Skip to content
Sections
All notes

All notes · Governance

Vendor Assessment Without a Year of Work

A proportionate assessment that takes an hour for most tools, and what deserves more than that.

Governance · Procedure

Full third-party assessment is designed for systems holding your data permanently. Most AI tool decisions do not need it, and applying it universally is what makes the process slower than the field.

A practical review based on “Vendor Assessment Without a Year of Work” includes the time required for assessment, contracting, rollout and later reassessment. Teams can use timesheet and task tracking to make that operational effort visible across owners and deadlines, while keeping the legal, security and model-risk decision in the documented approval process.

For an independent benchmark, compare the local approach with NIST AI Resource Center; the useful test is whether ownership, access and recovery remain proportionate and explainable when the usual expert is absent.

The tiering question

What data classification will this handle?

Public and internal: light assessment.

Confidential or regulated: full process.

Affecting people outside the organisation: full process plus register entry.

Most requests are the first category and should be answerable in an hour.

The light assessment

The seven clauses from the terms note: training use, retention, human review, subprocessors, location, output indemnity, change of terms.

Who the supplier is and how long they have existed.

Whether anybody owns it internally.

A time-bounded approval.

One page, one person, one hour.

What the full process adds

Security questionnaire and whatever certifications you require.

Contract negotiation on the clauses that matter.

Data protection impact assessment where the regime requires it.

Reference checks.

And a register entry with a named owner.

The subprocessor question

Worth asking in both tiers: which model providers sit behind this service?

Many products in this category are interfaces over somebody else's model.

Which means your assessment of the visible supplier may be assessing the wrong party, and the answer is frequently not volunteered.

The small-supplier problem

Much of the interesting tooling comes from young companies with no certifications and no negotiating flexibility.

A process requiring both excludes the entire category.

For low-classification use, a short assessment and a time-bounded approval is a defensible answer, and refusing everything new is a decision with its own costs.

Reassessment

On the schedule, on a material terms change, and on acquisition.

Acquisition specifically: the terms you assessed belong to a company that no longer exists.

Set an alert for your approved suppliers, which is a search subscription and costs nothing.

Recording it

The completed assessment, dated, with who did it.

Kept, because the same supplier will return and because somebody will ask what was checked.

This also makes the next assessment faster, which is how the process becomes sustainable.

What to check

Is there a light path, or one process for everything?

How long does the light path take?

Do you ask about model subprocessors?

And would you notice if an approved supplier were acquired?

The point

Most AI tool decisions do not need full third-party assessment.

Tier it by data classification and answer the light path in an hour.

Underlying all of this

Everything in this collection reduces to four habits: find out what people are doing and why before deciding anything, provide something good enough that the approved route is the easy one, write rules about information rather than about tools, and monitor the destination rather than the content. None requires a product, and a programme doing all four controls more than one built on prohibition.

The recurring pattern

The recurring pattern across every section here is the same: the response that feels like control reduces it. A ban removes visibility rather than use. Content inspection drives activity to personal devices. A discovery exercise with consequences produces quiet answers. In each case the organisation ends up knowing less about a risk it believes it has handled.