Taking longer than expected.
Reload the pageTaking longer than expected.
Reload the pageScore any AI vendor across 18 questions and 4 dimensions in five minutes. Get a comparison-grade risk tier, the weakest areas to push on, and a 10-question follow-up checklist tailored to that vendor.
Built for CISOs, AI risk owners, and procurement teams running structured due diligence on AI vendors and foundation-model providers.
We use the vendor name throughout the report and the follow-up questions. Nothing is shared with sales unless you opt in.
Learn what AI vendor risk means, why third-party AI providers introduce risks unlike traditional SaaS vendors, the frameworks that anchor a defensible AI vendor risk program (NIST SP 800-161r1, NIST AI RMF, ISO 42001), the assessment questions a CISO should ask before signing, and how to keep ongoing vendor risk current as models and sub-processors change.
Read moreTemplateA structured 62-question vendor assessment questionnaire across 8 security domains that CISOs and procurement teams use to evaluate AI vendors before onboarding. Covers data privacy, security architecture, model transparency, compliance certifications, incident response, contractual protections, business continuity, and audit rights.
Read moreGuideA 60-question vendor risk questionnaire (VRQ) template for generative AI and AI-feature SaaS vendors, organised into six sections (model and provider, data governance, security, compliance and audit, operational, contractual), with each question referenced to the source standard - SIG 2024, CSA CCM v4, ISO/IEC 27036, NIST SP 800-161, and HHS HIPAA Risk Analysis guidance.
Read moreFree toolEighteen dimension-scored questions that produce a defensible risk rating for any AI vendor before you let it near production data.
Read moreGuideThe practical playbook for building the AI vendor inventory CFOs now demand. Scope, classification, risk tiering, spend visibility, exit clauses, BAA and DPA matrices, with citations to NIST SP 800-161, IDC AI vendor surveys, IAPP vendor risk guidance, and Gartner AI vendor frameworks.
Read moreComplianceHow APRA Prudential Standard CPS 230 (effective 1 July 2025) governs AI systems and AI vendors as material service providers for Australian banks, insurers and super funds - and how to manage AI operational risk, concentration and resilience.
Read more