AI Vendor Assessment Template
This template is used to assess vendors, platforms, SaaS products, model providers, embedded AI features, and third-party AI services that process, generate, retain, expose, or act on enterprise data.
The purpose of this template is to ensure vendor AI is identified, reviewed, controlled, evidenced, and managed before it is enabled, purchased, integrated, scaled, or relied upon.
Vendor AI must be mapped into the enterprise AI Control Architecture rather than treated as a standalone product feature.
1. Vendor Assessment Information
Vendor Name
[Enter vendor name]
Product / Platform / Service Name
[Enter product, platform, or service name]
AI Feature or Capability Name
[Enter AI feature or capability name]
Assessment Date
[Enter date]
Assessment Owner
Name:
Function:
Email:
Business Owner
Name:
Function:
Email:
Vendor Owner
Name:
Function:
Email:
Technical Owner
Name:
Function:
Email:
Not applicable reason, if any:
Related AI Use Case
Related AI Inventory Record
2. Vendor AI Capability Overview
AI Capability Description
[Describe what the vendor AI capability does]
AI Capability Type
Select all that apply:
[ ] AI-enabled SaaS feature
[ ] Embedded vendor AI
[ ] Hosted model API
[ ] Cloud AI service
[ ] AI agent
[ ] AI workflow automation
[ ] AI search or RAG capability
[ ] AI summarization
[ ] AI drafting
[ ] AI classification
[ ] AI recommendation
[ ] AI decision support
[ ] AI tool/action execution
[ ] Customer-facing AI
[ ] Security operations AI
[ ] Developer AI tool
[ ] Other
Current Enablement Status
Select one:
[ ] Not enabled
[ ] Enabled for pilot
[ ] Enabled for limited users
[ ] Enabled in production
[ ] Enabled by default
[ ] Disabled
[ ] Unknown
Is the AI Feature Optional?
[ ] Yes
[ ] No
[ ] Unknown
Can the AI Feature Be Disabled?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Admin Control Notes
[Describe admin controls, feature flags, tenant settings, user-level settings, or limitations]
3. Business Use and Scope
Intended Business Use
[Describe how the enterprise intends to use the vendor AI capability]
Business Process Affected
[Describe business process, workflow, or function affected]
Intended Users
Select all that apply:
[ ] Employees
[ ] Contractors
[ ] Developers
[ ] Security team
[ ] Customer support team
[ ] HR team
[ ] Finance team
[ ] Legal or compliance team
[ ] Business operations team
[ ] Customers
[ ] Suppliers
[ ] Partners
[ ] Public users
[ ] Other
External Exposure
Select one:
[ ] Internal only
[ ] Internal with vendor processing
[ ] Partner-facing
[ ] Supplier-facing
[ ] Customer-facing
[ ] Public-facing
[ ] Unknown
Scope Limitations
[Describe any user, business unit, geography, data, workflow, or feature restrictions]
4. Data Processing Assessment
Data Processed by Vendor AI
Select all that apply:
[ ] No enterprise data
[ ] Public data
[ ] Internal data
[ ] Confidential data
[ ] Restricted data
[ ] Regulated data
[ ] Personal data
[ ] Customer data
[ ] Employee data
[ ] Financial data
[ ] Legal or privileged data
[ ] Security-sensitive data
[ ] Source code
[ ] Secrets or credentials
[ ] Production data
[ ] Unknown
Data Sources
Does Vendor AI Process Prompts?
[ ] No
[ ] Yes
[ ] Unknown
Does Vendor AI Process Outputs?
[ ] No
[ ] Yes
[ ] Unknown
Does Vendor AI Process Uploaded Files?
[ ] No
[ ] Yes
[ ] Unknown
Does Vendor AI Process Retrieved Context?
[ ] No
[ ] Yes
[ ] Unknown
Data Processing Notes
[Describe how data is sent to, processed by, or accessed by the vendor AI capability]
5. Data Retention and Reuse
Does the Vendor Retain Prompts?
