AI vendor review · browser-local worksheet
Assess AI vendors with evidence and human review
Document intended use, data, model providers, access, evidence freshness and reviewer rationale in one local scorecard.
Review the whole service relationship
Start with purpose and impact; map data and model dependencies; review access and lifecycle terms; link evidence to dates; and record a human decision with rationale. Revisit the record when scope, models, subprocessors or access change.
NIST AI Risk Management Framework and NIST supply-chain guidance provide useful organizing structures, but neither replaces your organization’s obligations or judgment.
Guides and templates
- AI Vendor Assessment Questionnaire
- How to Evaluate AI Vendors
- AI RFP Template and Procurement Checklist
- AI Contract Clauses and DPA Checklist
- AI Vendor Security Review Checklist
- EU AI Act Vendor Due Diligence
- AI Vendor Risk by Industry
- AI Vendor Tiering and Monitoring
- AI Vendor Reviews by Tool Category
- AI Security Questionnaire Response Template
A scoped review example
Consider a fictional ticket-drafting service used by a support team. Begin with the service edition, which ticket fields it can read, who sends a completed reply and which systems can receive output. A supplier's general security brochure does not answer whether that particular setup trains on ticket content or permits subcontractors to access it. Treat each unanswered point as a request for evidence, rather than interpreting the absence of a statement as a safe default.
The reviewer might ask for the relevant data-processing term, the model-provider list and an architecture description. Record references and dates without pasting the documents into the worksheet. If the intended use later changes from drafting to sending replies automatically, reassess the scope and oversight questions. The earlier review describes the earlier use; it cannot authorize a broader deployment by itself.
Questions before you begin
Should I assess a whole supplier or a single product?
Start with a named service, edition, configuration and intended use. Expand the review when evidence shows shared dependencies or when your procurement process requires a wider supplier assessment.
What should I do with an unknown answer?
Record it explicitly, identify the evidence needed and assign follow-up. Unknown is a review state, not a finding that a supplier is compliant or noncompliant.
Can this page inspect a report or contract?
No. The worksheet takes your entries and short references. A qualified reviewer must inspect the underlying evidence and decide whether its scope and conclusions are relevant.
Does a completed worksheet approve a purchase?
No. Keep the business decision, reviewer rationale and conditions separate from the generated follow-up points. Apply your normal procurement, security, privacy and legal review process.
Updated 2026-10-08. Sources are linked on this page.