30-Question Scored Assessment
Comprehensive vendor questionnaire across security, data privacy, model governance, bias controls, and business continuity — each question weighted by risk category.
Configure your context
AI drafts your output
Review and refine
Download and share
Supported frameworks include: EU AI Act, NIST AI RMF, ISO 42001, GDPR, UK GDPR, CCPA/CPRA, DPDPA, APPI, PIPL, PDPA, LGPD, POPIA
What you get
A single generation produces a complete, scored vendor assessment — not a questionnaire template, but a structured assessment with evidence requests, scoring, and an executive recommendation.
Comprehensive vendor questionnaire across security, data privacy, model governance, bias controls, and business continuity — each question weighted by risk category.
Clear pass/fail thresholds with minimum scores per category — so you know definitively whether a vendor meets your organisation's AI procurement standards.
Structured list of supporting documents to request from the vendor — model cards, penetration test reports, data processing records, and certifications.
One-page vendor scorecard with category breakdown, overall recommendation (Approve / Approve with Conditions / Reject), and key risk flags for senior stakeholders.
Dedicated section covering the vendor's data processing basis, sub-processor disclosure, encryption standards, breach notification process, and AI-specific data retention.
Jurisdiction-specific contract requirements, DPA obligations, AI Act compliance status, and red-flag conditions that should block approval regardless of overall score.
Fill in your organisation and vendor details below. The more context you provide, the more precisely targeted your vendor assessment will be.
Your generated document will appear here.
Fill in the form and click Generate to begin.
Built with responsible AI principles. Human review is not optional — it's a core part of the process.
Full disclaimer
Not legal advice
This document does not constitute legal advice and must not be relied upon as such. Consult a qualified legal professional before implementing or relying on this document in whole or in part.
Regulation currency
Laws, regulations, and guidance cited are subject to change. Content reflects the position as at the date of generation and may not account for subsequent amendments, enforcement decisions, or judicial interpretations.
Proposed legislation
Where proposed or draft legislation is referenced — including the EU AI Liability Directive — such references describe legislation that has not been enacted. Its final form, scope, timing, and territorial application remain unconfirmed.
AI output limitations
AI output can contain errors or omissions. Do not rely on this document as a complete statement of your legal obligations or as a substitute for specialist compliance advice.
Generate a complete, 30-question scored vendor assessment with evidence requests and executive summary in minutes.
Assess Vendor