[ ] No
[ ] Yes
[ ] Unknown
Does the Vendor Retain Outputs?
[ ] No
[ ] Yes
[ ] Unknown
Does the Vendor Retain Uploaded Files?
[ ] No
[ ] Yes
[ ] Unknown
Does the Vendor Retain Logs or Telemetry?
[ ] No
[ ] Yes
[ ] Unknown
Retention Period
[Describe retention period for prompts, outputs, files, logs, telemetry, and generated content]
Can Retained Data Be Deleted?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Can Vendor Use Enterprise Data for Training?
[ ] No
[ ] Yes
[ ] Opt-out available
[ ] Unknown
Can Vendor Use Enterprise Data for Product Improvement?
[ ] No
[ ] Yes
[ ] Opt-out available
[ ] Unknown
Training / Reuse Configuration
[Describe training, fine-tuning, telemetry, product improvement, analytics, or reuse settings]
Retention and Reuse Notes
[Describe risks, restrictions, contractual terms, or required controls]
6. Processing Location and Subprocessors
Processing Location
[Describe where AI processing occurs, including regions or data centers if known]
Data Residency Requirements
[Describe applicable data residency or jurisdictional requirements]
Cross-Border Transfer Involved?
[ ] No
[ ] Yes
[ ] Unknown
Subprocessors Involved?
[ ] No
[ ] Yes
[ ] Unknown
Subprocessor Summary
Processing Location Notes
[Describe cross-border transfer, subprocessors, residency, or jurisdiction concerns]
7. Identity and Access
Vendor AI Identity Model
Select all that apply:
[ ] Uses user identity
[ ] Uses delegated user authority
[ ] Uses application identity
[ ] Uses service identity
[ ] Uses vendor-managed identity
[ ] Uses agent identity
[ ] Hybrid identity
[ ] Unknown
Permission Model
[Describe how the vendor AI determines what data, records, users, tools, or workflows it can access]
Does Vendor AI Respect Existing User Permissions?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Can AI-Mediated Activity Be Distinguished?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Access Review Available?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Revocation Path
[Describe how AI access, user access, service access, or feature access can be revoked]
Identity and Access Notes
[Describe identity, access, delegated authority, permission inheritance, attribution, and revocation concerns]
8. Prompt and Input Controls
System Prompt or Vendor Instructions Visible?
[ ] No
[ ] Yes
[ ] Partially
[ ] Unknown
Can Enterprise Configure AI Instructions or Guardrails?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Does Vendor Provide Prompt/Input Filtering?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Does Vendor Detect Sensitive Data in Inputs?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Does Vendor Address Prompt Injection Risk?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
External or Untrusted Inputs Processed?
[ ] No
[ ] Yes
[ ] Unknown
Prompt and Input Notes
[Describe input validation, prohibited inputs, prompt injection, system prompt protection, and configuration limitations]
9. Output and Decision Controls
Output Types
Select all that apply:
[ ] Informational answer
[ ] Summary
[ ] Draft
[ ] Classification
[ ] Recommendation
[ ] Score
[ ] Extracted data
[ ] Generated code
[ ] Customer response
[ ] Internal communication
[ ] Decision support
[ ] Workflow instruction
[ ] Action request
[ ] Generated record
[ ] Other
Does Output Influence Decisions?
[ ] No
[ ] Yes
[ ] Unknown
Does Output Become a Record?
[ ] No
[ ] Yes
[ ] Unknown
Does Output Reach Customers or External Parties?
[ ] No
[ ] Yes
[ ] Unknown
Vendor Output Controls Available
Select all that apply:
[ ] Output review workflow
[ ] Human approval workflow
[ ] Output labeling
[ ] Source attribution
[ ] Confidence indicator
[ ] Generated content marker
[ ] Customer-facing restrictions
[ ] Output logging
[ ] Correction or retraction support
[ ] None
[ ] Unknown
Output and Decision Notes
[Describe output validation, decision impact, generated records, customer-facing controls, and correction paths]
10. Tool and Action Capability
Can Vendor AI Use Tools, APIs, or Workflows?
