Vendor Evaluation & Contract Checklist

Interactive checklist and scorecard for evaluating AI vendors and third-party models. Includes structured fields for technical fit, model provenance, security, data handling, SLAs, liability/indemnity, exit/portability, sandbox testing, weighted scoring, and a final recommendation.

Interactive Tool

Vendor Evaluation & Contract Checklist

Use this interactive checklist to evaluate AI vendors and third-party models. Score each category from 1 (Poor) to 5 (Excellent). Provide evidence and contract language where applicable. Save this evaluation to standardize vendor selection, surface contractual risks, and make vendor handoffs repeatable.

Name of the vendor or provider.
Specific product, model, or service being evaluated.
Evaluation date (YYYY-MM-DD recommended).
How well the product fits your technical requirements (architecture, APIs, integration effort, performance).
1.0 10.0
List key compatibilities, missing features, integration effort, and benchmark results.
Does the vendor disclose model origin, training data sources, and licensing?
Document provenance, licenses, third-party components, potential IP risks, and any red flags.
Assessment of security controls, certifications (e.g., SOC 2, ISO 27001), encryption, and vulnerability management.
1.0 10.0
Select controls the vendor attests to or demonstrates.
If yes, capture contractual restrictions required (consent, anonymization, opt-out).
Vendor-stated retention periods for customer data (e.g., 90 days). Capture retention for backups and logs as well.
Recommended clauses: purpose limitation, no model retraining on customer data without explicit consent, data minimization, encryption, deletion on termination, audit rights, and subprocessors disclosure.
Assess uptime guarantees, support response, remedies, and monitoring/data access.
1.0 10.0
Capture uptime %, support hours, response times, credits, monitoring access, and escalation paths.
Check for indemnity for IP infringement, data breaches, and appropriate limits of liability/insurance.
Specify necessary changes (e.g., carve-outs, cap amounts, insurance requirements).
How easy is it to export data and switch vendors? Consider formats, APIs, and migration support.
1.0 10.0
Suggested clauses: data export within X days, machine-readable formats, escrow, transition support, and no vendor lock-in.
Proposed tests, datasets, pass/fail criteria, security conditions, and duration.
Summarize results against criteria and list any unexpected behaviors or performance shortfalls.
Assess pricing model fit, flexibility, transparency, and total cost of ownership.
1.0 10.0
Record pricing model, discounts, minimum commitments, and termination charges.
Optional: specify weights as JSON (example: {"technical":30,"security":20,"data":15,"sla":15,"commercial":20}). If left blank, use your organization's default weights.
Calculate the weighted average using category scores and weights, then scale to 0-100. Enter final score here or leave blank to calculate externally.
Decision based on evaluation.
Person completing this checklist.
Action items, owners, deadlines, clauses to include in the contract, and any required approvals.
You can explore this tool now. Sign in or create an account to save your responses and return to them later.
Make this tool part of your work

Save a personal copy, bring it to your team, or tailor the questions and workflow to fit what you are hungry to improve.

Member customization and team collaboration are coming soon.

Discussion

Comments and conversation will live here.