1. Describe the engagement
Capture procurement stage, use case, criticality, data, hosting and who may be affected.
Translate your use case, data profile and operational exposure into a tailored set of supplier questions, evidence requests, scoring guidance and contract-focused actions.
Complete the context fields, review the generated risk profile, then use the question set during sourcing, contracting, onboarding and periodic reassessment.
Capture procurement stage, use case, criticality, data, hosting and who may be affected.
The tool weights material risk factors and assigns questionnaire priorities without hidden data.
Collect supplier responses, compare evidence, identify red flags and retain an auditable record.
Fields marked required must be completed. The generated questionnaire is guidance and should be adapted to your legal, regulatory and contractual context.
The tool applies a transparent weighting model to contextual risk factors, then raises the priority of question areas that are commonly material for the selected operating profile.
Weighted points represent potential governance intensity, not legal classification. Question priority changes when inputs indicate sensitive data, material impacts, autonomous integration, continuous learning or complex dependencies.
The result does not replace legal advice, security testing, privacy assessment, financial due diligence, sector-specific review or direct verification of supplier evidence.
Use it to structure market engagement, RFPs, contract schedules, onboarding gates and recurring reviews. Record accepted exceptions, compensating controls, owners and deadlines.
Continue the assessment with complementary governance and risk-management tools.
It is a structured set of questions used to assess a supplier’s governance, data practices, security, privacy, model controls, resilience, subcontractors, assurance and contractual readiness for a defined AI use case.
No. The score measures the intensity of due diligence suggested by your context. Supplier quality can only be evaluated after reviewing responses, evidence, testing and contract terms.
A practical scale is 0 for no evidence, 1 for partial evidence, 2 for adequate evidence and 3 for strong, current and independently assured evidence. Apply documented judgment and record exceptions.
Prioritise current service-specific evidence for security, privacy, data provenance, model testing, incident response, subprocessors, change control, audit assurance and exit arrangements.
Yes. Export the question set to CSV, add commercial and technical requirements, define mandatory evidence and explain how responses will be evaluated.
Use a risk-based cadence and reassess after material model, hosting, subprocessor, data-use, regulatory or intended-use changes. Higher-risk services often justify at least annual review with interim monitoring.
A red flag is a response or absence of evidence that may indicate unacceptable uncertainty, weak control design, limited transparency or contractual imbalance requiring escalation or compensating controls.
Where material, assess both the direct supplier and underlying model or infrastructure providers. Confirm responsibility allocation, evidence coverage, incident flow-down and change notification.
No. It supports structured due diligence but does not determine legal status, regulatory classification or compliance. Obtain qualified advice for applicable jurisdictions and sectors.
Record the risk statement, evidence considered, rationale, compensating controls, accountable approver, review date, trigger events and any contractual protections.
Avoid entering confidential personal or security-sensitive details. This page states that calculations are local, but users should follow their organisation’s information-handling rules and verify the wider site’s implementation.
Complete evidence review, use-case testing, security and privacy checks, contract controls, human oversight design, incident procedures, monitoring thresholds, rollback planning and accountable approval.