Analysis and buyer guides

Procurement Due Diligence for Autonomy Suppliers: A Checklist

1080 words6 sourcesUpdated 2026-08-24

Autonomy suppliers are unusually hard to diligence because the two things a buyer most wants to know — has it been fielded, and where does the human sit — are the two things a demonstration cannot show. This defence procurement due diligence checklist sets out twenty-five questions in five groups, each written so that the answer is a document, a date or a name rather than an assurance. Questions that cannot be answered in writing are themselves findings.

Group one: evidence of prior fielding

Start here, because every later question is cheaper to ask once you know whether anyone has bought the system before.

  1. Name every customer that has publicly announced an order, with the URL of each announcement.
  2. For any undisclosed customer, state the announcing party, the date and the value band that was published.
  3. Identify the single strongest independent source — not company-issued — describing the system in use, and supply the link.
  4. State whether any reported use was in operations, in a named exercise, or in a trial or evaluation.
  5. Give the date of the most recent delivery under a live contract, and confirm whether that contract remains in force.

The method for checking those answers against primary award databases is set out in how to verify a defence AI vendor's deployment claims. For a worked example of what the strongest answer looks like, the 13 Israeli companies with documented operational use each rest on a named outlet rather than a press release. Breaking Defense's August 2025 interview with Roboteam, on changes in unmanned combat, is the kind of source that survives this question; a slide reading "trusted by tier-one operators" is not.

Group two: where the human sits

Autonomy is a spectrum of specific functions, not a product attribute, and the vocabulary is not standardised across vendors. The distinctions that matter are set out at greater length in in the loop, on the loop, out of the loop.

  1. List each function the system performs autonomously — navigation, detection, classification, tracking, prioritisation, engagement — and state for each whether a human authorises, supervises, or is absent.
  2. Describe what happens on loss of link: does the platform hold, return, continue the task, or continue to an engagement?
  3. State whether the system can select a target without an operator action, and if so under what configuration and what constraint.
  4. Describe the abort path: who can stop an engagement, by what action, and what is the latency of that action.
  5. State what is logged at each decision point, in what format, and for how long it is retained.

US policy is the most widely used reference point for framing these questions. Department of Defense Directive 3000.09, reissued in January 2023, requires that autonomous and semi-autonomous weapon systems be designed to allow commanders and operators to exercise appropriate levels of human judgment over the use of force, and the Congressional Research Service publishes a short public summary of the policy and its definitions. Neither document binds a non-US buyer, and neither is a substitute for your own legal review, but both give a buyer a published vocabulary to hold a vendor to.

Group three: export, licensing and end use

An autonomy supplier can be technically suitable and legally unavailable to you. Establish that early, before a trial consumes a budget cycle.

  1. Confirm which national export authority licenses the system, and whether a licence covering your country exists, is applied for, or has not been sought.
  2. State whether the product classification permits the configuration you intend to buy, or only a reduced one.
  3. Identify any third-country content that triggers a second jurisdiction's controls, including US-origin components subject to re-export rules.
  4. Set out the end-use and re-transfer undertakings you will be asked to sign, and who signs them on your side.
  5. State what happens to licence status on a change of control of the vendor.

For Israeli suppliers specifically, the marketing licence and the export licence are separate instruments issued at different stages, and dual-use items sit with a different ministry again. What to ask, and where the official texts are published, is set out in Israeli defence export controls.

Group four: data, models and the update path

This is the group most often skipped and most likely to generate a dispute in year two.

  1. State what data the system collects, where it is stored, and whether any of it leaves your infrastructure.
  2. Confirm whether operational data from your deployment is used to train models served to other customers.
  3. Describe the model update mechanism: cadence, who approves a release, and whether you can decline one.
  4. State whether the system can run fully disconnected, and which functions degrade if it does.
  5. Set out what happens to models, weights and configuration if the contract ends or the vendor is acquired.

Group five: sustainment, obsolescence and exit

  1. Give the size of the field-support team and the number of people who have worked on this product for more than two years.
  2. State mean time to repair and spares lead time against actual fielded numbers, not a target.
  3. Identify single-source components, particularly sensors and compute, and the qualified alternative for each.
  4. State the training burden: hours to competence for an operator, and who delivers that training in your country.
  5. Set out the escrow, licence-back or transition arrangement that applies if the vendor fails.

A supplier at an early stage will answer several of these with "not yet". That is legitimate and worth recording as such. What should not pass is a confident answer with no document behind it, and a technology readiness level offered in place of a customer, a distinction covered in TRL is not deployment evidence.

How defence procurement due diligence maps to published evidence

Groups one and three are externally checkable; groups two, four and five are not, and depend entirely on what the vendor commits to in writing. That asymmetry is worth being explicit about internally, because it determines which answers belong in a contract and which belong in a risk register.

The Israeli Defence-AI Deployment Index grades 50 companies on group one alone, using four evidence grades. Twenty-two of the 50 sit at L2, meaning a publicly announced contract exists and nothing has been published about the system in use. For a buyer, an L2 supplier is not a weaker supplier; it is a supplier whose group-one answers will have to come from the company and its references rather than from the public record.

Limits of this reading

A checklist tests disclosure, not performance. Nothing above establishes that a system works, that its detection rates hold in your environment, or that its autonomy behaves as documented under degraded conditions. Only trials you run yourself, on your terrain, with your operators, answer that.

Public sourcing is also silent on classified programmes and on government-to-government business, both of which are substantial in this sector. A vendor with thin public evidence may be constrained rather than inexperienced, and the honest way to record that is as an open question, not a mark against them.

Frequently asked questions

What should a buyer ask an autonomous systems supplier first?

Ask for the URL of every publicly announced order and the single strongest independent report of the system in use. Those two answers are externally checkable within an hour and they determine how much weight the rest of the diligence has to carry.

Which published standard defines human control over autonomous weapons?

US Department of Defense Directive 3000.09, reissued in January 2023, is the most widely cited public reference. It requires that autonomous and semi-autonomous weapon systems be designed to allow commanders and operators to exercise appropriate levels of human judgment over the use of force.

Is a low public-evidence grade a reason to exclude a supplier?

No. Grades record what has been published, not capability. Classified contracts, undisclosed end users and government-to-government sales all produce thin public records. Treat a low grade as a prompt to source the evidence privately, in writing, rather than as a disqualification.

Sources

  1. idf.ai, The Israeli Defense-AI Deployment Index v1.0, 24 August 2026
  2. US Department of Defense, DoD Directive 3000.09, Autonomy in Weapon Systems, 25 January 2023
  3. Congressional Research Service, US Policy on Lethal Autonomous Weapon Systems
  4. SAM.gov, Contracting domain
  5. Breaking Defense, Israeli robotic defense firm sees big change in unmanned combat, August 2025
  6. DECA — Israel Defense Export Controls Agency, Ministry of Defense

Independent publication of idf.ai. Not affiliated with, endorsed by, or connected to the Israel Defense Forces, the Israeli Ministry of Defense, or any government body. Compiled entirely from publicly published sources. No classified, restricted or non-public information. Listed companies may dispute any entry: send the published source that contradicts it and the entry will be amended or removed.

Continue

The full index

All 50 companies, graded by publicly documented deployment evidence, with every source openable.

Open the index