Process guide

A human-owned AI vendor approval process

Use clear roles and decision points so vendor evaluation is neither an unstructured email chain nor an automated pass-or-fail exercise.

Step 1

Frame the request

Capture the vendor, proposed use case, business purpose, intended users, data categories, integrations, decision impact, and requested timing. Return requests that are too vague to review.

Step 2

Triage the review

Identify which functions should participate. Relevant reviewers may include security, privacy, legal, procurement, compliance, accessibility, finance, risk, and the business owner.

Step 3

Collect proportionate evidence

Ask only for information connected to the use case. Track the source and scope of each item, and avoid receiving confidential material through channels not approved by your organization.

Step 4

Resolve or expose gaps

Assign follow-up questions. If a gap cannot be closed, state its decision impact and whether a control, narrower use, contractual condition, or later review could address it.

Step 5

Record the decision

Document the recommendation, rationale, approver, conditions, prohibited uses, implementation owners, and review triggers. “Approved” without scope is not a durable decision.

Step 6

Monitor what can change

Revisit the decision when the use case, model, data flow, subprocessors, contract, controls, or impact changes materially.

Decision record

Minimum fields worth preserving