Tool directory

Vendor Assessment

Vendor AI Assessment

A structured assessment that screens third-party AI vendors before they touch client data — covering data handling, model governance, security, and contractual protections — so the team can clear or block a tool with a defensible, repeatable record instead of a rubber-stamp and a shrug.

How it works

A diligence framework for vendors that use AI in their product — what data they take, how models are governed, what the contract actually promises, and where a human stays in the loop.

It produces a decision record you can point to later, not just a completed questionnaire.

What it covers

01

Data handling & residency

Asks where inputs are stored, whether they're used for training, how long they're retained, and which jurisdictions they transit — so the team knows what data the vendor may see and whether cross-border transfer rules apply before anything is sent.

02

Model & training governance

Surfaces what model powers the tool, whether the vendor fine-tunes on customer data, whether outputs can be attributed, and how the vendor handles hallucination and drift — the governance questions that separate a real vendor from a wrapper.

03

Security & access controls

Maps certifications (SOC 2, ISO 27001), encryption at rest and in transit, access logging, and tenant isolation — so the tool meets the firm's baseline before it's even considered for sensitive work.

04

Confidentiality & contractual terms

Checks whether the vendor's terms grant training rights, limit liability, protect client confidences, and allow audit — flagging paper that gives the vendor more than the firm would give a counterparty.

05

Human-in-the-loop & output review

Assesses whether the tool is designed for attorney review of outputs or to act autonomously, what logging exists, and how errors are surfaced — so the tool slots into the firm's review workflow instead of routing around it.

06

Decision record & re-assessment

Records the assessment outcome — approved, approved with conditions, or blocked — with the rationale and owner, and schedules a re-assessment when the vendor's model, terms, or scope change so approvals don't age into silent risk.

What it needs from you

The inputs that make the output useful. Missing any of these usually shows up as a vague result.

Vendor documentation
Security packet, model cards, sub-processor list, and DPA.
Intended use
What the tool will do and which data it will touch.
Questionnaire responses
Vendor answers on training data, retention, and human review.
Internal requirements
Your security, privacy, and governance minimums.

What you get back

Representative outputs, with illustrative examples. Every output is reviewed by a qualified professional before it is relied on.

Assessment report

Findings per dimension with a clear risk rating.

Example
Data handling: acceptable. Model governance: gap — no documented evaluation process.

Contract requirements

The specific terms needed before approval.

Example
Require: no training on customer data, 30-day deletion, sub-processor change notice.

Decision record

Approve, approve with conditions, or decline — with the reasoning preserved.

Example
Approved with conditions — conditional on DPA amendment executed before rollout.

Want this configured for your team?

We tailor each tool to your playbooks, thresholds, and review requirements before it goes live.