AI Governance Institute
All governance templates →How do we manage third-party AI vendors safely throughout the vendor lifecycle?

Implementation Kit

AI Vendor Monitoring Schedule and Contract Checklist

Managing an AI vendor from map to requalification. A vendor map with risk classification, the five contract clauses that matter with negotiation notes, and a risk-based monitoring schedule with requalification triggers.

Who this is for: The vendor manager who owns AI vendors across their whole life, not just onboarding.

Download the kit (Markdown) ↓3 artifacts. Every table also copies as CSV.

1. AI vendor map

Spreadsheet

Every external AI dependency, classified by what it touches and what it decides.

Template

VendorDependency typeDecisions influencedData sharedRisk tierContract statusLast review
<vendor>API / embedded SaaS AI / hosted fine-tune<what it affects><data categories>Minimal / Limited / HighDraft / Signed / Renewal dueYYYY-MM-DD

Worked example

VendorDependency typeDecisions influencedData sharedRisk tierContract statusLast review
GreenhouseEmbedded SaaS AIApplicant rankingCandidate CVsHighSigned2026-08-30
AnthropicAPINone (summaries only)Contract textMinimalSigned2026-07-02
FraudCoHosted fine-tuneTransaction hold / releaseTransaction + KYC dataHighRenewal due 2026-112026-06-15

Acceptance criteria

  • The map covers APIs, embedded SaaS AI, and vendor-hosted fine-tuned models.
  • Risk tier reflects both the data shared and the decisions the vendor influences.
  • Every High-tier vendor has a review date within the last 12 months.

2. Five key clauses library

Spreadsheet

The five AI vendor clauses, why each matters, and the position to hold in negotiation.

Template

ClauseWhy it mattersNegotiation noteFallback
Training-data opt-outStops your data improving the vendor modelAsk for contractual, not a UI toggleDocumented opt-out + deletion right
Output ownershipConfirms you own generated outputs and inputsVendors usually concedeYou own inputs and outputs; vendor gets a service-improvement licence only if de-identified
Change notificationTime to re-test before a model shiftsVendors resist advance notice30 days for material model or safety changes
IndemnificationAllocates IP and harmful-output riskTie to the vendor's control of training dataIP-infringement carve-out from the liability cap
Audit rightsLets you verify claimsOn-site is rare; accept evidence-basedAnnual questionnaire + third-party report + records on request

Worked example

ClauseStatus with FraudCoNote
Training-data opt-outSecuredContractual, MSA 9.1
Output ownershipSecuredWe own model outputs and case data
Change notificationOpenVendor offered 10 days; holding for 30 for model changes
IndemnificationOpenNegotiating IP carve-out from the cap
Audit rightsSecuredAnnual questionnaire + SOC 2 + right to records

Acceptance criteria

  • All five clauses are assessed against the current contract for every material vendor.
  • Negotiation positions are agreed with Legal before talks start.
  • Open clauses have an owner and a target close date tied to the renewal calendar.

3. Vendor monitoring schedule

Spreadsheet

Review cadence by risk tier, plus the events that force an out-of-cycle requalification.

Template

VendorRisk tierReview cadenceNext reviewRequalification triggers
<vendor>HighEvery 6 monthsYYYY-MM-DDmajor model update; safety-posture change; incident; ownership change
<vendor>LimitedAnnualYYYY-MM-DDmaterial model update; contract renewal
<vendor>MinimalAt renewalYYYY-MM-DDcontract renewal

Worked example

VendorRisk tierReview cadenceNext reviewRequalification triggers
GreenhouseHighEvery 6 months2027-02-28model swap; new sub-processor; bias-audit failure
FraudCoHighEvery 6 months2026-12-15model update; SOC 2 lapse; funding event
AnthropicMinimalAt renewal2027-07-02model deprecation affecting our integration

Acceptance criteria

  • Cadence scales with risk tier and is on someone's calendar.
  • Requalification triggers are specific events, and firing one starts a review regardless of the schedule.
  • A completed review updates the vendor map's last-review date.

Governance controls this kit produces evidence for

Completing the artifacts above gives you a head start on the evidence requirements for these controls.

PRC-001
PRC-001

The vendor map and its review history are the due diligence record across the vendor lifecycle.

PRC-002
PRC-002

The five-clauses library is the contractual requirements standard with negotiation positions.

PRC-007
PRC-007

The monitoring schedule and requalification triggers are the vendor governance-change monitoring process.

PRC-008
PRC-008

"Major model update" as a requalification trigger implements the vendor model-update disclosure and re-assessment protocol.

PRC-004
PRC-004

"Incident" as a trigger plus the review cadence support vendor incident notification handling.

This kit backs one playbook. Read the full guidance for the reasoning behind each artifact.

Decide what to implement next

Assess your governance gaps, then create an action plan with owners and target dates. Build and export without an account; sign in when you want to save your plan.

Start the AI governance assessment →