by construction: one bad framework term or one stale incumbent now touches every project at once

If this is you, the next step is

We stress-test the list, the frameworks and one exit plan against a live scenario, and report the gaps.

Audit your vendor governance annually

Where construction firms sit on vendor governance today

The distribution across the ladder, why the mode sits at Screened, and the regulatory floor rising underneath the whole curve.

Most construction firms sit at stages 1 and 2 — either unable to list their AI-bearing suppliers or able to list them without any contractual hold over them. The distribution below is illustrative, synthesised from published engineering-and-construction adoption research rather than measured from a survey panel, and its shape is the point: the population thins sharply at exactly the transition where knowledge has to become obligation.

Distribution of construction firms across the vendor-governance ladder

Illustrative distribution. The stage 2 → 3 drop is the structural one: an AI questionnaire costs an afternoon, while an AI schedule costs a negotiation — and only one of them survives contact with a vendor's lawyers.

Share of firms

  • 31% — 1 · Unvetted
  • 33% — 2 · Screened (the plateau)
  • 21% — 3 · Contracted
  • 11% — 4 · Verified
  • 4% — 5 · Portfolio-governed

Source: Illustrative, synthesised from McKinsey engineering & construction research

The regulatory floor under this curve is rising on three fronts, and all three route through vendor paper. Data protection: where a vendor's system processes site imagery or worker data, the vendor is usually a processor under Article 28 of the GDPR (opens in a new tab), which makes a written contract with specific mandatory terms a legal requirement, not a best practice — see the ICO's UK GDPR guidance (opens in a new tab) and the EDPB (opens in a new tab) on controller-processor duties, and the project GDPR governance page for the site-level treatment. AI-specific regulation: the EU AI Act allocates duties between providers and deployers, and a contractor deploying a vendor's system inherits the deployer's share. And assurance: ISO/IEC 42001 (opens in a new tab) gives vendors a certifiable AI management system to point at — increasingly via UK certification bodies such as BSI (opens in a new tab) — which is useful evidence and, as the FAQ below argues, not a substitute for site verification.

The construction AI vendor map: what to govern, how hard

Eight vendor categories, the decision each one touches, the route it arrives by, and the governance tier it earns — plus the two-axis test that assigns the tier.

Governance effort should follow the decision, not the invoice. The map below is the categorisation we use to tier AI vendors on a contracting business: what the system's output actually feeds — a valuation, a programme, a safety intervention, an excavation — which of the three routes it usually arrives by, and the governance tier that combination earns. Tier 1 gets the full treatment: scored questionnaire, full AI schedule, acceptance trial, in-service monitoring. Tier 2 gets the schedule and a proportionate trial. Tier 3 gets the register, the data clauses and an annual glance.

Vendor categoryThe decision its output feedsUsual arrival routeFailure looks likeTier
Progress-monitoring visionInterim valuations, programme reviews, claims evidenceProject procurementOver- or under-certification; a disputed programme record1
Site safety analyticsSupervision priorities, incident preventionProject procurementMissed hazards trusted as covered; alert fatigue1
Plant machine control & payload AIExcavation to design surface, lift and load decisionsEmbedded (plant hire)Wrong surface cut; a strike near live services1
Drone survey & reality captureEarthworks quantities, as-built verificationProject procurement (often sub-let)Quantity errors flowing into payment and dispute2
Design & BIM copilotsDesign options, clash resolution, model coordinationCorporate procurementA generated option carried into construction unchecked2
Estimating & bid AITender pricing, risk allowancesCorporate procurementSystematic mispricing; confidentiality leakage in prompts2
Document & contract AITender review, correspondence, claims draftingCorporate procurementHallucinated obligations; privileged material in training pools2
Scheduling & logistics optimisationSequence options, site logistics plansProject procurementA plausible but wrong sequence adopted under time pressure3
The construction AI vendor map. Tier reflects decision consequence and contractual proximity, not spend — note how often the highest-consequence systems arrive by the least-governed route.