[ ] No
[ ] Yes
[ ] Unknown
Vendor AI Action Capability
Select all that apply:
[ ] No action capability
[ ] Read-only retrieval
[ ] Draft-only action
[ ] Workflow trigger
[ ] Record creation
[ ] Record modification
[ ] Communication sending
[ ] Access request or approval
[ ] Financial transaction
[ ] Security action
[ ] Production change
[ ] Administrative action
[ ] Other
Tool / Action Summary
Approval Gates Available?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Action Boundaries Available?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Kill Switch Available?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Rollback or Correction Available?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Tool and Action Notes
[Describe action risks, approval gates, action limits, kill switches, rollback, and vendor limitations]
11. Monitoring, Logging, and Evidence
Vendor Logs Available
Select all that apply:
[ ] Admin activity logs
[ ] User activity logs
[ ] AI usage logs
[ ] Prompt logs
[ ] Prompt metadata
[ ] Output logs
[ ] Output metadata
[ ] Retrieval logs
[ ] Data access logs
[ ] Tool call logs
[ ] Action logs
[ ] Approval logs
[ ] Policy violation logs
[ ] Incident logs
[ ] None
[ ] Unknown
Log Retention Period
[Describe vendor log retention period]
Can Logs Be Exported?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Can Logs Be Integrated with SIEM/SOC?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Evidence Available for Audit?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Evidence Notes
[Describe logging gaps, evidence limitations, export options, audit support, and monitoring concerns]
12. Security, Privacy, Legal, and Compliance
Security Review Required?
[ ] No
[ ] Yes
[ ] Unknown
Privacy Review Required?
[ ] No
[ ] Yes
[ ] Unknown
Legal Review Required?
[ ] No
[ ] Yes
[ ] Unknown
Compliance Review Required?
[ ] No
[ ] Yes
[ ] Unknown
Regulatory Impact
Select all that apply:
[ ] No known regulatory impact
[ ] Personal data regulation
[ ] Financial regulation
[ ] Health or safety regulation
[ ] Employment regulation
[ ] Consumer protection
[ ] Sector-specific regulation
[ ] Cross-border data transfer
[ ] Records retention
[ ] Legal privilege
[ ] Unknown
Contractual Requirements
Select all that apply:
[ ] Data processing agreement
[ ] AI-specific data use restrictions
[ ] Training/reuse restriction
[ ] Audit rights
[ ] Incident notification terms
[ ] Subprocessor disclosure
[ ] Data deletion obligation
[ ] Data residency obligation
[ ] Security assurance evidence
[ ] Service change notification
[ ] Liability or indemnity review
[ ] Other
Security / Privacy / Legal Notes
[Describe key legal, privacy, compliance, or security issues]
13. Vendor Assurance and Evidence
Assurance Evidence Provided
Select all that apply:
[ ] Security certification
[ ] SOC report
[ ] ISO certification
[ ] Penetration test summary
[ ] AI risk documentation
[ ] Model card or system card
[ ] Data processing documentation
[ ] Privacy documentation
[ ] Subprocessor list
[ ] Audit log documentation
[ ] Incident response documentation
[ ] Responsible AI documentation
[ ] Admin control documentation
[ ] None
[ ] Unknown
Vendor AI Documentation Reviewed?
[ ] No
[ ] Yes
[ ] Partially
[ ] Unknown
Vendor Assurance Findings
Vendor Assurance Notes
[Summarize evidence received, evidence gaps, findings, and unresolved questions]
14. Vendor Incident Support
Vendor AI Incident Process Available?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Incident Notification Terms Defined?
