AI Vendor Assessment Tool

AI vendor review · browser-local worksheet

Assess AI vendors with evidence and human review

Document intended use, data, model providers, access, evidence freshness and reviewer rationale in one local scorecard.

Open the free scorecard · Use the questionnaire template

1. Provider, service, and use

2. Data, model chain, and access

3. Lifecycle, incident, and exit terms

4. Evidence references and freshness

Record a document/control reference and its review/expiry dates; do not paste the evidence itself. Missing references and past-due evidence remain visible as follow-up flags.

Review areaReferenceReviewedExpires

5. Human review record

The tool flags information for a reviewer. A person—not the score—decides whether to proceed, proceed with conditions, or decline.

Limits: This tool does not verify vendor claims, upload results, determine legal applicability, certify compliance or make procurement decisions. Unknown answers stay visible for follow-up.

Review the whole service relationship

Start with purpose and impact; map data and model dependencies; review access and lifecycle terms; link evidence to dates; and record a human decision with rationale. Revisit the record when scope, models, subprocessors or access change.

NIST AI Risk Management Framework and NIST supply-chain guidance provide useful organizing structures, but neither replaces your organization’s obligations or judgment.

Guides and templates

A scoped review example

Consider a fictional ticket-drafting service used by a support team. Begin with the service edition, which ticket fields it can read, who sends a completed reply and which systems can receive output. A supplier's general security brochure does not answer whether that particular setup trains on ticket content or permits subcontractors to access it. Treat each unanswered point as a request for evidence, rather than interpreting the absence of a statement as a safe default.

The reviewer might ask for the relevant data-processing term, the model-provider list and an architecture description. Record references and dates without pasting the documents into the worksheet. If the intended use later changes from drafting to sending replies automatically, reassess the scope and oversight questions. The earlier review describes the earlier use; it cannot authorize a broader deployment by itself.

Questions before you begin

Should I assess a whole supplier or a single product?

Start with a named service, edition, configuration and intended use. Expand the review when evidence shows shared dependencies or when your procurement process requires a wider supplier assessment.

What should I do with an unknown answer?

Record it explicitly, identify the evidence needed and assign follow-up. Unknown is a review state, not a finding that a supplier is compliant or noncompliant.

Can this page inspect a report or contract?

No. The worksheet takes your entries and short references. A qualified reviewer must inspect the underlying evidence and decide whether its scope and conclusions are relevant.

Does a completed worksheet approve a purchase?

No. Keep the business decision, reviewer rationale and conditions separate from the generated follow-up points. Apply your normal procurement, security, privacy and legal review process.

Updated 2026-10-08. Sources are linked on this page.