← AI Governance Readiness Check
AI Vendor Risk Assessment Template
Use this before approving or materially expanding an AI vendor. Require written evidence where the answer matters.
Data & privacy
- What customer, employee, confidential, or personal data enters the system?
- Can prompts, files, outputs, logs, or embeddings be retained?
- Can customer data be used to train or improve vendor models?
- Where is data stored and processed, and which subprocessors receive it?
- What deletion, return, and retention commitments are contractual?
Security & access
- What independent security evidence is available?
- Are SSO, MFA, role-based access, logging, and administrative controls supported?
- How are model, plugin, connector, and API permissions constrained?
- How are prompt injection, data exfiltration, and unsafe tool actions addressed?
- What incident notification obligations apply?
AI-specific governance
- What models are used and how are material model changes communicated?
- What intended-use limits and known failure modes are documented?
- What testing, monitoring, evaluation, or human-oversight mechanisms exist?
- Can outputs be traced to model/version/configuration when an issue occurs?
- What happens to service quality or customer data if a model provider changes?
Commercial & exit risk
- Are uptime, support, incident, and continuity expectations explicit?
- Can the organization export its data and evidence cleanly?
- Can the AI feature be disabled without breaking the core workflow?
- What audit, regulatory-cooperation, or evidence rights exist?
- Is there a documented go / conditional / no-go decision with an owner?