AI Tool Vendor Due Diligence Kit™
Evaluate AI tools before they become operating dependencies by defining the use case, classifying consequence, verifying data handling and permissions, testing real workflows, and preserving a controlled exit path.
1 of 4
Turn AI procurement into a controlled risk decision.
Move the hard questions ahead of adoption so feature demos do not outrun privacy, security, model, contract, and dependency review.
Classify the use case.
Define what the tool will do, what data it touches, how much autonomy it receives, and what failure would cost.
Verify the vendor.
Review supplier provenance, privacy and retention, security controls, model limitations, intellectual-property exposure, and contract evidence.
Preserve an exit path.
Set approval conditions, monitoring, reassessment triggers, incident response, export, deletion, and credential-revocation steps before dependency grows.
A practical due-diligence system for AI vendors and tools.
Use-case risk tiers
Classify consequence, data exposure, autonomy, affected people, and review depth.
Vendor + control review
Evaluate supplier chain, data practices, security, permissions, model behavior, intellectual property, and commercial terms.
Approval + monitoring
Document conditions, exceptions, review dates, incident response, reassessment triggers, and controlled exit.
A vendor can pass a demo and still fail the operating test.
Evidence changes, vendors change, permissions expand, and use cases drift. Reassess material changes instead of treating approval as permanent.
Define. Verify. Test. Decide. Monitor.
Start with one real tool and intended workflow, complete the risk and evidence review, record approval conditions, test representative tasks, and schedule reassessment before wider adoption.


