Free evaluation tool

AI Vendor Evaluation Checklist

Review an AI vendor's data practices, security documentation, and contract terms. Create a practical summary of what you know, what is missing, and what to ask next.

Optional starting fields

Does the planned use involve protected health information (PHI)?

The healthcare and BAA section applies when PHI use is Yes or Unsure. When No, that section is outside the stated scope — it is not marked satisfied.

Do not enter patient information, passwords, or confidential documents into this tool.

Answers are kept in this page session only. Nothing is sent to VNDRIQ. Refreshing or leaving the page clears the review.

Documented records your own assessment that an item is documented. VNDRIQ has not verified the vendor claim.

A.Data handling

What information the product touches, where it goes, and who may see it.

A

What information will the product receive?

A

Where is that information processed and stored?

A

Is customer data used to train models?

A

What retention and deletion options are documented?

A

Which subprocessors may receive the data?

B.Healthcare and BAA documentation

Whether healthcare use is supported by the agreement structure for this product.

B

Is a BAA available for the specific product and service tier?

B

Has its applicability to the intended use been reviewed?

B

Are relevant downstream service arrangements documented?

B

Are healthcare-use restrictions or exclusions identified?

C.Security and access

Access controls, encryption, auditing, and incident readiness.

C

Are authentication and access controls documented?

C

Are encryption practices described?

C

Are audit logs available?

C

Is current independent security documentation available?

C

Are incident response and notification procedures documented?

D.Contract and operational fit

Ownership, exit terms, limitations, and internal ownership of the review.

D

Are data ownership and permitted uses clear?

D

Are termination, export, and deletion terms documented?

D

Are responsibility and liability terms ready for review?

D

Are important product limitations documented?

D

Is an internal review owner assigned?

D

Is there a process for reviewing vendor or product changes?

Results

Review completion

0% of applicable items documented

Applicable items

20

Documented

0

Needs clarification

0

Not reviewed

20

Review completion describes how much of the checklist you have answered. It is not a compliance score, and VNDRIQ has not verified any vendor claims.

Outstanding questions

Resolve first: BAA applicability

Planned use involves PHI: Unsure. BAA availability and applicability for the specific product and service tier remains unresolved. Confirm a BAA is available for the specific product and service tier, and that it covers the intended use, before any protected health information decision.

A. Data handling

  • What information will the product receive?
  • Where is that information processed and stored?
  • Is customer data used to train models?
  • What retention and deletion options are documented?
  • Which subprocessors may receive the data?

B. Healthcare and BAA documentation

  • Is a BAA available for the specific product and service tier?
  • Has its applicability to the intended use been reviewed?
  • Are relevant downstream service arrangements documented?
  • Are healthcare-use restrictions or exclusions identified?

C. Security and access

  • Are authentication and access controls documented?
  • Are encryption practices described?
  • Are audit logs available?
  • Is current independent security documentation available?
  • Are incident response and notification procedures documented?

D. Contract and operational fit

  • Are data ownership and permitted uses clear?
  • Are termination, export, and deletion terms documented?
  • Are responsibility and liability terms ready for review?
  • Are important product limitations documented?
  • Is an internal review owner assigned?
  • Is there a process for reviewing vendor or product changes?

Evaluation summary

Vendor / product

Not provided

Date generated

October 7, 2026

Intended use

Not provided

Planned use involves PHI

Unsure

A. Data handling

  • What information will the product receive?
  • Where is that information processed and stored?
  • Is customer data used to train models?
  • What retention and deletion options are documented?
  • Which subprocessors may receive the data?

B. Healthcare and BAA documentation

  • Is a BAA available for the specific product and service tier?
  • Has its applicability to the intended use been reviewed?
  • Are relevant downstream service arrangements documented?
  • Are healthcare-use restrictions or exclusions identified?

C. Security and access

  • Are authentication and access controls documented?
  • Are encryption practices described?
  • Are audit logs available?
  • Is current independent security documentation available?
  • Are incident response and notification procedures documented?

D. Contract and operational fit

  • Are data ownership and permitted uses clear?
  • Are termination, export, and deletion terms documented?
  • Are responsibility and liability terms ready for review?
  • Are important product limitations documented?
  • Is an internal review owner assigned?
  • Is there a process for reviewing vendor or product changes?

This summary organizes due diligence. It does not establish compliance, does not certify the vendor, and does not replace professional review. Responses marked Documented record your own assessment; VNDRIQ has not verified any vendor claim.