AI Governance Institute
All governance templates →How are we managing third-party AI risks?

Implementation Kit

Third-Party AI Inventory and Contract Review Checklist

The estate-wide view of external AI: every API and embedded model in use, the state of each contract against the clauses that matter, and whether the training-data opt-out is actually confirmed. Complements the per-vendor due diligence kit.

Who this is for: The third-party risk owner who needs to know the whole external AI exposure, not one vendor at a time.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. External AI dependency inventory

Spreadsheet

One row per external AI API or vendor-embedded model. The portfolio, with contract and opt-out status visible.

Template

DependencyProviderUse caseData sentRisk tierContract review statusTraining-data opt-out
<API or embedded model><vendor><what we use it for><data categories>Minimal / Limited / HighNot started / In review / CompleteConfirmed / Requested / Not available / N/A

Worked example

DependencyProviderUse caseData sentRisk tierContract review statusTraining-data opt-out
Chat completion APIAnthropicContract summarizationCounterparty names, termsMinimalCompleteConfirmed (DPA 6.2)
Zendesk AIZendeskSupport reply draftingTickets, order metadataLimitedIn reviewRequested 2026-08-20
Embedded resume parserGreenhouseCV to structured fieldsCandidate CVsHighCompleteConfirmed
Meeting summarizerOtter.aiCall notesMeeting audio, namesLimitedNot startedNot available

Acceptance criteria

  • Every external AI API and every vendor-embedded AI feature is listed, drawn from the AI inventory.
  • Contract review status and opt-out status are tracked per row, not assumed.
  • High and Limited rows without a complete contract review have an owner and a date.

2. AI API contract review checklist

Spreadsheet

A fast triage of one agreement against the clauses that matter for an external AI API.

Template

ClausePresent?Acceptable?Note
Training-data use (our data not used to train by default, or opt-out)Y / NY / N
Data retention and deletion of prompts and outputsY / NY / N
Data location and transfer mechanismY / NY / N
Model change notificationY / NY / N
Liability cap and IP indemnification for AI outputsY / NY / N
Incident notification windowY / NY / N
Sub-processor list and change noticeY / NY / N
Audit or evidence rightsY / NY / N

Worked example

ClausePresent?Acceptable?Note
Training-data useYYNot used for training per MSA 9.1
Retention and deletionYY30 days, then deleted
Data location and transferPartialNUS only; need EU option, raised with vendor
Model change notificationNNChangelog only; redline drafted
Liability and IP indemnityYNIP claims inside the general cap; want a carve-out
Incident notificationYY24h
Sub-processor noticeYY30-day notice
Audit rightsYYAnnual questionnaire + SOC 2

Acceptance criteria

  • Each clause is checked against the signed agreement, not the vendor summary.
  • Every "not acceptable" has a redline in progress or an approved decision to accept.
  • The checklist result updates the contract review status on the inventory.

3. Training-data opt-out tracking log

Spreadsheet

Proof that opt-out was pursued and confirmed for every vendor where it applies.

Template

VendorOpt-out available?Default stateRequested onConfirmed onEvidenceOwner
<vendor>Yes / No / UnknownOn / Off by defaultYYYY-MM-DDYYYY-MM-DD<link or ref><name>

Worked example

VendorOpt-out available?Default stateRequested onConfirmed onEvidenceOwner
AnthropicN/A (not used for training)n/an/a2026-07-02DPA 6.2Vendor Risk
ZendeskYesOff by default2026-08-20pendingsupport case 44812Vendor Risk
Otter.aiUnknownunknown2026-09-01pendingemail to supportIT

Acceptance criteria

  • Every vendor that could train on your data has a row with a current status.
  • Confirmed opt-outs point to written evidence, not a sales assurance.
  • Pending items have an owner and are chased.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

PRC-014
PRC-014

The dependency inventory is the shadow and third-party AI inventory for external APIs and embedded models.

PRC-002
PRC-002

The contract review checklist evidences which AI-specific clauses are in place across the estate.

DGC-001
DGC-001

The opt-out log documents whether your data feeds vendor training, per data provenance requirements.

PRC-007
PRC-007

The "model change notification" checklist row establishes the hook for ongoing vendor governance-change monitoring.

PRC-009
PRC-009

The inventory makes provider concentration visible for a concentration-risk assessment.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →