Third-Party Model & Vendor Risk Checklist (Interactive)

Interactive vendor and model evaluation checklist that collects answers, evidence, residual risk scoring, and recommended mitigations to support consistent procurement and engineering decisions.

Interactive Tool

Third-Party Model & Vendor Risk Checklist

Use this checklist to consistently evaluate third-party models and vendors. Record answers, supporting evidence, residual risk, and required mitigations. Saved assessments build organizational memory and help procurement and engineering make faster, better-informed decisions.

Legal entity name
Primary procurement or technical contact
Include model version, API identifier, or package name
YYYY-MM-DD
Team or person responsible
Does the contract clearly define data ownership, retention, deletion, and allowed uses?
Contract clauses, vendor statements, screenshots, or links to documents
Are training data sources, lineage, evaluation artifacts, and documented limitations provided?
Links to model cards, datasheets, test artifacts, or vendor statements
Does the vendor provide uptime SLAs, support SLAs, rollback/patch capabilities, and incident response commitments?
Summarize key SLA terms or link to the contract
Authentication, authorization, encryption, rate-limiting, audit logging, and IP protections in place?
Pen test reports, SOC/ISO attestations, architecture diagrams, API docs
Does the contract include compliance clauses, audit rights, breach notification, and regulatory responsibilities?
Regulatory mappings, contract clauses, or auditor notes
Logging, observability, model-drift monitoring, update policies, and incident playbooks?
Monitoring metrics, SLIs, runbooks, or links
Are licensing terms clear and do they protect your IP? Any restrictions on outputs?
License links, export restrictions, or flagged terms
Are accuracy, bias, robustness, and safety documented for your use case?
Attach or link to test reports, notebooks, metrics, or evaluation scripts
Overall residual risk after controls and mitigations
1.0 10.0
List contract changes, sandboxing, additional testing, monitoring, denylist, and owners with due dates
Procurement and engineering decision
Name and role of the person approving the outcome
YYYY-MM-DD
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.