Two features of this map deserve emphasis. First, the top of the tier column is dominated by systems that never pass a corporate gate: progress vision and safety analytics are bought by projects, and machine control arrives inside a plant hire agreement. The firm's most consequential AI vendors are precisely the ones its central governance never sees at stage 1. Second, 'failure looks like' is deliberately written in commercial and safety terms, not model terms — a vendor's model drifting is not the event; the event is the mis-certified valuation or the excavator cutting the wrong surface. Construction's own consequence scale is the right one: the sector HSE regulates (opens in a new tab) remains among the most dangerous to work in, which is why the safety-adjacent rows tier highest regardless of contract value.

Which governance depth does a vendor earn?

Plot each register entry on two axes: how the vendor arrived (contractual proximity) and what its failure costs (decision consequence). The quadrant sets the depth — and the top-left is where construction differs from every other industry's vendor governance.

Your site, someone else's AI

  • Machine control on hired plant; a sub-let drone operator
  • Highest exposure, weakest paper — the construction-specific quadrant
  • Fix: site-rules declaration, flow-down with evidence, hire-desk addendum

Verify before reliance

  • Progress vision feeding valuations; safety analytics
  • You hold the contract — use it
  • Fix: full AI schedule, acceptance trial, contracted hold points

Register and watch

  • Subcontractors' own estimating and planning tools
  • Low consequence to you, but invisible drift risk
  • Fix: induction declaration, register entry, annual review

Standard schedule

  • Document AI, scheduling assistants, design copilots
  • Direct contract, checkable output
  • Fix: light AI schedule — data clauses, change notice — and spot checks
Decision consequence — top: Safety-critical, irreversible or feeds payment, bottom: Advisory; rework is cheap and visible
Contractual proximity — left: Arrives inside someone else's package, right: You hold the contract

The embedded-arrival problem: governing AI you never procured

Machine control on hired plant, subcontractors' own tools and client-specified systems — the three shapes of AI that reach your site without a purchase decision you made.

The hardest vendors to govern are the ones you have no contract with. On a live construction site, a material share of the AI estate arrived embedded in something else — and because there was no purchase event on your side, the standard governance playbook has nothing to attach to. Three shapes of embedded arrival cover almost all of it, and each has a workable control that construction's existing machinery can carry.

  • Plant hire with embedded intelligence

    Modern excavators, dozers and cranes arrive with machine control, payload estimation and operator-assist features running models the hire agreement never mentions. The exposure is direct: machine control cuts to a design surface, and a wrong surface near live services is a safety event, not a software bug. The control is a hire-desk addendum — the hirer warrants the machine-control system and version at mobilisation, notifies changes during the hire, states whether telemetry from your sites trains third-party models, and provides audit logs on request. One page, attached at the same desk that already checks inspection certificates and operator tickets.

  • Subcontractors' own tools

    Your groundworks subcontractor runs its own drone operator; your M&E package uses its own fabrication-checking AI; half your chain drafts correspondence with an LLM. You cannot and should not approve their toolchains — but where their tools process your site's data or feed deliverables you certify, two controls apply: a declaration duty at mobilisation (AI-bearing systems declared under site rules, the way plant and temporary works already are) and a flow-down clause obliging the subcontractor to impose equivalent AI terms down its own chain, with evidence on request. Flow-down depth — how many tiers the obligation demonstrably survives — is the honest metric here, and at most firms today it is one.

  • Client-specified systems

    Increasingly the employer's requirements name the AI: the client mandates a progress-monitoring platform, a safety-analytics system or a carbon-tracking tool, and the contractor must operate it. You inherit deployer duties over a system you did not select and cannot swap. The control is at tender: price the governance, and qualify. Ask for the vendor's accuracy evidence and data terms as part of the employer's requirements, state in your tender what you will and will not rely on its output for, and record whose decision the system's failures belong to. A contractor that operates a client-specified system without that paper has silently adopted the client's vendor risk as its own.

