Practitioner template
AI Supplier Assessment
Assess the AI provider, service boundary, data handling, changes, performance information, security, continuity, and responsibilities.
Download TemplateBlank template
- Provider and service
- Approved intended use
- Customer data handled
- Retention and training use
- Sub-processors and locations
- Security and access
- Model and service version
- Change notification and rollback
- Performance and limitations
- Incident and continuity response
- Contractual responsibilities
- Conclusion and actions
Completed fictional example
Fictional teaching example: This is not an executed or approved validation record.
- Provider and service
- Fictional hosted document-review model service
- Approved intended use
- Propose source-linked validation-document comments for qualified review
- Customer data handled
- Permitted validation documents; no patient or production records
- Retention and training use
- Zero retention and no customer-data training by contract
- Sub-processors and locations
- Approved processing region and listed sub-processors
- Security and access
- Encrypted transport, tenant isolation, role-restricted API key
- Model and service version
- Pinned service alias with provider change record; exact weights unavailable
- Change notification and rollback
- Advance notice for material behavior change; prior version subject to availability
- Performance and limitations
- Provider benchmark is contextual only; customer challenge set controls acceptance
- Incident and continuity response
- Notification, export, manual review fallback, and service suspension defined
- Contractual responsibilities
- Provider secures service; customer controls use, sources, roles, review, and release
- Conclusion and actions
- Conditionally suitable with locked population, local evaluation, monitoring, and stop criteria