Process guide

A human-owned AI vendor approval process

Use clear roles and decision points so vendor evaluation is neither an unstructured email chain nor an automated pass-or-fail exercise.

What an AI vendor approval process should do

An AI vendor approval process defines how a request is framed, which reviewers participate, what evidence is needed, how gaps are handled, who makes the decision, and what changes trigger another review. Approval must stay bounded to the documented use case and conditions.

Intended roles:
Business requesters, decision owners, program leads, and reviewers across security, privacy, legal, procurement, compliance, accessibility, finance, risk, or AI governance.
Use it when:
A new AI vendor or use case enters review, a prior decision needs renewal, or the use, data flow, model, integration, contract, or impact changes materially.
Inputs:
Vendor and use-case details, business purpose, users, affected people, data categories, integrations, requested timing, internal requirements, evidence, gaps, and reviewer assignments.
Outputs:
Review route, evidence requests, findings, exceptions, conditions, prohibited uses, approver, implementation owners, and reassessment triggers.
Boundary:
This guide is a documentation framework. Each organization must reconcile it with its own policies, contracts, risk tolerances, and qualified advice.

About this resource

AI Vendor Decision publishes static informational resources for structuring an internal vendor review. The site does not receive documents, assess vendors, provide professional advice, or make approval decisions. Check each resource against your current use case, evidence, policies, contracts, and applicable requirements.

Step 1

Frame the request

Capture the vendor, proposed use case, business purpose, intended users, data categories, integrations, decision impact, and requested timing. Return requests that are too vague to review.

Step 2

Triage the review

Identify which functions should participate. Relevant reviewers may include security, privacy, legal, procurement, compliance, accessibility, finance, risk, and the business owner.

Step 3

Collect proportionate evidence

Ask only for information connected to the use case. Track the source and scope of each item, and avoid receiving confidential material through channels not approved by your organization.

Step 4

Resolve or expose gaps

Assign follow-up questions. If a gap cannot be closed, state its decision impact and whether a control, narrower use, contractual condition, or later review could address it.

Step 5

Record the decision

Document the recommendation, rationale, approver, conditions, prohibited uses, implementation owners, and review triggers. “Approved” without scope is not a durable decision.

Step 6

Monitor what can change

Revisit the decision when the use case, model, data flow, subprocessors, contract, controls, or impact changes materially.

Decision record

Minimum fields worth preserving

Frequently asked questions

Who should own an AI vendor approval decision?

The organization should name an accountable decision owner with authority for the defined use case. Security, privacy, legal, procurement, compliance, finance, risk, accessibility, business, or AI-governance reviewers may contribute within their responsibilities.

When should an AI vendor decision be revisited?

Revisit it when the use case, users, data flow, model, subprocessors, integrations, contract, controls, or impact changes materially, or when a documented review trigger occurs.

Does approval apply to every use of the vendor?

No. A durable decision identifies the approved scope, conditions, prohibited uses, owners, and review triggers. Approval without scope should not be treated as blanket approval.