The common thread is that embedded arrival is governed by declaration and flow-down rather than by selection — which is a pattern construction already trusts. Nobody expects to choose the subcontractor's scaffold supplier, but everybody expects the scaffold to be declared, inspected and tagged. Extending the same logic to models is culturally easy once it is framed that way; the mistake is trying to govern the embedded estate with procurement instruments, which have nothing to grip. Note what this section is not: retrofitting governance onto your own legacy site systems is a different problem with different controls, and it has its own page in this knowledge base.

What vendor relationships look like in public

Two publicly documented reference points — one from the buyer's side of the table, one from the vendor's — read against the ladder. Neither is an Atomic Loops engagement.

Public material on construction AI vendor relationships is thinner than the marketing suggests, but two kinds of evidence are genuinely instructive: a contractor that has publicly described operationalising a vendor's AI inside an existing discipline, and a vendor that publishes the transparency artefacts buyers should be demanding. One of each, below, read from the buyer's side of the ladder.

Two reference points read against the ladder

Outcomes as described in each organisation's own published material — follow the links and verify before reusing figures. Stages are our reading of the buyer-side behaviour each example illustrates, not a claim about either organisation's internal programme.

Shawmut Design and Construction project siteShawmut Design and ConstructionUS construction management firm · national project portfolio24
Challenge
Safety observation data across a national portfolio was too voluminous for human review to prioritise — the classic case for buying a vendor's AI rather than building one.
Approach
Shawmut has publicly described adopting AI-driven analysis of jobsite imagery and safety observations from specialist vendors, and — critically for the governance reading — wiring the output into an existing operating routine: risk indicators feeding the safety team's planning and supervision priorities rather than arriving as a standalone dashboard.
Reported outcome
Shawmut has publicly presented its use of predictive safety analytics as part of its safety programme across projects, positioning vendor AI as an input to supervisor attention rather than a replacement for it.
What it shows about the curveThe stage-4 behaviour is visible from outside: the vendor's output was given a defined consumer — an existing safety routine with named owners — before it was scaled. A vendor system whose output has a contracted destination and a human hold point is governed; the identical system running as an unowned dashboard is stage-2 exposure with better marketing.

Shawmut — news and announcements (opens in a new tab)

Autodesk design and construction software environmentAutodeskGlobal design & construction software vendor23
Challenge
Buyers of AI-assisted design and construction tools increasingly ask what a feature's model does, what data trained it, and what happens to customer data — questions most vendors answer ad hoc, deal by deal.
Approach
Autodesk publishes trust and transparency documentation for its AI capabilities through its trust centre, describing how AI features handle customer data — an example of a vendor systematising the disclosures that buyers otherwise have to extract through questionnaires.
Reported outcome
Published, per-capability transparency material that a contractor's screening process can consume directly — and cite in contract annexes — rather than negotiating disclosure from scratch.
What it shows about the curveMature vendors already produce the artefacts your PQQ should ask for; the governance test is simply whether a vendor can hand them over. A vendor that cannot produce transparency documentation, sub-supplier lists or model-change policies on request has answered your screening questionnaire by not answering it — and that finding belongs in the tender score.

Autodesk trust centre (opens in a new tab)

The AI schedule: what the contract must carry

Eight obligations, the contract mechanism that carries each one in NEC and JCT practice, and the evidence each produces when a client or auditor asks.

The AI schedule is a standard appendix, not a bespoke rewrite. Construction contracting already has the slots for it — additional condition sets on NEC forms, supplemental schedules and riders on JCT forms, addenda on plant hire and SaaS paper — and the discipline is to draft the obligations once, tier them, and let the QS append the right depth per package. The table below is the full-depth set for tier-1 systems; tiers 2 and 3 take subsets. Where the vendor processes personal data — site imagery with workers in frame, access records — the Article 28 processor terms sit alongside this schedule as a legal requirement, covered in depth by the project GDPR governance page; this schedule carries the obligations GDPR does not reach.

