Construction & InfrastructureRegulations, Compliance & Governance
AI governance for construction vendors: screening, contracting and verifying the AI your suppliers bring
AI vendor governance in construction is the discipline of controlling the AI systems suppliers bring onto your projects — from prequalification screening and subcontract AI schedules to site acceptance trials, in-service change notices and exit at practical completion. It matters because most AI on a construction site arrives through someone else's contract, not through your IT department.

Key takeaways
- AI reaches a construction business by three routes — corporate procurement, project procurement and embedded arrival inside subcontract packages, plant hire and client-specified systems — and each route needs a different governance surface. Governing only the tools you bought directly leaves most of the estate unwatched.
- Govern vendors by the decision their AI touches and the route it arrived by, not by spend. A £900-a-month progress-vision subscription that feeds interim valuations carries more exposure than a seven-figure ERP module that never leaves head office.
- The enforcement surface already exists: the PQQ, the subcontract, the plant hire agreement and the tender scoresheet. Vendor governance that works is an AI schedule inside the procurement machinery a contractor already runs — not a new bureaucracy beside it.
- Never rely on a vendor's accuracy claim you have not tested on your own site. An acceptance trial against measured ground truth — one work section, agreed thresholds, before the output feeds a valuation or a safety decision — is the single highest-leverage control on this page.
- Practical completion is a vendor-governance event. Data return or deletion, licence continuity for the defects period, and the evidence pack for what the AI decided during the build all have to be contracted at signature, because at PC the leverage is gone.
Abbreviations used on this page
- PQQ
- Pre-qualification questionnaire (supplier screening stage)
- NEC
- New Engineering Contract (contract suite; option Z carries additional clauses)
- JCT
- Joint Contracts Tribunal (contract suite)
- BIM
- Building information modelling
- CDE
- Common data environment (the ISO 19650 project information store)
- DPIA
- Data protection impact assessment
- PC
- Practical completion
- SAT
- Site acceptance test (here: acceptance trial of a vendor's AI on live site data)
- QS
- Quantity surveyor
- SLA
- Service level agreement
- LLM
- Large language model
- AIMS
- AI management system (the ISO/IEC 42001 construct)
Free · 8 questions · ~3 minutes
Score how you govern the AI your suppliers bring
Eight questions, one at a time, about three minutes. Answer them and we build your personalised vendor-governance report — your stage on the ladder, your score on each of the four dimensions, and the specific gap between what your vendors have promised and what your contracts can enforce — and send it to your inbox.
0 of 8 answered
Pick an option to continue
Report ready
Your personalised vendor-governance report is ready
Tell us where to send it. Your stage appears on screen straight away, and the full report — dimension scores, the promise-versus-paper gaps most common at your stage, and a 90-day plan for your weakest dimension — arrives in your inbox.
Your result
Your full report is on its way to your inbox.
Stage 1 · Unvetted
AI-bearing suppliers arrive through normal procurement with no AI-specific scrutiny — nobody can list which vendors run models on live projects, let alone what those models touch.
Your next moveTrawl three live projects for AI-bearing suppliers — including plant and subcontractor kit — and build the register with a named owner and renewal dates.
Stage 2 · Screened
AI questions are asked before suppliers are appointed — a maintained register exists and tenders on sensitive packages carry an AI questionnaire — but nothing the vendor says becomes binding.
Your next moveDraft a standard AI schedule and append it to the next subcontract or subscription on a sensitive package, with the tender answers annexed as warranted statements.
Stage 3 · Contracted
AI obligations are written into the paper vendors sign — data rights, model change notice, performance measures and exit — and flow-down clauses push the same obligations one tier below.
Your next moveRun a site acceptance trial on one contracted system — vendor output against measured ground truth on a defined work section — before its output feeds another valuation.
Stage 4 · Verified
Vendor claims are tested before reliance and watched in service — acceptance trials against site ground truth, in-service performance tracking, change notices that trigger re-verification, and verified flow-down.
Your next movePool the evidence: an approved AI vendor list per category, with trial results and performance history feeding tender scoring across the portfolio.
Stage 5 · Portfolio-governed
Vendor governance is a corporate capability: an approved AI vendor list per category, framework agreements with pre-negotiated AI terms, performance history that prices tenders, and rehearsed exit plans.
Your next moveMake list membership expire: fresh trial evidence per category per year, one challenger slot funded, one exit rehearsal on the calendar.
0 / 24
Procurement screening
— / 6
Contract & flow-down
— / 6
Deployment verification
— / 6
In-service oversight & exit
— / 6
Your score maps to a stage on the vendor-governance ladder. The dimension breakdown matters more than the total: a firm that contracts well but never verifies is exposed differently from one that verifies what its contracts cannot enforce — and the weakest dimension is where the next quarter belongs. Your lowest-scoring dimension is —, and that is where the next investment belongs.
Your score maps to a stage on the vendor-governance ladder. The dimension breakdown matters more than the total: a firm that contracts well but never verifies is exposed differently from one that verifies what its contracts cannot enforce — and the weakest dimension is where the next quarter belongs.Your four dimensions score evenly, so there is no single weak link to attack — follow the stage’s next move above rather than picking a dimension.
Want the weakest dimension turned into working paper?
We walk your commercial and digital leads through the dimension scores, then turn the weakest one into artefacts your teams can issue — tender questions for your next AI-bearing package, an AI schedule marked against your standard subcontract, or an acceptance-trial protocol for a system already live. You keep the artefacts either way.
