Free due-diligence tool · 2026 edition

Know the risk before you trust an AI vendor

Turn vendor claims and reviewed evidence into a transparent decision brief across privacy, security, AI governance, contracts, and operational resilience.

Your answers are processed and saved only in this browser by this static page. Do not enter confidential contracts, security findings, personal data, credentials, or vendor secrets.
Step 1 of 6 · Decision context

Define the exact vendor decision

Assess the specific product, plan, deployment, region, and use case—not the vendor brand in general. Context changes the acceptable evidence and controls.

Required for the report.
Controls often differ by plan.
Accountable reviewer or workstream.
Scoring rule: Verified requires current evidence that applies to this exact context. Choose Partial when evidence is incomplete or plan-dependent, No when the capability is absent, and Unknown when it has not been established.
Transparent methodology

Five dimensions, explicit evidence gaps

The assessment adapts public risk-management and secure-AI guidance into a practical vendor-review aid. It is not affiliated with, endorsed by, or a certification from any source organization.

25%

Data & privacy

Use, retention, deletion, location, subprocessors, isolation, and encryption.

25%

Security & access

Identity, roles, logs, assurance, incident response, and API protections.

20%

AI governance

Limitations, testing, human authority, AI threats, monitoring, and change control.

15%

Contract & compliance

DPA, ownership, accountable review, service terms, and breach commitments.

15%

Operations & exit

Portability, offboarding, cost controls, escalation, and accessibility.

How to interpret the result

  • Control maturity: Verified = 100, Partial = 55, Unknown = 15, and No = 0, weighted by the importance of each question.
  • Context uplift: higher impact, sensitive data, production use, operational authority, and weak evidence increase the final risk score.
  • Decision gates: a material red flag can pause the decision even when the average score looks acceptable.
  • Scope: the output supports due diligence and pilot planning; it never authorizes procurement or production deployment.

Need the complete review process?

Use the step-by-step guide to define scope, grade evidence, review privacy and security, test AI-specific threats, negotiate contract protections, and run a bounded pilot.

Read the AI Vendor Due-Diligence Guide
Continue the evidence chain

Move from vendor claims to measured outcomes

Risk review narrows the conditions for a safe pilot. It does not replace workflow design or observed evidence.

Step 1

Design the workflow

Define inputs, AI tasks, review, exception paths, controls, metrics, and rollback.

Build a Blueprint
Step 2

Track pilot evidence

Capture corrections, exceptions, fallback, failures, incidents, and review effort.

Track a Pilot
Step 3

Make the decision

Combine observed value, quality, reliability, controls, and evidence.

Score the Pilot
FAQ

AI vendor due-diligence questions