Schedule sectionWhat it obliges the vendor to doMechanismEvidence it produces
Site data rights & training-use barSite imagery, telemetry and derived outputs remain yours; no use in cross-customer training without written consentSchedule definitions + licence carve-out; overrides the vendor's standard termsA data-rights position you can state to a client in one sentence
Model change noticeNotify retraining, version changes and model-provider swaps before deployment to your projectsNotice clause with a defined period and a named recipientThe change log that pairs with re-verification records
Performance measures & remediesWarrant the measured accuracy from the acceptance trial; misses convert to defined remedies — fee relief, scope carve-out, re-trialWarranted statements annexed from tender answers + trial resultsA number to hold the vendor to, and what a miss is worth
Human hold pointsNamed decisions the system's output must not execute without your named role approvingOperational schedule referenced from the subcontractThe oversight record a deployer duty asks for
Sub-supplier & model-provider disclosureDisclose the chain — hosting, model provider, annotation subcontractors — and notify changesDisclosure annex + notification clauseThe chain map behind every processing and residency claim
Incident dutyNotify defined AI incidents within a set period; cooperate with your investigation; preserve logsIncident clause aligned to your site incident procedureThe timeline an investigator or insurer reconstructs later
Insurance & liability alignmentHold stated cover for AI-attributable errors; liability caps aligned to the decisions the system touchesInsurance schedule + liability clause reviewed against PI termsThe answer when your own insurer asks who carries model error
Exit & continuity at PCReturn or certifiably delete site data; export decision evidence to the CDE; state what survives for the defects periodExit clause with deliverables, tested once before PCThe offboarding certificate and the archived evidence pack
The eight sections of a construction AI schedule. 'Mechanism' names where the obligation typically lives in NEC/JCT contracting practice; 'evidence' is what the clause produces for a client, auditor or insurer.

Two drafting notes from the field. First, the schedule's power is in the annex habit: tender-questionnaire answers and acceptance-trial results are annexed as warranted statements, which is what converts screening and verification work into contract position without further negotiation. Second, resist the temptation to draft liability maximalism — the schedule's job is to make eight things explicit that standard forms leave silent, and a vendor's red line on one clause is tender intelligence, not an obstacle. The information-management backbone matters too: decision evidence lands in the project's CDE under ISO 19650 (opens in a new tab) conventions, so the AI record lives where the rest of the project record already lives.

The AI schedule checklist

Score your most consequential AI-bearing contract — the progress-vision subscription, the safety-analytics agreement, the machine-control hire. Tick what the signed paper actually contains; this list works without JavaScript.

0 of 8 ticked

0 of 8 — the vendor's lawyers wrote your governance

No ticks almost always means the click-through terms govern, and they answer every question in the vendor's favour. Do not start by renegotiating: start by reading what you signed — the gap list writes itself, and renewal is your moment. We can mark the terms up against this schedule in a week.

A 90-day plan: put one progress-vision vendor under governance

The stage 2 → 4 move made concrete on one common construction problem — a progress-monitoring vision system whose output feeds interim valuations, currently running on the vendor's own terms.

Vendor governance generalises badly and executes well. Rather than a firm-wide programme, the plan below runs the full lifecycle — register, schedule, trial, in-service wiring — on one live, high-consequence case that most contractors recognise: a progress-monitoring vision vendor on a commercial build, subscribed by the project eighteen months ago on click-through terms, whose installed-quantity estimates have quietly started informing the QS's interim valuations. One project, one vendor, one quarter — and every artefact it produces is reusable on the next package.

One vendor from click-through to verified, in one quarter

Scope discipline makes the 90 days: one project, one vendor, one decision (the valuation). If a phase needs more than its window, narrow the trade scope of the trial — not the plan.

