Step 1
Frame the request
Capture the vendor, proposed use case, business purpose, intended users, data categories, integrations, decision impact, and requested timing. Return requests that are too vague to review.
Process guide
Use clear roles and decision points so vendor evaluation is neither an unstructured email chain nor an automated pass-or-fail exercise.
An AI vendor approval process defines how a request is framed, which reviewers participate, what evidence is needed, how gaps are handled, who makes the decision, and what changes trigger another review. Approval must stay bounded to the documented use case and conditions.
AI Vendor Decision publishes static informational resources for structuring an internal vendor review. The site does not receive documents, assess vendors, provide professional advice, or make approval decisions. Check each resource against your current use case, evidence, policies, contracts, and applicable requirements.
Step 1
Capture the vendor, proposed use case, business purpose, intended users, data categories, integrations, decision impact, and requested timing. Return requests that are too vague to review.
Step 2
Identify which functions should participate. Relevant reviewers may include security, privacy, legal, procurement, compliance, accessibility, finance, risk, and the business owner.
Step 3
Ask only for information connected to the use case. Track the source and scope of each item, and avoid receiving confidential material through channels not approved by your organization.
Step 4
Assign follow-up questions. If a gap cannot be closed, state its decision impact and whether a control, narrower use, contractual condition, or later review could address it.
Step 5
Document the recommendation, rationale, approver, conditions, prohibited uses, implementation owners, and review triggers. “Approved” without scope is not a durable decision.
Step 6
Revisit the decision when the use case, model, data flow, subprocessors, contract, controls, or impact changes materially.
Decision record
The organization should name an accountable decision owner with authority for the defined use case. Security, privacy, legal, procurement, compliance, finance, risk, accessibility, business, or AI-governance reviewers may contribute within their responsibilities.
Revisit it when the use case, users, data flow, model, subprocessors, integrations, contract, controls, or impact changes materially, or when a documented review trigger occurs.
No. A durable decision identifies the approved scope, conditions, prohibited uses, owners, and review triggers. Approval without scope should not be treated as blanket approval.