← AI Governance Readiness Check

AI Vendor Risk Assessment Template

Use this before approving or materially expanding an AI vendor. Require written evidence where the answer matters.

Data & privacy

  1. What customer, employee, confidential, or personal data enters the system?
  2. Can prompts, files, outputs, logs, or embeddings be retained?
  3. Can customer data be used to train or improve vendor models?
  4. Where is data stored and processed, and which subprocessors receive it?
  5. What deletion, return, and retention commitments are contractual?

Security & access

  1. What independent security evidence is available?
  2. Are SSO, MFA, role-based access, logging, and administrative controls supported?
  3. How are model, plugin, connector, and API permissions constrained?
  4. How are prompt injection, data exfiltration, and unsafe tool actions addressed?
  5. What incident notification obligations apply?

AI-specific governance

  1. What models are used and how are material model changes communicated?
  2. What intended-use limits and known failure modes are documented?
  3. What testing, monitoring, evaluation, or human-oversight mechanisms exist?
  4. Can outputs be traced to model/version/configuration when an issue occurs?
  5. What happens to service quality or customer data if a model provider changes?

Commercial & exit risk

  1. Are uptime, support, incident, and continuity expectations explicit?
  2. Can the organization export its data and evidence cleanly?
  3. Can the AI feature be disabled without breaking the core workflow?
  4. What audit, regulatory-cooperation, or evidence rights exist?
  5. Is there a documented go / conditional / no-go decision with an owner?

This is an operational due-diligence starting point, not legal or security advice.

Get the structured workbook →