AI Vendor Assessment Template

This template is used to assess vendors, platforms, SaaS products, model providers, embedded AI features, and third-party AI services that process, generate, retain, expose, or act on enterprise data.

The purpose of this template is to ensure vendor AI is identified, reviewed, controlled, evidenced, and managed before it is enabled, purchased, integrated, scaled, or relied upon.

Vendor AI must be mapped into the enterprise AI Control Architecture rather than treated as a standalone product feature.


1. Vendor Assessment Information

Vendor Name

[Enter vendor name]

Product / Platform / Service Name

[Enter product, platform, or service name]

AI Feature or Capability Name

[Enter AI feature or capability name]

Assessment Date

[Enter date]

Assessment Owner

Name:
Function:
Email:

Business Owner

Name:
Function:
Email:

Vendor Owner

Name:
Function:
Email:

Technical Owner

Name:
Function:
Email:
Not applicable reason, if any:

2. Vendor AI Capability Overview

AI Capability Description

[Describe what the vendor AI capability does]

AI Capability Type

Select all that apply:

[ ] AI-enabled SaaS feature
[ ] Embedded vendor AI
[ ] Hosted model API
[ ] Cloud AI service
[ ] AI agent
[ ] AI workflow automation
[ ] AI search or RAG capability
[ ] AI summarization
[ ] AI drafting
[ ] AI classification
[ ] AI recommendation
[ ] AI decision support
[ ] AI tool/action execution
[ ] Customer-facing AI
[ ] Security operations AI
[ ] Developer AI tool
[ ] Other

Current Enablement Status

Select one:

[ ] Not enabled
[ ] Enabled for pilot
[ ] Enabled for limited users
[ ] Enabled in production
[ ] Enabled by default
[ ] Disabled
[ ] Unknown

Is the AI Feature Optional?

[ ] Yes
[ ] No
[ ] Unknown

Can the AI Feature Be Disabled?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Admin Control Notes

[Describe admin controls, feature flags, tenant settings, user-level settings, or limitations]

3. Business Use and Scope

Intended Business Use

[Describe how the enterprise intends to use the vendor AI capability]

Business Process Affected

[Describe business process, workflow, or function affected]

Intended Users

Select all that apply:

[ ] Employees
[ ] Contractors
[ ] Developers
[ ] Security team
[ ] Customer support team
[ ] HR team
[ ] Finance team
[ ] Legal or compliance team
[ ] Business operations team
[ ] Customers
[ ] Suppliers
[ ] Partners
[ ] Public users
[ ] Other

External Exposure

Select one:

[ ] Internal only
[ ] Internal with vendor processing
[ ] Partner-facing
[ ] Supplier-facing
[ ] Customer-facing
[ ] Public-facing
[ ] Unknown

Scope Limitations

[Describe any user, business unit, geography, data, workflow, or feature restrictions]

4. Data Processing Assessment

Data Processed by Vendor AI

Select all that apply:

[ ] No enterprise data
[ ] Public data
[ ] Internal data
[ ] Confidential data
[ ] Restricted data
[ ] Regulated data
[ ] Personal data
[ ] Customer data
[ ] Employee data
[ ] Financial data
[ ] Legal or privileged data
[ ] Security-sensitive data
[ ] Source code
[ ] Secrets or credentials
[ ] Production data
[ ] Unknown

Data Sources

Data Source Classification Owner Vendor Access? Notes
[Source] [Classification] [Owner] [Yes/No/Unknown] [Notes]

Does Vendor AI Process Prompts?

[ ] No
[ ] Yes
[ ] Unknown

Does Vendor AI Process Outputs?

[ ] No
[ ] Yes
[ ] Unknown

Does Vendor AI Process Uploaded Files?

[ ] No
[ ] Yes
[ ] Unknown

Does Vendor AI Process Retrieved Context?

[ ] No
[ ] Yes
[ ] Unknown

Data Processing Notes

[Describe how data is sent to, processed by, or accessed by the vendor AI capability]

5. Data Retention and Reuse

Does the Vendor Retain Prompts?