  1. Days 1–15

    Register the estate, read the signed terms

    Trawl the project for every AI-bearing supplier — subscriptions, plant, subcontractor kit — and build the register with tiers. Pull the progress-vision vendor's actual signed terms and map them against the eight-section schedule: what the vendor may do with site imagery, what notice a model change requires, what exit provides. Name the commercial owner for the vendor relationship and confirm with the QS exactly how the system's output currently reaches the valuation.

    A tiered register; a gap map of the signed terms; one named owner

  2. Days 16–45

    Negotiate the AI schedule at the renewal window

    Draft the tier-1 schedule for this vendor — data rights and training-use bar, change notice, performance measures with remedies, hold points (the QS certifies; the system informs), disclosure, incident duty, exit at PC. Open the conversation at the renewal or an agreed variation, with the tender-stage questionnaire annexed. Expect movement on the training-use bar and the remedies clause; both are negotiable if the trial (next phase) is offered as the evidence base for the warranted numbers.

    The schedule agreed or the vendor's refusals documented for the tender file

  3. Days 46–70

    Run the acceptance trial against the QS's measure

    Three weeks, one floor or work section, trades agreed in advance. The system's installed-quantity estimates are reconciled weekly against the QS's own measure — ground truth the firm produces, never the vendor. Thresholds and the decision rule are fixed before the trial starts: within threshold, the output may inform (not replace) the valuation on those trades; outside it, the trade is carved out and re-trialled after the vendor's next model update.

    Measured, site-specific accuracy per trade; a signed trial report annexed to the schedule

  4. Days 71–90

    Wire the in-service loop and archive the evidence

    Stand up the small recurring machinery: change notices route to the named owner and trigger a one-day re-check on affected trades; monthly, the QS's measure on one rotating section is reconciled against the system as a drift check; the trial report, terms and change log are filed in the CDE with the project record. Close the quarter by presenting the vendor file to the client's team — the same pack answers auditor and insurer questions from now on.

    A governed, evidenced vendor relationship — and the template for the next package

The order matters

  1. Terms before trial

    Run the contract conversation before the acceptance trial, not after. A trial run under click-through terms produces evidence the vendor's licence may let it ignore — and a vendor that knows a warranted-performance clause is coming negotiates the trial protocol honestly, because it will live with the number.

  2. Trial before reliance

    The valuation is the decision that makes this vendor tier 1, so nothing from the system touches a certificate until the trial's decision rule says which trades qualify. Under-certification is a subcontractor cash-flow problem and over-certification is the firm's own money; neither is where you discover the model struggles with ceiling voids.

  3. One vendor before the estate

    The register will surface a dozen candidates and the temptation is to govern them all at once. Resist it. The first full lifecycle produces the schedule template, the trial protocol and the negotiation experience; the second vendor costs half as much, and the fifth is routine. Breadth before depth produces paperwork; depth before breadth produces capability.

Failure modes that unwind vendor governance

Vendor governance regresses through the vendor's lifecycle events, not through your own neglect. Four patterns account for most of it.

A governed vendor relationship decays through events on the vendor's side of the table — renewals, funding rounds, acquisitions, product pivots — that your controls were not written to survive. The four patterns below are the ones that undo otherwise competent stage-3 and stage-4 positions, each with the cheap preventive that keeps it theoretical.

Likelihood: highImpact: medium

The renewal that reset the terms

SaaS renewals arrive as continuity — same product, same login — while the master terms underneath are repapered: a broader training licence, new hosting, a different model provider. The negotiated AI schedule from two years ago quietly ceases to apply, and nobody on the project notices because nothing on screen changed.

PreventionRenewal dates live on the register with a 90-day flag; every renewal re-executes the schedule as a condition of continuation.

Likelihood: highImpact: high

The pilot that became infrastructure

A system brought in for a six-week trial on pilot terms — free tier, no schedule, sample-data promises — performs well and simply keeps running. Eighteen months later its output is embedded in valuations and progress reports across three projects, still on paper that disclaims everything. The firm's reliance grew; the governance never did.

