# Vendor AI risk review kit

Use this kit to evaluate AI vendors with operating evidence rather than platform claims. It covers model risk, data handling, controls, support, portability, cost transparency, and exit planning.

## What it includes

- A vendor questionnaire for data handling, retention, subprocessors, model training, audit logs, evaluations, support, and portability.
- An evidence checklist for security documentation, model cards, incident process, cost controls, and exit plan.
- A vendor risk schema for control evidence and decision state.
- A risk brief for approval or rejection decisions.
- An exit map for migration and vendor transition.

## How to use it

Run this before procurement approval or production rollout. Require actual artifacts and contractual language where risk is material. Revisit vendor decisions when workload, data class, region, or model behavior changes.