[ ] No
[ ] Yes
[ ] Unknown

Does the Vendor Retain Outputs?

[ ] No
[ ] Yes
[ ] Unknown

Does the Vendor Retain Uploaded Files?

[ ] No
[ ] Yes
[ ] Unknown

Does the Vendor Retain Logs or Telemetry?

[ ] No
[ ] Yes
[ ] Unknown

Retention Period

[Describe retention period for prompts, outputs, files, logs, telemetry, and generated content]

Can Retained Data Be Deleted?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Can Vendor Use Enterprise Data for Training?

[ ] No
[ ] Yes
[ ] Opt-out available
[ ] Unknown

Can Vendor Use Enterprise Data for Product Improvement?

[ ] No
[ ] Yes
[ ] Opt-out available
[ ] Unknown

Training / Reuse Configuration

[Describe training, fine-tuning, telemetry, product improvement, analytics, or reuse settings]

Retention and Reuse Notes

[Describe risks, restrictions, contractual terms, or required controls]

6. Processing Location and Subprocessors

Processing Location

[Describe where AI processing occurs, including regions or data centers if known]

Data Residency Requirements

[Describe applicable data residency or jurisdictional requirements]

Cross-Border Transfer Involved?

[ ] No
[ ] Yes
[ ] Unknown

Subprocessors Involved?

[ ] No
[ ] Yes
[ ] Unknown

Subprocessor Summary

Subprocessor Role Data Processed Location Notes
[Name] [Role] [Data] [Location] [Notes]

Processing Location Notes

[Describe cross-border transfer, subprocessors, residency, or jurisdiction concerns]

7. Identity and Access

Vendor AI Identity Model

Select all that apply:

[ ] Uses user identity
[ ] Uses delegated user authority
[ ] Uses application identity
[ ] Uses service identity
[ ] Uses vendor-managed identity
[ ] Uses agent identity
[ ] Hybrid identity
[ ] Unknown

Permission Model

[Describe how the vendor AI determines what data, records, users, tools, or workflows it can access]

Does Vendor AI Respect Existing User Permissions?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Can AI-Mediated Activity Be Distinguished?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Access Review Available?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Revocation Path

[Describe how AI access, user access, service access, or feature access can be revoked]

Identity and Access Notes

[Describe identity, access, delegated authority, permission inheritance, attribution, and revocation concerns]

8. Prompt and Input Controls

System Prompt or Vendor Instructions Visible?

[ ] No
[ ] Yes
[ ] Partially
[ ] Unknown

Can Enterprise Configure AI Instructions or Guardrails?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Does Vendor Provide Prompt/Input Filtering?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Does Vendor Detect Sensitive Data in Inputs?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Does Vendor Address Prompt Injection Risk?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

External or Untrusted Inputs Processed?

[ ] No
[ ] Yes
[ ] Unknown

Prompt and Input Notes

[Describe input validation, prohibited inputs, prompt injection, system prompt protection, and configuration limitations]

9. Output and Decision Controls

Output Types

Select all that apply:

[ ] Informational answer
[ ] Summary
[ ] Draft
[ ] Classification
[ ] Recommendation
[ ] Score
[ ] Extracted data
[ ] Generated code
[ ] Customer response
[ ] Internal communication
[ ] Decision support
[ ] Workflow instruction
[ ] Action request
[ ] Generated record
[ ] Other

Does Output Influence Decisions?

[ ] No
[ ] Yes
[ ] Unknown

Does Output Become a Record?

[ ] No
[ ] Yes
[ ] Unknown

Does Output Reach Customers or External Parties?

[ ] No
[ ] Yes
[ ] Unknown

Vendor Output Controls Available

Select all that apply:

[ ] Output review workflow
[ ] Human approval workflow
[ ] Output labeling
[ ] Source attribution
[ ] Confidence indicator
[ ] Generated content marker
[ ] Customer-facing restrictions
[ ] Output logging
[ ] Correction or retraction support
[ ] None
[ ] Unknown

Output and Decision Notes

[Describe output validation, decision impact, generated records, customer-facing controls, and correction paths]

10. Tool and Action Capability

Can Vendor AI Use Tools, APIs, or Workflows?

