AI Vendor Assessment: How to Vet an AI Tool Before You Approve It
Last updated: June 2026 · Guardrail Studio
"Just ban it" pushes staff to shadow AI; "just allow it" exposes your data. The answer is a lightweight vendor assessment — a repeatable way to decide which AI tools are safe to approve. Here's the checklist, and the two answers that should trigger an automatic block.
Why "ban it" and "allow it" both fail
Block every AI tool and your team will use them anyway, off the books — that's shadow AI, the worst of both worlds. Approve everything and you've no idea which tools train on your data or where it's stored. A short, consistent assessment lets you say a confident yes or no, and gives you a record you can show a client or insurer.
The 10 questions every AI vendor assessment should ask
- Does the vendor contractually commit not to train on our inputs?
- Is there an enterprise/business tier with data-protection terms?
- Do they document data retention and support deletion?
- Is data residency / hosting location disclosed and acceptable?
- Are sub-processors disclosed?
- Do they hold recognized security certifications (SOC 2, ISO 27001)?
- Is access controllable (SSO, roles, admin oversight)?
- Is there a documented breach-notification process?
- Are the terms compatible with our client confidentiality obligations?
- Is the commercial model sustainable for our use?
The two questions that should trigger an automatic block
Two answers are deal-breakers regardless of the rest: if the vendor trains on your inputs with no opt-out, or if the terms are incompatible with your client confidentiality obligations, the tool should not be approved for anything beyond public data — no matter how good it is.
Free vendor assessment checklist
| Question | Answer | Weight |
|---|---|---|
| No-train commitment? | Yes / Partial / No | Block if No |
| Enterprise tier w/ DPA? | Yes / No | High |
| Retention + deletion? | Yes / No | Medium |
| Data residency disclosed? | Yes / No | Medium |
| Client-confidentiality compatible? | Yes / No | Block if No |
Keep an approved-tool list staff actually use
The list only works if it's visible and requesting an addition is fast. Pin it in your main channel, name an owner, and turn assessment requests around quickly. Slow or hidden approval is what creates shadow AI in the first place.
Guardrail's auto-scoring vendor assessment
Guardrail's AI Policy OS includes a vendor-assessment spreadsheet that scores each tool and returns an automatic APPROVE / BLOCK recommendation, plus the policy and risk register that put it to work. See our PDPA guide for the data-residency angle.
Get the auto-scoring vendor assessment
Policy, 25-risk register, staff training, playbooks, and proof — editable and live in an afternoon.
Get the AI Policy OS from S$129 →Frequently asked questions
What's the most important question in an AI vendor assessment?
Does the vendor contractually commit not to train on your inputs? If a tool trains on what you submit, your confidential and client data could surface elsewhere. A 'no' (or 'unknown') on that question should block approval for anything beyond public data.
How do we keep an approved-tool list that people use?
Make it visible (pin it where staff work), make requesting a new tool easy, and review it regularly. The friction that drives 'shadow AI' is usually a slow or hidden approval process — fix that and compliance follows.
Do we need to assess free tools too?
Yes — especially free tools, since free tiers are the ones most likely to train on inputs and lack data-protection terms. Restrict free tools to public data only, or block them for company work.