VNDRIQ 6.1 — Governance Workflows
Executive Approval & Governance Workflows
Document, review, approve, conditionally approve, reject, renew, and periodically re-evaluate AI vendors through structured governance workflows. VNDRIQ provides governance workflow documentation to support enterprise procurement and risk management.
Governance Overview
Executive Approval Dashboard
247
Total Vendors Reviewed
132
Approved Vendors
48
Conditionally Approved
34
Under Review
19
Rejected
8
Expired Approvals
14
Approvals Expiring Soon
11
Awaiting Executive Review
22
Awaiting Evidence
17
High-Risk Vendors
31 days
Average Review Time
84%
Governance Completion Score
26
Decision Queue
43
Recent Decisions
Governance Records
Approval Records
| Vendor | Business Unit | Business Owner | Exec Sponsor | Status | Risk Rating | Evidence | Next Review |
|---|---|---|---|---|---|---|---|
| OpenAI Enterprise | Clinical Operations | Sarah Chen | Dr. James Holloway | Conditionally Approved | Moderate Risk | Verified | 2026-11-20 |
| Anthropic Claude | Research & Development | Michael Torres | Dr. James Holloway | Approved | Low Risk | Verified | 2026-10-10 |
| Abridge AI | Clinical Documentation | Dr. Emily Park | Dr. James Holloway | Under Review | Elevated Risk | Requested | 2026-08-01 |
| DeepScribe | Clinical Documentation | Dr. Emily Park | Dr. James Holloway | Approved | Low Risk | Verified | 2026-09-25 |
| S10.AI | Clinical Operations | Sarah Chen | Dr. James Holloway | Under Review | Elevated Risk | Pending Review | 2026-07-15 |
| Pearl AI | Dental Operations | Dr. Robert Kim | Dr. Lisa Anderson | Conditionally Approved | Moderate Risk | Verified | 2026-08-28 |
Record Detail
Approval Record
Vendor
OpenAI Enterprise
Business Unit
Clinical Operations
Business Owner
Sarah Chen
Executive Sponsor
Dr. James Holloway
Requestor
IT Procurement
Review Team
Security, Privacy, Legal
Submission Date
2026-04-15
Approval Date
2026-05-20
Expiration Date
2027-05-20
Last Review
2026-05-20
Next Review
2026-11-20
Approval Status
Conditionally Approved
Approval Category
Limited Use
Evidence Status
Verified
Risk Rating
Moderate Risk
Decision Summary
Approved for clinical documentation with BAA and human review
Governance Notes
Quarterly review required. No PHI training on customer data.
Governance Workflow
Approval Workflow Stages
Submitted
Evidence Collection
Technical Review
Security Review
Privacy Review
Governance Review
Executive Review
Legal Review
Conditional Approval
Approved
Rejected
Archived
Submitted
Vendor intake request received
Evidence Collection
Documentation requested and uploaded
Technical Review
Architecture and integration assessment
Security Review
Security controls and penetration testing
Privacy Review
Data privacy and PHI exposure evaluation
Governance Review
AI governance and model lifecycle review
Executive Review
Executive sponsor sign-off
Legal Review
Contract, BAA, and legal terms review
Conditional Approval
Approved with governance conditions
Approved
Full governance approval granted
Rejected
Vendor not approved for use
Archived
Approval record archived
Governance Conditions
Conditional Approval Types
No PHI
Vendor must not process protected health information
No PII
Vendor must not process personally identifiable information
Internal Use Only
Restricted to internal operational use
Human Review Required
Human oversight required for all outputs
Private Deployment Required
Must use private cloud or on-prem deployment
Limited Department Approval
Approved for specific departments only
Additional Security Controls Required
Compensating security controls required before use
Quarterly Review Required
Subject to quarterly governance re-evaluation
Vendor Documentation Pending
Awaiting vendor-provided documentation
Contract Review Required
Legal contract review required before activation
These are governance conditions, not legal conclusions. Organizations should consult legal counsel for regulatory compliance.
Cross-Functional Review
Review Assignments
Security
Jennifer Walsh
Privacy
Priya Sharma
Compliance
David Okafor
Legal
Marcus Reid
Procurement
Anna Becker
Clinical
Dr. Emily Park
IT
Tom Zhang
Executive
Dr. James Holloway
Governance
Rachel Dunn
Audit Trail
Decision Log
| Date | Reviewer | Decision | Reason | Evidence | Notes | Documentation |
|---|---|---|---|---|---|---|
| 2026-05-20 | Jennifer Walsh (Security) | Conditional Approval | BAA verified, additional controls required for PHI access | Verified | Quarterly review scheduled | SOC 2 Report, BAA, Security Whitepaper |
| 2026-05-15 | Dr. James Holloway (Executive) | Approved | All governance stages completed successfully | Verified | Full approval for research workflows | Complete Evidence Package |
| 2026-05-10 | Marcus Reid (Legal) | Conditional Approval | Contract terms require additional review | Verified | Data processing addendum under negotiation | DPA, BAA Draft |
| 2026-04-28 | Priya Sharma (Privacy) | Under Review | PHI exposure assessment in progress | Requested | Awaiting data flow diagram | Data Flow Diagram (Pending) |
| 2026-04-15 | Jennifer Walsh (Security) | Submitted | Initial vendor intake received | Pending Review | Evidence collection initiated | Vendor Intake Form |
| 2026-03-25 | Dr. Emily Park (Clinical) | Approved | Clinical workflow validation complete | Verified | Human review protocol established | Clinical Validation Report |
| 2026-03-10 | Marcus Reid (Legal) | Conditional Approval | BAA executed with data retention limitations | Verified | 2-year data retention cap enforced | Executed BAA, Retention Policy |
| 2026-02-28 | Dr. Lisa Anderson (Executive) | Conditional Approval | FDA cleared with clinical oversight requirement | Verified | Diagnostic outputs require dentist review | FDA 510(k), Clinical Evidence |
Risk Governance
Risk Acceptance
Residual Risk
Moderate Risk
Executive Acceptance
Dr. James Holloway, Chief Medical Officer
Review Date
2026-05-20
Expiration
2026-11-20
Business Justification
Clinical documentation automation improves physician efficiency and reduces after-hours documentation burden. No viable lower-risk alternative meets workflow requirements.
Compensating Controls
BAA executed, human review of all AI outputs, quarterly security assessment, restricted PHI access, audit logging enabled, private deployment configuration
Approval Lifecycle
Renewal Tracking
| Vendor | Approval Type | Renewal Status | Next Review | Days Remaining |
|---|---|---|---|---|
| OpenAI Enterprise | Conditionally Approved | Upcoming Renewal | 2026-11-20 | 159 days |
| Anthropic Claude | Approved | Current | 2026-10-10 | 88 days |
| DeepScribe | Approved | Current | 2026-09-25 | 73 days |
| Pearl AI | Conditionally Approved | Upcoming Renewal | 2026-08-28 | 45 days |
| S10.AI | Research Only | Scheduled | 2026-07-15 | 1 days |
| Abridge AI | Pilot Only | Scheduled | 2026-08-01 | 18 days |
| Nuance DAX | Retired | Expired | 2026-06-01 | 43 days overdue |
| Suki AI | Limited Use | Overdue | 2026-06-15 | 29 days overdue |
Evidence Management
Documentation Checklist
Security Whitepaper
AvailableSOC Report
VerifiedISO Evidence
AvailablePrivacy Policy
VerifiedTerms of Service
VerifiedBAA
VerifiedArchitecture Overview
AvailableSubprocessor List
PendingAI Governance Documentation
AvailableResponsible AI Documentation
RequestedIncident Response Plan
AvailableBusiness Continuity Plan
PendingGovernance FAQ
Executive Approval & Governance
What is an AI vendor approval workflow?▼
An AI vendor approval workflow is a structured governance process that organizations use to evaluate, review, and approve AI vendors before deployment. It typically includes stages such as evidence collection, technical review, security review, privacy review, governance review, executive review, and legal review. The workflow documents decisions, conditions, risk acceptance, and renewal schedules to ensure ongoing governance accountability.
Who should approve enterprise AI vendors?▼
Enterprise AI vendor approval should involve a cross-functional review team including security, privacy, compliance, legal, procurement, clinical, IT, governance, and executive stakeholders. Each role evaluates the vendor from their domain perspective. Final approval typically requires executive sponsor sign-off, with legal review ensuring contractual protections such as BAAs and data processing agreements are in place.
What is conditional approval for AI vendors?▼
Conditional approval means a vendor is approved for use with specific governance conditions attached. Common conditions include no PHI processing, human review of AI outputs, private deployment requirements, limited department approval, additional security controls, quarterly review requirements, or pending vendor documentation. Conditional approvals are governance conditions, not legal conclusions, and require ongoing monitoring.
When should AI vendors be re-reviewed?▼
AI vendors should be re-reviewed on a defined schedule, typically monthly, quarterly, semi-annually, or annually depending on risk level and approval type. Re-review is also triggered by significant changes such as security incidents, policy updates, subprocessor changes, model version updates, or contract renewals. High-risk vendors and conditionally approved vendors typically require more frequent review.
How should governance teams document AI vendor decisions?▼
Governance teams should maintain a structured decision log that records the date, reviewer, decision, reasoning, evidence status, governance notes, and supporting documentation for each stage of the approval workflow. Documentation should include the approval record, risk acceptance details, conditional approval conditions, review assignments, evidence checklist, and renewal schedule. This creates an auditable governance trail for regulatory accountability.
Governance Network
Related Governance Resources
Vendor Registry
Browse the full vendor registry
Vendor Monitoring Center
Continuous vendor governance tracking
Vendor Approval Library
Browse vendors by approval tier
Vendor Profiles
Detailed vendor intelligence profiles
Vendor Comparison
Side-by-side vendor comparisons
Healthcare AI Governance
Six-pillar governance framework
AI Governance for DSOs
DSO-specific governance program
AI Vendor Risk Management
Healthcare AI risk evaluation
Foreign AI Registry
Sovereign AI risk and jurisdictional review
Healthcare AI Resources
Governance education hub
Benchmark Reports
Healthcare AI governance benchmarks
Vendor Categories
Browse vendors by technology category
Governance Disclaimers
- • VNDRIQ provides governance workflow documentation to support enterprise procurement and risk management.
- • Approval decisions remain the responsibility of each organization.
- • VNDRIQ does not provide legal advice or regulatory approval.
- • Illustrative workflow examples are for demonstration purposes.