How the score maps to a stage
- 0–5 — Stage 1, Unvetted. AI-bearing suppliers arrive through normal procurement with no AI-specific scrutiny — nobody can list which vendors run models on live projects, let alone what those models touch.
- 6–11 — Stage 2, Screened. AI questions are asked before suppliers are appointed — a maintained register exists and tenders on sensitive packages carry an AI questionnaire — but nothing the vendor says becomes binding.
- 12–16 — Stage 3, Contracted. AI obligations are written into the paper vendors sign — data rights, model change notice, performance measures and exit — and flow-down clauses push the same obligations one tier below.
- 17–21 — Stage 4, Verified. Vendor claims are tested before reliance and watched in service — acceptance trials against site ground truth, in-service performance tracking, change notices that trigger re-verification, and verified flow-down.
- 22–24 — Stage 5, Portfolio-governed. Vendor governance is a corporate capability: an approved AI vendor list per category, framework agreements with pre-negotiated AI terms, performance history that prices tenders, and rehearsed exit plans.
What AI vendor governance means on a construction business
A definition, the three routes AI actually arrives by, and why the enforcement surface is the procurement machinery you already run.
AI vendor governance in construction is the set of controls a firm applies to AI systems it buys rather than builds — screening suppliers before appointment, binding them in contract, verifying their claims against the site, watching them in service and off-boarding them at practical completion. It is the outward-facing half of AI governance: the governance charter sets your own house rules, and this page is about the suppliers those rules must reach — because on most construction businesses, nearly all of the AI estate is someone else's product.
What makes the construction version of this problem distinctive is how AI arrives. It comes by three routes: corporate procurement (design and estimating tools licensed once, centrally), project procurement (progress vision, drone survey and monitoring systems bought per project, package by package), and embedded arrival — AI that turns up inside things you procured for other reasons: machine control on hired plant, a subcontractor's own tools, a monitoring system the client specified in the employer's requirements. Each route crosses a different desk, so no single function ever sees the whole estate — and the governance thesis of this page follows directly: govern vendors by the decision their AI touches and the route it arrived by, and enforce through the artefacts each route already produces — the PQQ, the subcontract, the plant hire agreement, the tender scoresheet.
Three routes an AI vendor takes onto a construction business
The governance surface is different on each route. Corporate procurement has a gate but covers the smallest share of the estate; project procurement is where most AI arrives and where the AI schedule does its work; embedded arrival has no purchase event at all — its controls are site rules, flow-down and the register.
- Human in the loop
- System-of-record action
- Data & feeds
- AI / model
- Where value leaks
The process, in words
- Corporate procurement is the governed route: design copilots and estimating tools pass an IT and legal review, master terms are negotiated once, and every project inherits them. It is also the smallest route — the corporate list is the estate most firms think they have.
- Project procurement is where most AI actually arrives: progress vision, drone survey and monitoring systems bought package by package. The governance surface is the procurement lifecycle itself — an AI questionnaire scored at tender, an AI schedule appended to the subcontract, a site acceptance trial before the output feeds a decision, in-service monitoring against the contracted measure, and a contracted offboarding at practical completion.
- Embedded arrival has no purchase event to govern: machine control arrives with the hired excavator, the subcontractor brings its own tools, the client specifies a monitoring platform in the employer's requirements. Its controls are declarative and contractual — a site-rules declaration at induction, flow-down clauses that survive the tiers, and entry onto the same register at the same tiers as everything bought directly.
Step-by-step insights
- Why the corporate route misleads more than it protects
- The corporate route works — that is exactly the problem. Because design and estimating tools pass a real gate, the firm's institutional memory says 'we govern our AI vendors', and the confidence generalises to an estate the gate never saw. On a typical contractor the corporate list is a minority of AI-bearing suppliers; the majority arrived through projects and packages. The first deliverable of any vendor-governance effort is therefore not a policy but a census: the corporate list, plus a trawl of live projects' subscriptions, plant and subcontractor systems, on one register with one owner.
- The package tender is the highest-leverage moment on the page
- Everything is negotiable before award and almost nothing after. The AI questionnaire costs the bidder an afternoon and costs you nothing; the same questions asked post-signature become change requests with prices attached. The mechanics matter: the questionnaire must be scored — visibly part of tender evaluation, so bidders take it seriously — and the winning answers must be annexed to the subcontract as warranted statements, or they evaporate the day the ink dries. That single administrative habit, answers-into-annex, is the cheapest control in this entire discipline.
- The AI schedule — one artefact, many contracts
- The schedule is a standard set of AI obligations drafted once and appended to whatever paper the route produces: an option Z clause set on an NEC subcontract, a supplemental schedule on a JCT form, an addendum to the plant hire agreement, a rider on a SaaS subscription. Drafting it per-deal is how legal teams drown; maintaining one tiered schedule — full depth for systems that feed valuations and safety decisions, light for advisory tools — is how coverage reaches the whole estate at a cost the business tolerates.
- The acceptance trial is construction's own idea, applied to AI
- Construction already refuses to energise a switchboard on the manufacturer's word — it runs a SAT. The acceptance trial applies the same instinct to a vendor's model: three weeks on one work section, output reconciled against ground truth the firm produced itself (the QS's measure, the setting-out survey, the supervisor's log), thresholds and a decision rule agreed before the trial starts. The trial's job is not to catch bad vendors — mostly it doesn't — it is to convert marketing accuracy into measured, site-specific accuracy, which is the number every later reliance decision should rest on.