PreventionPilot terms carry an expiry that hard-stops data flows; graduation to production requires the schedule and a trial, by rule not by memory.

Likelihood: mediumImpact: high

The vendor that got acquired

Construction AI vendors are acquisition targets by design. The acquirer consolidates terms, migrates hosting, swaps the model provider, or sunsets the product — and your project's data and evidence trail move jurisdictions with it. Assignment clauses in vendor paper typically permit all of this without your consent.

PreventionAssignment-notice and data-return triggers in the schedule, plus a second verified vendor per tier-1 category on the approved list.

Likelihood: mediumImpact: medium

Flow-down that stops one tier down

The subcontract carries the AI clauses, the subcontractor signs, and the obligation dies there: the drone operator two tiers down — the party actually running the model on your site's imagery — has never seen them. The firm's paper says the chain is governed; the chain says otherwise, and discovery arrives via an incident or a client audit.

PreventionFlow-down with evidence: the subcontractor produces its own chain's AI terms on request, sampled once per project per year.

Glossary

Hover a term for its definition — or expand the map full screen. The full definitions are written out below.

AI schedule
A standard appendix of AI-specific obligations — data rights, change notice, performance measures, hold points, disclosure, incident duty, insurance alignment, exit — appended to subcontracts, subscriptions and plant hire agreements, tiered by the exposure of the system it governs.
Arrival route
The path by which an AI-bearing system reaches the business: corporate procurement, project procurement, or embedded arrival inside plant hire, subcontract packages and client-specified systems. The route determines which governance surface can grip the vendor.
Acceptance trial
A bounded test of a vendor's AI on the buyer's own site before its output is relied on: one work section, ground truth produced by the buyer, thresholds and a decision rule agreed in advance. Construction's SAT discipline applied to a model.
Training-use bar
The contract clause preventing a vendor from using the buyer's site data — imagery, telemetry, documents — to train models offered to other customers without written consent. Vendor standard terms usually grant themselves the opposite.
Model change notice
The obligation on a vendor to notify retraining, version changes and model-provider swaps before they reach the buyer's projects, so that verification can be repeated on the decisions affected.
Flow-down depth
The number of contractual tiers an AI obligation demonstrably survives below the main contract — from subcontractor to their sub-let operators. Most flow-down today dies at tier one; the metric is depth with evidence, not clause presence.
Governance tier
The depth of control a vendor earns from the decision its system touches and the route it arrived by — full schedule, trial and monitoring at tier 1 down to register-and-review at tier 3. Tiering by spend instead of consequence is the canonical mistake.
Embedded AI
AI that reaches a site inside something procured for other reasons — machine control on hired plant, a subcontractor's own tools, a client-specified monitoring platform — and therefore never passes a purchase gate the firm controls.
Client-specified system
An AI system named in the employer's requirements that the contractor must operate without having selected it, inheriting deployer duties over someone else's vendor choice. Governed at tender: price the governance, qualify the reliance, record whose risk it is.
Offboarding at PC
The contracted exit executed at practical completion: site data returned or deletion certified, decision evidence exported to the CDE, and continuity stated for the defects period. Leverage to enforce any of it ends at handover, so it is drafted at signature.
Approved AI vendor list
A per-category list of vendors whose systems have passed trials and accumulated performance history across the portfolio, entitling projects to call off under framework terms. Membership expires without fresh evidence — a live ranking, not a hall of fame.
Warranted statement
A tender-questionnaire answer or trial result annexed to the contract so that it binds as a warranty rather than surviving only as a representation. The annex habit is what makes screening and verification work contractually real.

Frequently asked questions

The questions commercial directors, digital leads and QSs ask most often when the vendor conversation turns to AI.

What should we ask AI vendors at PQQ or tender stage?

