Generic vendor security assessments miss AI-specific risks — training data leakage, model behavior under adversarial inputs, data residency for inference. This checklist closes those gaps so you sign vendors that fit your actual risk profile.

What's inside

Three-tier framework (Standard, Standard+, Restricted) covering data handling, model behavior, breach notification, and the AI-specific risks generic SOC 2 reviews skip. Use one per vendor decision.

How to use it

  1. Walk through every item in order — skipping ahead usually means missing the prerequisite that makes a later item work.
  2. Score honestly. The point of a checklist is to surface gaps, not to feel good about what's already done.
  3. Run it again in 90 days. Checklists are a baseline; the value is in the delta between runs.