- Embedded arrival — governing purchases you never made
- The embedded route cannot be governed at purchase because you were not the purchaser. Three controls substitute. Site rules: mobilisation and induction paperwork requires declaration of AI-bearing systems a subcontractor or hire firm brings, the same way lifting equipment is declared. Flow-down: your subcontract obliges the subcontractor to impose equivalent AI terms on its own chain, with evidence on request. The register: declared systems join the same register at the same tiers, so an excavator's machine control and your own progress cameras are visible to the same review. None of this is exotic — it is the plant-and-temporary-works pattern construction already runs, aimed at models instead of cranes.
- Practical completion is a data event as well as a commercial one
- At PC the vendor's commercial interest in your project ends, and with it your leverage. Three questions must already be answered in the contract: where does the captured data go (returned, deleted with certificate, or retained under what licence); what happens to the decision evidence — the outputs, alerts and audit logs a client or regulator may later ask about, which belong archived in the CDE with the rest of the project record; and what survives for the defects period, when the progress archive is often the cheapest way to establish what was built when. Firms that first think about this at handover discover the vendor's standard terms answered all three questions years earlier, in the vendor's favour.
The five stages: from Unvetted to Portfolio-governed
For each stage: what it looks like on a real contractor, the signals a reviewer can check in an afternoon, the anti-pattern that traps firms there, and what leaving costs.
The ladder below tracks one thing: how far the firm's control over supplier AI has travelled from visibility to enforceability to evidence. Stage 1 cannot see the estate; stage 2 can see it but not bind it; stage 3 binds conduct on paper; stage 4 verifies performance against the site; stage 5 pools the evidence into a portfolio capability. Each stage's detail is written for the people who run procurement and digital on a contracting business, not for a conference slide.
Defensible reliance on vendor AI, against position on the ladder
The curve inflects at stage 3–4: reliance a firm can defend to a client, an auditor or an insurer barely rises while knowledge stays contractually toothless, then climbs steeply once obligations are signed and claims are tested on site. The far end flattens — stage 5 adds speed and resilience more than new defensibility.
Reliance you can defend by stage
- Stage 1 · Unvetted — 31% of operators. AI-bearing suppliers arrive through normal procurement with no AI-specific scrutiny — nobody can list which vendors run models on live projects, let alone what those models touch.
- Stage 2 · Screened — 33% of operators. AI questions are asked before suppliers are appointed — a maintained register exists and tenders on sensitive packages carry an AI questionnaire — but nothing the vendor says becomes binding.
- Stage 3 · Contracted — 21% of operators. AI obligations are written into the paper vendors sign — data rights, model change notice, performance measures and exit — and flow-down clauses push the same obligations one tier below.
- Stage 4 · Verified — 11% of operators. Vendor claims are tested before reliance and watched in service — acceptance trials against site ground truth, in-service performance tracking, change notices that trigger re-verification, and verified flow-down.
- Stage 5 · Portfolio-governed — 4% of operators. Vendor governance is a corporate capability: an approved AI vendor list per category, framework agreements with pre-negotiated AI terms, performance history that prices tenders, and rehearsed exit plans.
Curve shape: logistic, plotted from the stage data above. Distribution: Framing consistent with NIST AI Risk Management Framework third-party guidance.
Select a stage
Every stage's full detail is in the page source — the selector only changes which panel is visible, so nothing here depends on JavaScript to exist.
Stage 1
Unvetted
31% of operators sit here
AI-bearing suppliers arrive through normal procurement with no AI-specific scrutiny — nobody can list which vendors run models on live projects, let alone what those models touch.
Stage 1 is not a decision anyone took; it is the default produced by how construction buys. AI does not arrive at a contractor the way it arrives at a bank — through an IT procurement gate — it arrives inside packages: a progress-monitoring subscription bought by a project team, machine control that came with the hired excavator, a drone survey sub-let two tiers down. Each purchase was individually reasonable, and nobody is positioned to see the whole.
The tell is the register question. Ask who could list, today, every supplier whose system runs a model on live projects — including the plant fleet and the subcontractors' own tools — and at stage 1 the honest answer is nobody. The corporate IT list exists, but it covers the smallest of the three arrival routes. The exposure is not hypothetical: the firm is already relying on model output in valuations, programme reviews and safety conversations without knowing it has done so.
What makes stage 1 expensive is that every commercial event happens on the vendor's paper. The click-through terms that came with the subscription typically grant the vendor broad rights over uploaded site data, disclaim accuracy entirely, and permit model changes without notice. None of that was negotiated, because nobody knew a negotiation was happening.
In practice
The subscription three people knew about
A regional contractor's commercial director, asked by a client's auditor which AI systems had touched the project, commissioned a one-week internal trawl. It found eleven: two corporate tools, four project-level subscriptions bought on purchasing cards, machine control on three items of hired plant, and two subcontractor-operated vision systems the firm had never seen terms for. The auditor's question could not be answered from any list the firm held — it was answered by asking site teams one by one.