Six questions carry most of the value: what does the model actually do and on what decisions; what data trained it and was any of it from projects like ours; where does our site data go and is it used for cross-customer training; who are the sub-suppliers, including the model provider and hosting; what accuracy is claimed and on what independent evidence; and what notice do we get when the model changes. Score the answers in tender evaluation and annex the winner's answers to the contract as warranted statements — unannexed answers evaporate at signature.

What is an AI schedule and where does it sit in an NEC or JCT contract?

An AI schedule is a standard appendix of AI-specific obligations — data rights, model change notice, performance measures, human hold points, sub-supplier disclosure, incident duty, insurance alignment and exit — drafted once and appended per contract. In NEC practice it typically travels as an additional (option Z) clause set with a defined schedule; in JCT practice as a supplemental schedule or rider; on plant hire and SaaS paper as an addendum. It does not rewrite the standard form — it adds the eight obligations the form was never drafted to carry.

How do we govern AI a subcontractor brings onto our site?

Through declaration and flow-down rather than selection. Site rules require AI-bearing systems to be declared at mobilisation and induction, the way plant and temporary works already are; the declared systems join your register at the appropriate tier. The subcontract carries a flow-down clause obliging the subcontractor to impose equivalent AI terms on its own chain — and, critically, to produce evidence on request, because flow-down that is required but never verified reliably dies one tier down, exactly where the drone operator processing your imagery sits.

How do we verify a vendor's accuracy claims before relying on them?

Run a site acceptance trial: three weeks or so on one work section, the system's output reconciled against ground truth your own team produces — the QS's measure, the setting-out survey, the supervisor's log — with thresholds and a decision rule agreed before the trial starts. Never let the vendor supply the ground truth or the trial section, or you are verifying the marketing. The measured result, annexed to the contract as the warranted performance, becomes the number every later reliance and remedy conversation uses.

A vendor is ISO/IEC 42001 certified. Is that enough assurance?

It is useful and insufficient. ISO/IEC 42001 certifies that the vendor operates an AI management system — governance process, roles, risk treatment — not that its model is accurate on your site, in your weather, on your trades. Treat certification as strong evidence at screening (it correlates with a vendor that can answer your questionnaire and produce artefacts) and as no substitute for the acceptance trial or the contract schedule. Certification paths, including what certification does and does not demonstrate, are covered in a dedicated page in this knowledge base.

Can progress-monitoring AI output be used in interim valuations?

Yes, as an input under a decision rule — not as the measure itself. The defensible pattern: a trial establishes per-trade accuracy against the QS's own measure; trades within threshold may have the system's output inform the valuation, with the QS certifying; trades outside threshold stay on manual measure. The certificate remains a human decision with the system as evidence, which keeps the QS's professional judgement — and the contract's payment machinery — where the standard forms assume it is. Uncontrolled use is how over-certification enters the account quietly.

What happens to our project data when the vendor contract ends?

Whatever the contract signed years earlier says — which, on vendor standard terms, usually means the vendor keeps a broad licence and you keep an export button until the subscription lapses. The schedule's exit clause reverses the default: site data returned or deletion certified, decision evidence — outputs, alerts, audit logs — exported to the CDE with the project record, and continuity stated for the defects period, when the progress archive is often the cheapest evidence of what was built when. Test the export path once before PC; an exit clause exercised for the first time at handover usually finds a gap.

The client specified the AI system in the employer's requirements. Where does that leave us?

Holding deployer duties over a vendor you did not choose — a position to price, not just accept. At tender: ask for the vendor's accuracy evidence, data terms and sub-supplier chain as part of the employer's requirements; state in your tender what you will and will not rely on its output for; and record whose risk the system's failures are. In delivery: register it, apply your hold points, and route its evidence into the CDE like any other tier-1 system. Operating a client-specified system without that paper silently adopts the client's vendor risk as your own.

Under the EU AI Act, are we the provider or the deployer when we buy construction AI?

