# AI supplier assessment

## Service

- Supplier / product / version:
- Authorized use cases:
- Prohibited use cases:
- Internal owner:
- Review / renewal date:

## Data and privacy

- accepted and prohibited data;
- processing and storage regions;
- retention, deletion, and export;
- use for training or improvement;
- subprocessors and change notification;
- international transfers and safeguards;
- audit rights and evidence of deletion.

## Security and operations

- authentication, SSO, roles, and service accounts;
- encryption, logging, and administrative access;
- tenant isolation;
- incident notification and cooperation;
- availability, limits, backup, and recovery;
- model changes, deprecation, and compatibility;
- available tests, certifications, and reports.

## Commercial and exit

- total cost and consumption limits;
- ownership of inputs, outputs, and configurations;
- portability of data and evaluations;
- technical dependencies;
- exit time and cost;
- replacement solution;
- liability, caps, and critical clauses.

## Decision

- Unresolved risks:
- Compensating controls:
- Approved / conditional / rejected use:
- Decision-maker and date:
