# AI Supplier Assessment

Version 1.0 | CSVtoCSA practitioner template | Updated 12 September 2026

## Purpose

Assess the AI provider, service boundary, data handling, changes, performance information, security, continuity, and responsibilities.

## When to use

Before approved AI use and after material supplier, model, data, security, or contract change.

## Instructions

- Define the specific system, service, change, population, and intended use.
- Complete each field from available records and accountable interviews; record unknowns rather than guessing.
- Link conclusions to affected GxP functions, failure scenarios, controls, evidence, and approval.
- Adapt the structure to the organization’s approved procedures and document-control process.

## Blank template

1. Provider and service

   Response: 

2. Approved intended use

   Response: 

3. Customer data handled

   Response: 

4. Retention and training use

   Response: 

5. Sub-processors and locations

   Response: 

6. Security and access

   Response: 

7. Model and service version

   Response: 

8. Change notification and rollback

   Response: 

9. Performance and limitations

   Response: 

10. Incident and continuity response

   Response: 

11. Contractual responsibilities

   Response: 

12. Conclusion and actions

   Response: 

## Completed fictional example

The example below is teaching material, not an executed or approved validation record.

1. Provider and service

   Fictional hosted document-review model service

2. Approved intended use

   Propose source-linked validation-document comments for qualified review

3. Customer data handled

   Permitted validation documents; no patient or production records

4. Retention and training use

   Zero retention and no customer-data training by contract

5. Sub-processors and locations

   Approved processing region and listed sub-processors

6. Security and access

   Encrypted transport, tenant isolation, role-restricted API key

7. Model and service version

   Pinned service alias with provider change record; exact weights unavailable

8. Change notification and rollback

   Advance notice for material behavior change; prior version subject to availability

9. Performance and limitations

   Provider benchmark is contextual only; customer challenge set controls acceptance

10. Incident and continuity response

   Notification, export, manual review fallback, and service suspension defined

11. Contractual responsibilities

   Provider secures service; customer controls use, sources, roles, review, and release

12. Conclusion and actions

   Conditionally suitable with locked population, local evaluation, monitoring, and stop criteria

## Use and limitations

Adapt this template to the applicable regulation, approved validation procedure, document-control process, risk method, and approval roles. CSVtoCSA does not present this template as a universally required validation record.