Buying and operating a vendor's system makes you the deployer; the vendor is the provider. Deployer duties — using the system per its instructions, human oversight, monitoring, incident reporting — are yours and cannot be contracted away, but the information and cooperation you need to discharge them must come from the provider, which is exactly what the schedule's disclosure, change-notice and incident clauses secure. Note the boundary: substantially modifying a system or marketing it under your own name can shift provider duties onto you. The Act's construction-specific impact has its own page in this knowledge base.

Can a vendor train its models on our site data?

Only if the contract lets it — and vendor standard terms almost always do. The commercial issue is bigger than confidentiality: your site imagery, production rates and programme data are competitive information, and a model trained on them may be sold to your competitors as the vendor's product improvement. The training-use bar puts the default at no, with written consent as the exception — some firms trade consent for fees or product commitments, which is a legitimate deal once it is a deal rather than a licence term nobody read. Where imagery includes workers, GDPR duties apply on top.

What does machine control on hired plant change about vendor governance?

It moves a tier-1 system outside your procurement entirely: the AI arrives with the excavator, the vendor relationship belongs to the hire firm, and the failure mode — cutting the wrong surface near live services — is a safety event. The workable control is a one-page addendum at the hire desk: machine-control system and version warranted at mobilisation, changes notified during the hire, telemetry-training position stated, audit logs available on request. Hire firms that cannot answer the version question are telling you something a questionnaire never would — and that answer belongs in plant selection.

How many AI vendors does a typical contractor actually have?

More than anyone expects before the first register is built. A mid-size contractor's trawl typically surfaces systems across most of the eight categories on this page's vendor map — a corporate design or estimating tool or two, progress and safety systems bought per project, machine control across the hired fleet, and several subcontractor-operated systems nobody had listed. The precise count matters less than the register's coverage of the three arrival routes: a register that only lists corporate tools is measuring the governed minority and missing the consequential majority.

About the author

Atomic Loops Engineering

Industrial AI practice

Atomic Loops builds production AI systems for construction, manufacturing, logistics and energy operators — vision inspection, progress analytics, forecasting and decision support integrated into the systems that already run the work. That includes sitting on the buyer's side of the table when the AI is someone else's product.

  • · Production AI deployments on live construction and infrastructure projects
  • · Vendor due-diligence and acceptance-trial design run with contractor teams
  • · Integration-first delivery: CDE and site-system write-back, monitoring, rollback
  • · 13 cited sources on this page

Sources

  1. Information Commissioner's OfficeUK GDPR guidance and resources (opens in a new tab)
  2. Health and Safety ExecutiveConstruction health and safety (opens in a new tab)
  3. Health and Safety ExecutiveWork-related fatal injury statistics (opens in a new tab)
  4. ISOISO/IEC 42001 — AI management systems (opens in a new tab)
  5. ISOISO 19650-1 — information management using BIM (opens in a new tab)
  6. European CommissionAI Act regulatory framework (opens in a new tab)
  7. gdpr-info.eu (Intersoft Consulting)Article 28 GDPR — Processor (opens in a new tab)
  8. NISTAI Risk Management Framework (opens in a new tab)
  9. BSIBSI Group — standards and certification (opens in a new tab)
  10. EDPBEuropean Data Protection Board (opens in a new tab)
  11. McKinsey & CompanyEngineering, construction & building materials insights (opens in a new tab)
  12. Shawmut Design and ConstructionNews and announcements (opens in a new tab)
  13. AutodeskTrust centre (opens in a new tab)

Find out exactly where your vendor governance stands — then fix the weakest link

We run the assessment with your commercial and digital leads, benchmark your vendor terms against what the market is signing, and leave you with a 90-day plan for one live vendor — register, schedule, trial, evidence. You keep the plan and the artefacts whether or not we build with you.

Published · Last updated

Benchmark request

Tell us where to send it

Benchmark for this page

Used once, to send this benchmark and follow it up personally. No newsletter, no automated sequences.