[ ] No
[ ] Yes
[ ] Unknown

Vendor AI Action Capability

Select all that apply:

[ ] No action capability
[ ] Read-only retrieval
[ ] Draft-only action
[ ] Workflow trigger
[ ] Record creation
[ ] Record modification
[ ] Communication sending
[ ] Access request or approval
[ ] Financial transaction
[ ] Security action
[ ] Production change
[ ] Administrative action
[ ] Other

Tool / Action Summary

Tool / Workflow / Action Risk Level Approval Available? Logging Available? Disable Available?
[Tool/action] [Low/Medium/High/Critical] [Yes/No/Unknown] [Yes/No/Unknown] [Yes/No/Unknown]

Approval Gates Available?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Action Boundaries Available?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Kill Switch Available?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Rollback or Correction Available?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Tool and Action Notes

[Describe action risks, approval gates, action limits, kill switches, rollback, and vendor limitations]

11. Monitoring, Logging, and Evidence

Vendor Logs Available

Select all that apply:

[ ] Admin activity logs
[ ] User activity logs
[ ] AI usage logs
[ ] Prompt logs
[ ] Prompt metadata
[ ] Output logs
[ ] Output metadata
[ ] Retrieval logs
[ ] Data access logs
[ ] Tool call logs
[ ] Action logs
[ ] Approval logs
[ ] Policy violation logs
[ ] Incident logs
[ ] None
[ ] Unknown

Log Retention Period

[Describe vendor log retention period]

Can Logs Be Exported?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Can Logs Be Integrated with SIEM/SOC?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Evidence Available for Audit?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Evidence Notes

[Describe logging gaps, evidence limitations, export options, audit support, and monitoring concerns]

12. Security, Privacy, Legal, and Compliance

Security Review Required?

[ ] No
[ ] Yes
[ ] Unknown

Privacy Review Required?

[ ] No
[ ] Yes
[ ] Unknown

Compliance Review Required?

[ ] No
[ ] Yes
[ ] Unknown

Regulatory Impact

Select all that apply:

[ ] No known regulatory impact
[ ] Personal data regulation
[ ] Financial regulation
[ ] Health or safety regulation
[ ] Employment regulation
[ ] Consumer protection
[ ] Sector-specific regulation
[ ] Cross-border data transfer
[ ] Records retention
[ ] Legal privilege
[ ] Unknown

Contractual Requirements

Select all that apply:

[ ] Data processing agreement
[ ] AI-specific data use restrictions
[ ] Training/reuse restriction
[ ] Audit rights
[ ] Incident notification terms
[ ] Subprocessor disclosure
[ ] Data deletion obligation
[ ] Data residency obligation
[ ] Security assurance evidence
[ ] Service change notification
[ ] Liability or indemnity review
[ ] Other

13. Vendor Assurance and Evidence

Assurance Evidence Provided

Select all that apply:

[ ] Security certification
[ ] SOC report
[ ] ISO certification
[ ] Penetration test summary
[ ] AI risk documentation
[ ] Model card or system card
[ ] Data processing documentation
[ ] Privacy documentation
[ ] Subprocessor list
[ ] Audit log documentation
[ ] Incident response documentation
[ ] Responsible AI documentation
[ ] Admin control documentation
[ ] None
[ ] Unknown

Vendor AI Documentation Reviewed?

[ ] No
[ ] Yes
[ ] Partially
[ ] Unknown

Vendor Assurance Findings

Finding ID Finding Severity Owner Status
[Finding ID] [Finding] [Low/Medium/High/Critical] [Owner] [Status]

Vendor Assurance Notes

[Summarize evidence received, evidence gaps, findings, and unresolved questions]

14. Vendor Incident Support

Vendor AI Incident Process Available?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Incident Notification Terms Defined?

