Assessment workflow

Build an evidence-linked AI vendor risk assessment

Review one vendor for one defined use case. Keep source material, interpretations, open questions, and the final decision distinct.

Six-step workflow

01

Define the use case

Name the intended users, workflow, decision impact, data categories, integrations, and business owner. A vendor cannot be assessed meaningfully in the abstract.

02

Set the review scope

Choose review depth based on the use case, not brand familiarity. Record why each review area is included, narrowed, or deferred.

03

Request relevant evidence

Ask questions that fit the proposed use. Seek policies, technical descriptions, contract terms, test summaries, and other materials appropriate to the risk.

04

Build an evidence register

For each item, record its source, date if available, scope, reviewer, and the claim it supports. Do not treat an assertion as proof merely because it is written down.

05

Record findings and gaps

Separate observed facts from interpretation. Mark missing, stale, ambiguous, or out-of-scope evidence and note any proposed controls or conditions.

06

Prepare a human-owned decision

Summarize the use case, evidence, material concerns, dependencies, and recommendation. Identify who can accept residual risk and who will monitor conditions.

Useful outputs

A reviewable assessment record

Assessment boundary

This workflow does not certify a vendor, prove compliance, establish security, or guarantee an outcome. Missing evidence remains missing, and consequential decisions may require legal, security, privacy, procurement, or other specialist review.