Procurement
Operational controls for procurement, with maturity levels, evidence requirements, and implementation guidance.
Not sure where to start? Answer 3 questions and get a tailored compliance action plan.
What applies to me? →17 controls
AI Vendor Due Diligence
Assess AI vendors against security, governance, and compliance criteria before procurement and at defined intervals during the vendor relationship.
AI Contractual Requirements
Set minimum AI vendor contract terms for data handling, transparency, audit rights, and incident notification.
Third-Party AI Model Evaluation
Evaluate third-party AI models against defined performance, safety, and bias criteria before deploying them in enterprise workflows.
Vendor AI Incident Notification Requirements
Require AI vendors to notify the organization of incidents affecting their AI systems within defined timeframes and with specified information.
AI Procurement Risk Assessment
Assess technical, legal, privacy, and operational risks before approving an AI system or service purchase. Document the findings.
Vendor Safety Commitment Verification
Check whether vendors honor published safety commitments, voluntary pledges, and contractual duties throughout the relationship.
Vendor Governance Change Monitoring
Monitor vendor changes to governance structures, safety leadership, and policies. Assess their effects on deployed system risks.
Vendor Model Update Disclosure and Re-Assessment Protocol
Require disclosure of material vendor model updates, including capability changes, safety results, and revised model cards (vendors' published model fact sheets). Trigger internal reassessment when updates affect prior due diligence.
AI Vendor Concentration Risk Assessment
Assess dependence on a small number of AI vendors or underlying model providers. Document supplier alternatives supporting continuity if a primary provider fails, suspends access, or becomes unavailable.
AI Vendor Financial Stability Assessment
Assess vendors’ financial stability and organizational viability during selection and recurring reviews. Consider market consolidation, regulatory costs, and dependence on further investor funding.
Federal AI Procurement Submission and Review Process
Set a process for federal AI procurement submissions. Track voluntary pre-deployment evaluation commitments becoming mandatory and update procurement workflows accordingly.
AI Safety Index and Benchmark Monitoring
Track external safety indices, benchmarks, and independent evaluations for your AI vendors and models. Include material findings in initial and recurring vendor risk assessments.
AI Platform Conflict-of-Interest Assessment
Assess conflicts when an AI vendor also supplies oversight, monitoring, or safety evaluations for its own models. Ensure governance decisions can be made without depending entirely on vendor-controlled evidence.
Shadow AI and Third-Party Widget Inventory and Classification
Discover and classify AI built into cloud software (SaaS), browser extensions, and code running in web pages. Apply appropriate processing and vendor-risk controls to these shadow AI sources.
Procurement-Stage AI Governance Conditions
Set governance conditions that must be met before AI procurement finishes. Include contractual standards, whistleblowing policies, and internal approval triggers.
AI Developer Tool Data Boundary Controls
Define which coding assistants and AI developer tools the enterprise permits, including what data they may transmit. Evaluate data boundaries before deployment and whenever vendor policies change.
AI Evaluator and Auditor Independence Assessment
Before relying on an outside AI evaluation, audit, or safety assessment, check that the assessor is qualified and independent of the vendor. Discount findings that fail the check.
Procurement, tracked weekly
New procurement controls and the regulatory developments driving them, plus everything else changing in AI governance. Every Thursday.