[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown
Vendor Support Contact
Name:
Role:
Email:
Support channel:
Vendor Evidence During Incident
Select all available:
[ ] Prompt logs
[ ] Output logs
[ ] User activity logs
[ ] Admin logs
[ ] Data access logs
[ ] Tool/action logs
[ ] Configuration history
[ ] Feature enablement history
[ ] Retention evidence
[ ] RCA / incident report
[ ] Unknown
Vendor Incident Notes
[Describe incident support, evidence availability, timelines, and escalation path]
15. Risk Assessment
Vendor AI Risk Drivers
Select all that apply:
[ ] Sensitive data processing
[ ] Regulated data processing
[ ] Personal data processing
[ ] Customer-facing output
[ ] Decision-supporting output
[ ] Tool or action capability
[ ] Vendor-managed identity
[ ] Limited logs
[ ] Limited admin controls
[ ] Vendor retention
[ ] Vendor training/reuse
[ ] Cross-border transfer
[ ] Subprocessor dependency
[ ] Feature enabled by default
[ ] Cannot fully disable feature
[ ] Weak incident support
[ ] Unknown vendor behavior
Vendor AI Risk Rating
Select one:
[ ] Low
[ ] Medium
[ ] High
[ ] Critical
Risk Rating Rationale
[Explain why this rating was selected]
Required Controls
Select all that apply:
[ ] Inventory record
[ ] Business owner assigned
[ ] Vendor owner assigned
[ ] Data owner approval
[ ] Data processing review
[ ] Training/reuse restriction
[ ] Retention restriction
[ ] Admin configuration control
[ ] Feature enablement approval
[ ] Access review
[ ] Output review
[ ] Tool/action review
[ ] Logging review
[ ] SIEM/SOC integration
[ ] Vendor incident process
[ ] Contract update
[ ] Assurance evidence
[ ] Exception record
16. Approval Decision
Assessment Outcome
Select one:
[ ] Approved for use
[ ] Approved with conditions
[ ] Approved for pilot only
[ ] Requires remediation before approval
[ ] Requires contract update
[ ] Requires additional review
[ ] Requires exception approval
[ ] Rejected
[ ] Deferred
Conditions for Approval
[List required conditions before enablement, purchase, production use, or scaling]
Required Remediation
Exceptions Required?
[ ] No
[ ] Yes
[ ] Unknown
Residual Risk
[Describe residual risk after required controls and conditions]
17. Review and Approval
Business Owner Decision
Name:
Decision:
Date:
Notes:
Vendor Risk Decision
Name or forum:
Decision:
Date:
Notes:
Security Decision
Name or forum:
Decision:
Date:
Notes:
Privacy / Legal Decision
Name or forum:
Decision:
Date:
Notes:
Not applicable reason, if any:
Architecture Decision
Name or forum:
Decision:
Date:
Notes:
18. Ongoing Review
Review Frequency
Select one:
[ ] Monthly
[ ] Quarterly
[ ] Semi-annually
[ ] Annually
[ ] At contract renewal
[ ] At vendor feature change
[ ] At material AI change
[ ] After incident
[ ] Other
Review Triggers
Select all that apply:
[ ] Vendor changes AI feature
[ ] Vendor changes data processing terms
[ ] Vendor changes retention terms
[ ] Vendor changes training/reuse terms
[ ] Vendor adds subprocessor
[ ] Vendor changes logging capability
[ ] Vendor changes admin controls
[ ] Vendor incident occurs
[ ] Enterprise use case changes
[ ] Data classification changes
[ ] Risk tier changes
[ ] Contract renewal
[ ] Regulatory change
Next Review Date
[Enter date]
19. Summary
Vendor:
Product/platform:
AI feature:
Business owner:
Vendor owner:
AI pattern:
Data processed:
Vendor retention:
Training/reuse:
Identity model:
Output impact:
Action capability:
Logs available:
Incident support:
Risk rating:
Approval decision:
Conditions:
Next review date: