| AI vendor inventory | Vendor, product, use case, owner, contract, data, hosting, jurisdiction and lifecycle status | Governance register | Vendor lists, contracts and use-case owners |
| Risk-tiering methodology | Scoring criteria, thresholds, review depth, approval route and reassessment triggers | Method and decision matrix | Risk appetite and existing methods |
| Due-diligence pack | AI, data, privacy, security, resilience, transparency and subcontractor questions | Questionnaire and evidence guide | Control requirements and vendor context |
| Control and contract library | Minimum controls, contractual review points, monitoring measures and evidence expectations | Control catalogue | Legal, privacy, security and procurement input |
| Governance workflow | Intake, triage, review, approval, exceptions, escalation, monitoring and exit | Process map and RACI | Organisation structure and systems |
| Reporting framework | Vendor risk, review status, overdue evidence, incidents, exceptions, actions and trends | Dashboard specification | Management information needs |