Know the risk before you trust an AI vendor
Turn vendor claims and reviewed evidence into a transparent decision brief across privacy, security, AI governance, contracts, and operational resilience.
- 28 control questions
- 5 weighted dimensions
- Context-aware red flags
- Vendor question list
- CSV and print report
Five dimensions, explicit evidence gaps
The assessment adapts public risk-management and secure-AI guidance into a practical vendor-review aid. It is not affiliated with, endorsed by, or a certification from any source organization.
Data & privacy
Use, retention, deletion, location, subprocessors, isolation, and encryption.
Security & access
Identity, roles, logs, assurance, incident response, and API protections.
AI governance
Limitations, testing, human authority, AI threats, monitoring, and change control.
Contract & compliance
DPA, ownership, accountable review, service terms, and breach commitments.
Operations & exit
Portability, offboarding, cost controls, escalation, and accessibility.
How to interpret the result
- Control maturity: Verified = 100, Partial = 55, Unknown = 15, and No = 0, weighted by the importance of each question.
- Context uplift: higher impact, sensitive data, production use, operational authority, and weak evidence increase the final risk score.
- Decision gates: a material red flag can pause the decision even when the average score looks acceptable.
- Scope: the output supports due diligence and pilot planning; it never authorizes procurement or production deployment.
Need the complete review process?
Use the step-by-step guide to define scope, grade evidence, review privacy and security, test AI-specific threats, negotiate contract protections, and run a bounded pilot.
Read the AI Vendor Due-Diligence Guide