What it looks like
- No register of AI-bearing suppliers across projects
- Tenders and PQQs ask about insurance and safety, never about models or training data
- Vendor click-through terms are accepted unread at the point of subscription
- Plant and subcontractor kit with embedded AI is invisible to the firm entirely
Diagnostic signals you can check this week
- Ask three project teams which AI-bearing systems run on their site and compare the answers with the corporate supplier list
- Pull the purchasing-card statements for one project and count the software subscriptions nobody in IT recognises
- Check one hired excavator's spec sheet for machine-control and payload-estimation features nobody assessed
- Find the signed terms for the progress-camera subscription — at stage 1 nobody can produce them
Anti-pattern · Sending every supplier a 40-page questionnaire
The instinctive fix is a blanket AI questionnaire to the whole supply chain — hundreds of suppliers, forty questions each. Most recipients do not run any AI, the ones that do answer defensively, and the returned paper is never read. The register dies of its own weight within a quarter. Inventory the estate first — one afternoon per live project — then aim questions only at the suppliers whose systems actually touch a decision, scaled to what the decision is worth.
What holds you here
Nobody can see the estate, so there is nothing to govern — every control downstream of a register does not exist yet.
Highest-leverage next move
Trawl three live projects for AI-bearing suppliers — including plant and subcontractor kit — and build the register with a named owner and renewal dates.
Cost of leaving
- Effort
- 4–8 weeks
- Team
- One commercial manager and one digital/IT lead, part-time, with each project's senior team for an afternoon
- Risk
- Low — the work is a stocktake; nothing contractual changes yet
- To next stage
- 1–2 months
If this is you, the next step is
A short engagement: three live projects trawled, the register built, the tiering applied.
Stage 2
Screened
33% of operators sit here
AI questions are asked before suppliers are appointed — a maintained register exists and tenders on sensitive packages carry an AI questionnaire — but nothing the vendor says becomes binding.
Stage 2 firms have solved visibility and mistaken it for control. The register is real and the tender questions are good ones — where does our site data go, is it used for training, who are your sub-suppliers, what accuracy do you claim and on what evidence. What is missing is consequence: the vendor's answers live in a tender file, and the contract that follows is the standard subcontract or the vendor's own terms, which say none of it.
This gap is invisible until it is tested. The vendor that answered 'your data is never used for cross-customer training' at tender is bound by the master subscription terms it signed, which say the opposite. Tender answers are representations at best; recovering anything on them is a litigation exercise, not a contract-management one. The practical result is that a stage-2 firm has excellent documentation of promises nobody has to keep.
Stage 2 is also where screening quality matters most, because it sets what stage 3 can bind. A questionnaire built from a generic IT-security template misses the questions construction actually needs answered: whether the model was trained on projects like yours, what happens to accuracy in rain and low light, whether the vendor's own drone sub-processor sees your site imagery, and what notice you get when the model changes. The frameworks to borrow from are published — the NIST AI Risk Management Framework for the risk vocabulary, ISO/IEC 42001 for what a vendor's management system should be able to evidence — but the questions must be translated into site terms or the answers will be marketing.
In practice
The tender answer that evaporated at renewal
A main contractor tendering a progress-monitoring package scored three bidders on an AI questionnaire. The winner's answers were exemplary — UK data residency, no training on customer imagery, named sub-processors. Eighteen months later, at renewal, the vendor's new master terms consolidated all customer data into a US-hosted training pool. Because the tender answers had never been annexed to the subscription agreement, nothing had been breached. The firm's only lever was to threaten non-renewal — mid-project, with eight sites live on the platform.
What it looks like
- A maintained register of AI-bearing suppliers with named owner and renewal dates
- An AI questionnaire runs at PQQ or tender stage on camera, survey and monitoring packages
- Questionnaire answers influence selection but are not annexed to any contract
- Plant hire and subcontractor-embedded AI is on the register but under no obligations
Diagnostic signals you can check this week
- Take one AI questionnaire response and find the contract clause that makes any answer in it binding — at stage 2 there is none
- Check whether the register records what each system's output feeds — a valuation, a programme, a safety decision — or just the vendor's name
- Ask the QS on a live project whether the AI questionnaire result changed any tender score, or was filed unread
- Compare the vendor's tender claim on data use with the signed subscription terms, line by line
Anti-pattern · Perfecting the questionnaire instead of the contract
Stage-2 firms iterate the questionnaire — more questions, sharper scoring, a prettier template — because the questionnaire is fully inside their control and the contract is not. A 60-question PQQ annexed to nothing is worth less than six questions whose answers are appended to the subcontract as warranted statements. Stop improving the asking; start making the answers survive into the paper the vendor actually signs.
What holds you here
Everything the firm knows about its vendors is a representation, not an obligation — the knowledge has no contractual teeth.
Highest-leverage next move
Draft a standard AI schedule and append it to the next subcontract or subscription on a sensitive package, with the tender answers annexed as warranted statements.
Cost of leaving
- Effort
- 3–6 months
- Team
- Commercial/legal lead to draft the AI schedule, QS input on NEC/JCT mechanics, digital lead for the technical clauses
- Risk
- Medium — the first vendors asked to sign an AI schedule will push back, and some prices will move
- To next stage
- 3–6 months
If this is you, the next step is
We draft the AI schedule against your standard subcontract and walk it through your first live negotiation.
Stage 3
Contracted
21% of operators sit here
AI obligations are written into the paper vendors sign — data rights, model change notice, performance measures and exit — and flow-down clauses push the same obligations one tier below.