[ ] Yes
[ ] No
[ ] Partially
[ ] Unknown

Vendor Support Contact

Name:
Role:
Email:
Support channel:

Vendor Evidence During Incident

Select all available:

[ ] Prompt logs
[ ] Output logs
[ ] User activity logs
[ ] Admin logs
[ ] Data access logs
[ ] Tool/action logs
[ ] Configuration history
[ ] Feature enablement history
[ ] Retention evidence
[ ] RCA / incident report
[ ] Unknown

Vendor Incident Notes

[Describe incident support, evidence availability, timelines, and escalation path]

15. Risk Assessment

Vendor AI Risk Drivers

Select all that apply:

[ ] Sensitive data processing
[ ] Regulated data processing
[ ] Personal data processing
[ ] Customer-facing output
[ ] Decision-supporting output
[ ] Tool or action capability
[ ] Vendor-managed identity
[ ] Limited logs
[ ] Limited admin controls
[ ] Vendor retention
[ ] Vendor training/reuse
[ ] Cross-border transfer
[ ] Subprocessor dependency
[ ] Feature enabled by default
[ ] Cannot fully disable feature
[ ] Weak incident support
[ ] Unknown vendor behavior

Vendor AI Risk Rating

Select one:

[ ] Low
[ ] Medium
[ ] High
[ ] Critical

Risk Rating Rationale

[Explain why this rating was selected]

Required Controls

Select all that apply:

[ ] Inventory record
[ ] Business owner assigned
[ ] Vendor owner assigned
[ ] Data owner approval
[ ] Data processing review
[ ] Training/reuse restriction
[ ] Retention restriction
[ ] Admin configuration control
[ ] Feature enablement approval
[ ] Access review
[ ] Output review
[ ] Tool/action review
[ ] Logging review
[ ] SIEM/SOC integration
[ ] Vendor incident process
[ ] Contract update
[ ] Assurance evidence
[ ] Exception record

16. Approval Decision

Assessment Outcome

Select one:

[ ] Approved for use
[ ] Approved with conditions
[ ] Approved for pilot only
[ ] Requires remediation before approval
[ ] Requires contract update
[ ] Requires additional review
[ ] Requires exception approval
[ ] Rejected
[ ] Deferred

Conditions for Approval

[List required conditions before enablement, purchase, production use, or scaling]

Required Remediation

Action ID Remediation Action Owner Due Date Status
[Action ID] [Action] [Owner] [Date] [Status]

Exceptions Required?

[ ] No
[ ] Yes
[ ] Unknown

Residual Risk

[Describe residual risk after required controls and conditions]

17. Review and Approval

Business Owner Decision

Name:
Decision:
Date:
Notes:

Vendor Risk Decision

Name or forum:
Decision:
Date:
Notes:

Security Decision

Name or forum:
Decision:
Date:
Notes:

Architecture Decision

Name or forum:
Decision:
Date:
Notes:

18. Ongoing Review

Review Frequency

Select one:

[ ] Monthly
[ ] Quarterly
[ ] Semi-annually
[ ] Annually
[ ] At contract renewal
[ ] At vendor feature change
[ ] At material AI change
[ ] After incident
[ ] Other

Review Triggers

Select all that apply:

[ ] Vendor changes AI feature
[ ] Vendor changes data processing terms
[ ] Vendor changes retention terms
[ ] Vendor changes training/reuse terms
[ ] Vendor adds subprocessor
[ ] Vendor changes logging capability
[ ] Vendor changes admin controls
[ ] Vendor incident occurs
[ ] Enterprise use case changes
[ ] Data classification changes
[ ] Risk tier changes
[ ] Contract renewal
[ ] Regulatory change

Next Review Date

[Enter date]

19. Summary

Vendor:
Product/platform:
AI feature:
Business owner:
Vendor owner:
AI pattern:
Data processed:
Vendor retention:
Training/reuse:
Identity model:
Output impact:
Action capability:
Logs available:
Incident support:
Risk rating:
Approval decision:
Conditions:
Next review date: