Sheet 07 · ART-07
Vendor evaluation worksheet
Structured, comparable criteria for evaluating a tool or vendor, so decisions rest on the same questions each time and the gaps are visible.
Artifact details
- Format
- Worksheet
- Owner
- AI Program Manager coordinates; Security, Risk, and Finance own their sections.
- When it is used
- When a new tool is proposed or an existing one is expanded beyond its approved scope.
- Retention
- Life of the vendor relationship plus contractual retention.
Contributors: Information Security, Risk, Legal & Privacy, Finance & Procurement, Business owner, Data & Reporting
Downloads
The blank template is a standalone worksheet with every field and its guidance, ready to fill in or print. Printing uses this page’s print stylesheet, which drops the navigation and the download controls.
Required fields
The guidance matters more than the field name. A field labelled “risks” with no guidance gets filled in with “standard AI risks” and the artifact stops being worth reading.
| Field | Guidance | Required |
|---|---|---|
| Capability fit | Against the stated business problem, not against a feature list. | Required |
| Security posture | Certifications, testing evidence, incident history, tenant isolation. | Required |
| Data handling | Where processed, subprocessors, training use, retention, deletion. | Required |
| Contractual terms | Data processing agreement, liability, indemnity, exit and portability. | Required |
| Cost | Licensing, implementation, support, and the internal time to run it. | Required |
| Maintainability | Who administers it, what breaks on a vendor update, what happens at renewal. | Required |
| Buy versus build versus existing | Can an approved tool already do this acceptably? | Required |
| Open questions and recommendation | Gaps stated plainly, with a recommendation to the decision owner. | Required |
Worked example
Filled in against the sample record set, so the template can be judged on what a real entry looks like rather than on its headings.
TL-05 Ledgerly AI — evaluation summary
- Capability fit: strong. Addresses invoice coding directly, with connectors to the finance system already in place.
- Security posture: current certification provided. Penetration test summary provided. No incident history disclosed.
- Data handling: GAP — subprocessor list incomplete. Vendor could not identify every party processing invoice data or the jurisdictions involved.
Terms, cost, and alternatives
- Contractual: data processing agreement not executed. Firm's standard subprocessor clause not accepted as drafted.
- Cost: $48,000 annual at proposed volume, plus an estimated 60 hours of internal setup.
- Buy versus build versus existing: no approved tool covers this. Existing finance automation handles matching but not coding.
Recommendation to the decision owner
- Do not proceed to production pilot until the data processing agreement is executed with a complete subprocessor list.
- Test-environment work may continue. Vendor checkpoint 2026-09-30; if unmet, recommend retiring the evaluation.
- Recorded as DEC-2026-06. Decision owner: Elena Ward, Risk, Legal & Privacy.
Blank template
The same fields with nothing in them. Print this page, or use the download above to get a standalone file.
Capability fit
Against the stated business problem, not against a feature list.
Security posture
Certifications, testing evidence, incident history, tenant isolation.
Data handling
Where processed, subprocessors, training use, retention, deletion.
Contractual terms
Data processing agreement, liability, indemnity, exit and portability.
Cost
Licensing, implementation, support, and the internal time to run it.
Maintainability
Who administers it, what breaks on a vendor update, what happens at renewal.
Buy versus build versus existing
Can an approved tool already do this acceptably?
Open questions and recommendation
Gaps stated plainly, with a recommendation to the decision owner.