Stage 3 is where governance crosses the company boundary and becomes enforceable. The instrument is unglamorous: a schedule of AI obligations appended to documents the industry already executes — an NEC option Z clause set, a JCT supplemental schedule, an addendum to the plant hire agreement. It does not rewrite the contract; it adds the eight or so obligations the standard forms were never drafted to carry: who owns site data and derived outputs, whether the vendor may train on them, what notice a model change requires, what accuracy is warranted and what a miss entitles you to, which decisions require a human, what happens at exit.
The character of vendor conversations changes here. At stage 2 the firm asks and hopes; at stage 3 it trades. Vendors — especially venture-backed ones whose product roadmap depends on training data — will resist the training-use bar and the change-notice clause, and the negotiation reveals more about the vendor than any questionnaire: the vendor that cannot say who its model provider is has just answered a different question. Some pushback is legitimate and priced; wholesale refusal on a tier-1 package is a selection result.
The limit of stage 3 is that paper binds conduct, not performance. A signed accuracy warranty does not make the model accurate on your site, in your weather, on your trades. The firm has obligations it has never tested and flow-down clauses it has never verified below tier one — which is why the move to stage 4 is about evidence, not more drafting.
In practice
The plant hire addendum that took one page
An infrastructure contractor hiring GPS machine-control excavators added a one-page AI addendum to its standard plant hire terms: the hirer warrants the machine-control model version at mobilisation, notifies version changes during the hire, confirms telemetry from the contractor's sites is not used to train third-party models without consent, and provides the design-surface audit log on request. Two of the three hire firms signed unchanged. The third revealed it could not produce version information at all — which moved a safety-critical earthworks package to the firms that could.
What it looks like
- A standard AI schedule exists and is appended to subcontracts, subscriptions and plant hire terms
- Site data rights and a training-use bar are explicit, not inherited from vendor click-through terms
- Vendors owe notice of model changes and disclosure of sub-suppliers and model providers
- Flow-down is required in subcontracts, though rarely verified below the first tier
Diagnostic signals you can check this week
- Pull the three most recent AI-bearing contracts and check for the schedule — coverage of new signings is the stage-3 metric
- Find the training-use clause in the progress-vision subscription; at stage 3 it is yours, not the vendor's default
- Ask what notice the firm received before the last model update on any vendor system — silence means the clause is absent or dead
- Check whether the drone survey subcontractor's own operator agreement carries the flow-down — usually it does not, yet
Anti-pattern · Drafting for the worst vendor and losing the best ones
Legal teams new to AI schedules draft maximalist terms — unlimited liability for model error, source-code escrow, audit rights on the vendor's training pipeline. Sensible vendors walk away and the projects quietly revert to click-through terms, which is a net governance loss. Tier the schedule: the full set for systems feeding valuations and safety decisions, a light set for advisory tools. The objective is coverage of the estate, and an 80% schedule signed beats a 100% schedule refused.
What holds you here
The contract asserts performance nobody has measured — obligations exist on paper that have never been tested against the site.
Highest-leverage next move
Run a site acceptance trial on one contracted system — vendor output against measured ground truth on a defined work section — before its output feeds another valuation.
Cost of leaving
- Effort
- 6–12 months to cover the estate as contracts renew
- Team
- Commercial lead owning the schedule, project QSs applying it, digital lead running verification design for stage 4
- Risk
- Medium — renewal cycles pace the rollout, and legacy signings stay on old terms until renegotiated
- To next stage
- 6–12 months
If this is you, the next step is
We design the trial protocol — ground truth, thresholds, decision rule — for one contracted vendor system.
Stage 4
Verified
11% of operators sit here
Vendor claims are tested before reliance and watched in service — acceptance trials against site ground truth, in-service performance tracking, change notices that trigger re-verification, and verified flow-down.
Stage 4 replaces trust with measurement. The core instrument is the acceptance trial — construction already knows it as the SAT, and applying it to AI is a small conceptual step: before the progress-vision system's output enters a valuation, it runs for three weeks on one work section alongside the QS's measured quantities; before the safety-analytics alerts drive supervision, a month of alerts is reconciled against what supervisors actually found. The trial converts the vendor's warranted accuracy from a contract clause into a measured number on your site, your weather, your trades — and it is astonishing how often the two differ.
In-service oversight is the second half. Models change under commercial pressure: vendors retrain, swap model providers, ship new versions — and construction sites change too, from groundworks to fit-out, summer to winter. A system verified in April against a concrete frame may be materially worse in November against internal finishes. Stage-4 firms treat the contracted change notice as a trigger: notice arrives, a re-verification runs on the affected decision, and the result is logged where a client's auditor can find it. The evidence pack this produces — trial results, performance history, change log — is precisely what a stage-5 tender scoresheet consumes.
The discipline that keeps stage 4 affordable is proportionality. Not every vendor earns a trial: the tier the vendor was assigned at screening decides the depth — full trial and quarterly reconciliation for systems feeding valuations and safety, an annual spot-check for advisory tools. Firms that try to verify everything verify nothing within two quarters; the register's tiers are what make the workload survivable.
In practice
The trial that repriced the package
A contractor trialled a progress-vision vendor on one floor of a commercial frame for three weeks: the system's installed-quantity estimates against the QS's own measure, threshold agreed in advance at ±8% on the trades in scope. The vendor's marketing claimed 95% capture; the trial measured well outside the threshold on two of five trades — mechanical services in ceiling voids and in-wall first fix, both poorly lit and partially occluded. The outcome was not termination: the schedule's remedy clause converted the miss into a fee reduction and a scope carve-out — those two trades stayed on manual measure, the other three went live, and re-trial was set for the next floor cycle.
