Define the use case
Name the intended users, workflow, decision impact, data categories, integrations, and business owner. A vendor cannot be assessed meaningfully in the abstract.
Assessment workflow
Review one vendor for one defined use case. Keep source material, interpretations, open questions, and the final decision distinct.
An AI vendor risk assessment is a use-case-specific review of relevant claims, evidence, findings, gaps, controls, and ownership. The goal is a record that another reviewer can examine—not a universal score or automatic pass/fail result.
AI Vendor Decision publishes static informational resources for structuring an internal vendor review. The site does not receive documents, assess vendors, provide professional advice, or make approval decisions. Check each resource against your current use case, evidence, policies, contracts, and applicable requirements.
Six-step workflow
Name the intended users, workflow, decision impact, data categories, integrations, and business owner. A vendor cannot be assessed meaningfully in the abstract.
Choose review depth based on the use case, not brand familiarity. Record why each review area is included, narrowed, or deferred.
Ask questions that fit the proposed use. Seek policies, technical descriptions, contract terms, test summaries, and other materials appropriate to the risk.
For each item, record its source, date if available, scope, reviewer, and the claim it supports. Do not treat an assertion as proof merely because it is written down.
Separate observed facts from interpretation. Mark missing, stale, ambiguous, or out-of-scope evidence and note any proposed controls or conditions.
Summarize the use case, evidence, material concerns, dependencies, and recommendation. Identify who can accept residual risk and who will monitor conditions.
Useful outputs
This workflow does not certify a vendor, prove compliance, establish security, or guarantee an outcome. Missing evidence remains missing, and consequential decisions may require legal, security, privacy, procurement, or other specialist review.
It is a structured review of one vendor for one defined use case. It connects relevant claims and evidence to findings, open gaps, controls, owners, and a human-owned decision.
Gather the proposed use, intended users, data and integrations, decision impact, internal requirements, vendor claims, relevant supporting materials, and any missing or ambiguous information. The required depth depends on the use case.
No. It does not certify a vendor, establish security or compliance, or guarantee approval. Missing evidence remains missing, and consequential decisions may require qualified specialists.