What it looks like
- New AI systems pass a site acceptance trial before their output feeds a decision
- In-service performance is tracked against the contracted measures, per project
- A vendor model change triggers notified re-verification, not silent adoption
- Flow-down is evidenced below tier one — the drone operator's terms have been read
Diagnostic signals you can check this week
- Ask for the last acceptance-trial report and check it names ground truth, thresholds and a decision rule agreed before the trial
- Check whether any vendor system's live performance is tracked against the contracted measure, or only complained about
- Find the last model-change notice received and the re-verification it triggered — the pair is the stage-4 signature
- Ask who has read the drone operator's terms two tiers down, and what evidence of flow-down exists in the file
Anti-pattern · Trialling against the vendor's own baseline
The failure mode is letting the vendor supply the ground truth — trials scored against the vendor's annotated imagery, or accuracy measured on the vendor's demonstration section. The trial then verifies the marketing, not the model. Ground truth must be yours: the QS's measure, the setting-out engineer's survey, the supervisor's incident log. If producing independent ground truth for a trial is too expensive, that is a signal the output was never independently checkable in service either — which is itself a governance finding.
What holds you here
Verification lives project by project — each project re-fights the same vendor battles, and nothing learned on one site prices the next tender.
Highest-leverage next move
Pool the evidence: an approved AI vendor list per category, with trial results and performance history feeding tender scoring across the portfolio.
Cost of leaving
- Effort
- 12–18 months to make verification routine across tiers
- Team
- Digital lead owning trial protocols, QS and engineering time for ground truth, commercial lead wiring results to remedies
- Risk
- Medium — trials cost real site time, and a failed trial on a system already in use forces an uncomfortable decision
- To next stage
- 12–18 months
If this is you, the next step is
We help you turn per-project verification into an approved-vendor capability the whole portfolio reuses.
Stage 5
Portfolio-governed
4% of operators sit here
Vendor governance is a corporate capability: an approved AI vendor list per category, framework agreements with pre-negotiated AI terms, performance history that prices tenders, and rehearsed exit plans.
Stage 5 moves the unit of governance from the project to the portfolio. The instruments are familiar corporate ones: framework agreements with the AI schedule pre-negotiated, so a project calls off a progress-vision deployment the way it calls off scaffolding; an approved list per category — vision, survey, safety analytics, machine control, document AI — with entry earned by trial evidence and exit triggered by performance; and a vendor performance record that follows the vendor across projects, so the firm's own measured history, not the vendor's references, prices the next award.
What stage 5 buys is speed with control, and it is worth being precise about the mechanism. At stage 4 every project pays the governance cost locally — its own negotiation, its own trial design. At stage 5 the marginal project inherits the framework terms, the trial protocol per category, and the vendor's accumulated record; deploying a governed system on a new site becomes a two-week call-off instead of a two-quarter negotiation. Governance stops being the reason digital adoption is slow, which is the political result that keeps it funded.
The standing risks at stage 5 are concentration and staleness. An approved list hardens into a moat: the incumbent's record advantages it, challengers stop being trialled, and the firm wakes up dependent on one vendor for a decision class across the whole portfolio — which is why the exit plan is a stage-5 artefact, not a stage-3 one, and why it needs rehearsing against a live scenario: vendor acquired, vendor insolvent, model degraded and disputed. A list nobody has exited in two years is a list, not governance.
In practice
The acquisition that tested the exit plan
A tier-1 progress-vision vendor on a contractor's approved list was acquired by a larger platform company, which announced migration to new terms — different data residency, a broader training licence — at the next renewal. Because the framework agreement carried assignment-notice and data-return clauses, and because the approved list held a second verified vendor in the category, the firm executed its exit plan on four of nine live projects and renegotiated the remainder from a position the acquirer could see. Elapsed time from announcement to stable position: seven weeks, with no project losing its progress record.
What it looks like
- An approved AI vendor list per category, maintained from portfolio-wide performance evidence
- Framework agreements carry the AI schedule once, so projects call off rather than renegotiate
- Vendor performance history feeds tender scoring and renewal decisions
- Exit and substitution plans exist for every tier-1 system, and one has been rehearsed
Diagnostic signals you can check this week
- Ask for the approved AI vendor list and the evidence behind the most recent addition and the most recent removal
- Check whether any framework agreement carries the AI schedule, or whether every project still negotiates alone
- Ask how the last tender in an AI-bearing category used the firm's own performance history in scoring
- Ask when an exit or substitution was last rehearsed, and against which scenario
Anti-pattern · Letting the approved list become the ceiling
Once the list exists, procurement convenience favours incumbents forever: call-offs are easy, trials are effort, and the challenger vendor with a better model never gets measured. Within three years the list is a snapshot of the market as it was, defended by the process that built it. Reserve one trial slot per category per year for a challenger, and make list membership expire without fresh evidence — the list must be a live ranking, not a hall of fame.
What holds you here
Sustaining stage 5 is a renewal discipline — evidence goes stale, incumbents entrench, and the exit plans rot unless exercised.
Highest-leverage next move
Make list membership expire: fresh trial evidence per category per year, one challenger slot funded, one exit rehearsal on the calendar.
Cost of leaving
- Effort
- Continuous
- Team
- A small central function — commercial, digital, legal — plus category owners; projects consume, the centre maintains
- Risk
- Concentrated — the failure modes are portfolio-wide by construction: one bad framework term or one stale incumbent now touches every project at once
If this is you, the next step is
We stress-test the list, the frameworks and one exit plan against a live scenario, and report the gaps.
Where construction firms sit on vendor governance today
The distribution across the ladder, why the mode sits at Screened, and the regulatory floor rising underneath the whole curve.
Most construction firms sit at stages 1 and 2 — either unable to list their AI-bearing suppliers or able to list them without any contractual hold over them. The distribution below is illustrative, synthesised from published engineering-and-construction adoption research rather than measured from a survey panel, and its shape is the point: the population thins sharply at exactly the transition where knowledge has to become obligation.
Distribution of construction firms across the vendor-governance ladder
Illustrative distribution. The stage 2 → 3 drop is the structural one: an AI questionnaire costs an afternoon, while an AI schedule costs a negotiation — and only one of them survives contact with a vendor's lawyers.
Share of firms
- 31% — 1 · Unvetted
- 33% — 2 · Screened (the plateau)
- 21% — 3 · Contracted
- 11% — 4 · Verified
- 4% — 5 · Portfolio-governed
Source: Illustrative, synthesised from McKinsey engineering & construction research
The regulatory floor under this curve is rising on three fronts, and all three route through vendor paper. Data protection: where a vendor's system processes site imagery or worker data, the vendor is usually a processor under Article 28 of the GDPR (opens in a new tab), which makes a written contract with specific mandatory terms a legal requirement, not a best practice — see the ICO's UK GDPR guidance (opens in a new tab) and the EDPB (opens in a new tab) on controller-processor duties, and the project GDPR governance page for the site-level treatment. AI-specific regulation: the EU AI Act allocates duties between providers and deployers, and a contractor deploying a vendor's system inherits the deployer's share. And assurance: ISO/IEC 42001 (opens in a new tab) gives vendors a certifiable AI management system to point at — increasingly via UK certification bodies such as BSI (opens in a new tab) — which is useful evidence and, as the FAQ below argues, not a substitute for site verification.
The construction AI vendor map: what to govern, how hard
Eight vendor categories, the decision each one touches, the route it arrives by, and the governance tier it earns — plus the two-axis test that assigns the tier.
Governance effort should follow the decision, not the invoice. The map below is the categorisation we use to tier AI vendors on a contracting business: what the system's output actually feeds — a valuation, a programme, a safety intervention, an excavation — which of the three routes it usually arrives by, and the governance tier that combination earns. Tier 1 gets the full treatment: scored questionnaire, full AI schedule, acceptance trial, in-service monitoring. Tier 2 gets the schedule and a proportionate trial. Tier 3 gets the register, the data clauses and an annual glance.
| Vendor category | The decision its output feeds | Usual arrival route | Failure looks like | Tier |
|---|---|---|---|---|
| Progress-monitoring vision | Interim valuations, programme reviews, claims evidence | Project procurement | Over- or under-certification; a disputed programme record | 1 |
| Site safety analytics | Supervision priorities, incident prevention | Project procurement | Missed hazards trusted as covered; alert fatigue | 1 |
| Plant machine control & payload AI | Excavation to design surface, lift and load decisions | Embedded (plant hire) | Wrong surface cut; a strike near live services | 1 |
| Drone survey & reality capture | Earthworks quantities, as-built verification | Project procurement (often sub-let) | Quantity errors flowing into payment and dispute | 2 |
| Design & BIM copilots | Design options, clash resolution, model coordination | Corporate procurement | A generated option carried into construction unchecked | 2 |
| Estimating & bid AI | Tender pricing, risk allowances | Corporate procurement | Systematic mispricing; confidentiality leakage in prompts | 2 |
| Document & contract AI | Tender review, correspondence, claims drafting | Corporate procurement | Hallucinated obligations; privileged material in training pools | 2 |
| Scheduling & logistics optimisation | Sequence options, site logistics plans | Project procurement | A plausible but wrong sequence adopted under time pressure | 3 |
Two features of this map deserve emphasis. First, the top of the tier column is dominated by systems that never pass a corporate gate: progress vision and safety analytics are bought by projects, and machine control arrives inside a plant hire agreement. The firm's most consequential AI vendors are precisely the ones its central governance never sees at stage 1. Second, 'failure looks like' is deliberately written in commercial and safety terms, not model terms — a vendor's model drifting is not the event; the event is the mis-certified valuation or the excavator cutting the wrong surface. Construction's own consequence scale is the right one: the sector HSE regulates (opens in a new tab) remains among the most dangerous to work in, which is why the safety-adjacent rows tier highest regardless of contract value.
Which governance depth does a vendor earn?
Plot each register entry on two axes: how the vendor arrived (contractual proximity) and what its failure costs (decision consequence). The quadrant sets the depth — and the top-left is where construction differs from every other industry's vendor governance.
Your site, someone else's AI
- Machine control on hired plant; a sub-let drone operator
- Highest exposure, weakest paper — the construction-specific quadrant
- Fix: site-rules declaration, flow-down with evidence, hire-desk addendum
Verify before reliance
- Progress vision feeding valuations; safety analytics
- You hold the contract — use it
- Fix: full AI schedule, acceptance trial, contracted hold points
Register and watch
- Subcontractors' own estimating and planning tools
- Low consequence to you, but invisible drift risk
- Fix: induction declaration, register entry, annual review
Standard schedule
- Document AI, scheduling assistants, design copilots
- Direct contract, checkable output
- Fix: light AI schedule — data clauses, change notice — and spot checks
The embedded-arrival problem: governing AI you never procured
Machine control on hired plant, subcontractors' own tools and client-specified systems — the three shapes of AI that reach your site without a purchase decision you made.
The hardest vendors to govern are the ones you have no contract with. On a live construction site, a material share of the AI estate arrived embedded in something else — and because there was no purchase event on your side, the standard governance playbook has nothing to attach to. Three shapes of embedded arrival cover almost all of it, and each has a workable control that construction's existing machinery can carry.
Plant hire with embedded intelligence
Modern excavators, dozers and cranes arrive with machine control, payload estimation and operator-assist features running models the hire agreement never mentions. The exposure is direct: machine control cuts to a design surface, and a wrong surface near live services is a safety event, not a software bug. The control is a hire-desk addendum — the hirer warrants the machine-control system and version at mobilisation, notifies changes during the hire, states whether telemetry from your sites trains third-party models, and provides audit logs on request. One page, attached at the same desk that already checks inspection certificates and operator tickets.
Subcontractors' own tools
Your groundworks subcontractor runs its own drone operator; your M&E package uses its own fabrication-checking AI; half your chain drafts correspondence with an LLM. You cannot and should not approve their toolchains — but where their tools process your site's data or feed deliverables you certify, two controls apply: a declaration duty at mobilisation (AI-bearing systems declared under site rules, the way plant and temporary works already are) and a flow-down clause obliging the subcontractor to impose equivalent AI terms down its own chain, with evidence on request. Flow-down depth — how many tiers the obligation demonstrably survives — is the honest metric here, and at most firms today it is one.
Client-specified systems
Increasingly the employer's requirements name the AI: the client mandates a progress-monitoring platform, a safety-analytics system or a carbon-tracking tool, and the contractor must operate it. You inherit deployer duties over a system you did not select and cannot swap. The control is at tender: price the governance, and qualify. Ask for the vendor's accuracy evidence and data terms as part of the employer's requirements, state in your tender what you will and will not rely on its output for, and record whose decision the system's failures belong to. A contractor that operates a client-specified system without that paper has silently adopted the client's vendor risk as its own.
The common thread is that embedded arrival is governed by declaration and flow-down rather than by selection — which is a pattern construction already trusts. Nobody expects to choose the subcontractor's scaffold supplier, but everybody expects the scaffold to be declared, inspected and tagged. Extending the same logic to models is culturally easy once it is framed that way; the mistake is trying to govern the embedded estate with procurement instruments, which have nothing to grip. Note what this section is not: retrofitting governance onto your own legacy site systems is a different problem with different controls, and it has its own page in this knowledge base.
What vendor relationships look like in public
Two publicly documented reference points — one from the buyer's side of the table, one from the vendor's — read against the ladder. Neither is an Atomic Loops engagement.
Public material on construction AI vendor relationships is thinner than the marketing suggests, but two kinds of evidence are genuinely instructive: a contractor that has publicly described operationalising a vendor's AI inside an existing discipline, and a vendor that publishes the transparency artefacts buyers should be demanding. One of each, below, read from the buyer's side of the ladder.
Two reference points read against the ladder
Outcomes as described in each organisation's own published material — follow the links and verify before reusing figures. Stages are our reading of the buyer-side behaviour each example illustrates, not a claim about either organisation's internal programme.
Shawmut Design and ConstructionUS construction management firm · national project portfolio24
- Challenge
- Safety observation data across a national portfolio was too voluminous for human review to prioritise — the classic case for buying a vendor's AI rather than building one.
- Approach
- Shawmut has publicly described adopting AI-driven analysis of jobsite imagery and safety observations from specialist vendors, and — critically for the governance reading — wiring the output into an existing operating routine: risk indicators feeding the safety team's planning and supervision priorities rather than arriving as a standalone dashboard.
- Reported outcome
- Shawmut has publicly presented its use of predictive safety analytics as part of its safety programme across projects, positioning vendor AI as an input to supervisor attention rather than a replacement for it.
- What it shows about the curveThe stage-4 behaviour is visible from outside: the vendor's output was given a defined consumer — an existing safety routine with named owners — before it was scaled. A vendor system whose output has a contracted destination and a human hold point is governed; the identical system running as an unowned dashboard is stage-2 exposure with better marketing.
AutodeskGlobal design & construction software vendor23
- Challenge
- Buyers of AI-assisted design and construction tools increasingly ask what a feature's model does, what data trained it, and what happens to customer data — questions most vendors answer ad hoc, deal by deal.
- Approach
- Autodesk publishes trust and transparency documentation for its AI capabilities through its trust centre, describing how AI features handle customer data — an example of a vendor systematising the disclosures that buyers otherwise have to extract through questionnaires.
- Reported outcome
- Published, per-capability transparency material that a contractor's screening process can consume directly — and cite in contract annexes — rather than negotiating disclosure from scratch.
- What it shows about the curveMature vendors already produce the artefacts your PQQ should ask for; the governance test is simply whether a vendor can hand them over. A vendor that cannot produce transparency documentation, sub-supplier lists or model-change policies on request has answered your screening questionnaire by not answering it — and that finding belongs in the tender score.