AI Governance Portfolio
Ask most compliance leaders how many AI vendors they have actually reviewed, and the answer is often an estimate. Ask for the documentation behind that estimate, and the conversation usually stops.
This Toolkit helps you build a reliable audit trail, one AI system and one vendor review at a time, while streamlining contract management. Replace uncertainty with clear evidence and standardized contract language.
Ownership of AI vendor risk often becomes unclear at exactly the wrong moment. Procurement approves the purchase, legal reviews draft contracts, and security requests evidence that may not yet exist. By the time the tool is deployed, several teams may assume someone else completed the review.
This kit is designed for that reality. Rather than assuming a single owner, it provides a shared framework for governance, legal, privacy, security, procurement, and risk teams. Everyone works from the same register, the same due diligence process, and the same contract references, creating a consistent record that remains clear and usable long after the original decision was made.
Four practical resources, built to stay consistent from review to renewal:
✔ Workbook (.xlsx): AI System Register Workbook
✔ Workbook (.xlsx): AI Vendor Due Diligence Workbook
✔ Template Library (.xlsx): AI Vendor Contract Clauses & SLA Library
✔ Template (.docx): Standalone AI Vendor Contract Schedule
✔ User Guide (.pdf): The AI System Inventory, Vendor Due Diligence, and Contracting Toolkit - User Guide
An AI vendor approved today may look very different a year from now. Models evolve, sub-processors change, and terms governing data use can be updated over time. Without an organized record and review process, it becomes difficult to demonstrate what was assessed, what changed, and why decisions were made.
Organizations that maintain a current AI vendor register are better prepared for audits, customer reviews, and regulatory inquiries. Those without one often find themselves reconstructing months of decisions from emails, spreadsheets, and scattered documentation. Contract management becomes unmanageable.
Building your AI inventory from scratch: When no formal inventory exists, this kit provides a structured starting point, helping teams document AI systems, owners, vendors, and risk levels in one place.
Reviewing a vendor before contract approval: Move beyond vendor assurances by capturing evidence, evaluating controls, and documenting the basis for approval decisions.
Connecting due diligence to contract protections: When a risk cannot be fully addressed before signing, the clause library helps translate findings into clear contractual requirements.
Managing vendor changes over time: Track changes such as new sub-processors, updated services, or revised data-use terms, and determine whether a new review is required.
+
Purpose: Provides a centralized record for AI systems, vendor tools, models, and APIs, including ownership, key risk indicators, and review dates.
The AI System Register Workbook helps provide:
A comprehensive register capturing ownership, vendor information, data sensitivity, human oversight, and deployment stage for each system.
An automated Risk Tier calculation, ranging from Minimal to Prohibited, based on the information entered.
A dashboard that highlights risk levels, review status, and systems requiring attention.
Example Use Case: When leadership asks how many AI systems are currently in production, the answer is already available in the register, without requiring days or weeks of manual information gathering.
Simple Artifacts to Produce: (1) a centralized AI system register with assigned ownership; (2) an automated risk-tier classification per system; and (3) a dashboard summarizing review status and systems requiring attention.
+
Purpose: Provides a structured process for assessing AI vendors, documenting evidence, identifying gaps, and recording approval decisions.
The AI Vendor Due Diligence Workbook helps provide:
A Vendor Profile that determines which due diligence questions are relevant based on the vendor's characteristics.
Assessment checklists that convert responses into gap ratings and recommended actions.
Findings, remediation actions, and dashboard recommendations indicating whether to proceed, proceed with conditions, or escalate for further review.
Example Use Case: Instead of separate teams performing disconnected reviews, stakeholders work from a single assessment process, helping critical issues surface before contracts are finalized.
Simple Artifacts to Produce: (1) a completed vendor due diligence assessment with gap ratings; (2) a findings and remediation action tracker; and (3) a documented approval recommendation (proceed, proceed with conditions, or escalate).
+
Purpose: Helps convert due diligence findings into contractual protections through a structured library of AI-related clauses and service-level provisions.
The AI Vendor Contract Clauses & SLA Library helps provide:
Minimum requirements and suggested negotiating positions for each clause category.
SLA examples covering response times, remediation commitments, recovery objectives, and incident notification requirements.
Cross-references between due diligence findings and related contract clauses.
Example Use Case: When a vendor review identifies a concern, teams can quickly identify relevant contract language rather than creating new provisions from scratch.
Simple Artifacts to Produce: (1) a clause library with minimum requirements and negotiating positions; (2) a set of SLA benchmarks by category; and (3) a cross-reference log linking due diligence findings to contract clauses.
+
Purpose: Provides a streamlined contracting option for lower-risk vendors, built on the same due diligence foundation but without the full clause-library process, while maintaining a documented decision record.
The Standalone AI Vendor Contract Schedule helps provide:
A clause selection guide aligned to vendor risk levels.
Core AI, technical, operational, and change-management provisions.
A Contracting Decision Record that documents inclusions, exclusions, and approval rationale.
Example Use Case: For lower-risk engagements, teams can use a focused contract schedule that skips the full clause-library process, not the underlying risk review, while preserving clear documentation of the decision.
Simple Artifacts to Produce: (1) a risk-aligned clause selection guide; (2) a streamlined contract schedule covering core provisions; and (3) a Contracting Decision Record documenting approval rationale.
To obtain instant access, add the AI System Inventory, Vendor Due Diligence, and Contracting Toolkit to your shopping cart and proceed to our Checkout page. Upon completion of purchase, you will be able to immediately download the toolkit on your User Dashboard.
We can also separately invoice you or your organization prior to submitting payment, if desired. This allows us to add your organization’s tax-related information, purchase order numbers, or any other additional information needed by your organization onto the invoice. To find out more, please reach out to us at hello@privacybootcamp.com.
After payment, you will have three months to download your toolkit. The use of our toolkits, and any specific document contained therein, is subject to our Terms and Conditions.
To obtain instant access, add the AI System Inventory, Vendor Due Diligence, and Contracting Toolkit to your shopping cart and proceed to our Checkout page. Upon completion of purchase, you will be able to immediately download the toolkit on your User Dashboard.
We can also separately invoice you or your organization prior to submitting payment, if desired. This allows us to add your organization’s tax-related information, purchase order numbers, or any other additional information needed by your organization onto the invoice. To find out more, please reach out to us at hello@privacybootcamp.com.
After payment, you will have three months to download your toolkit. The use of our toolkits, and any specific document contained therein, is subject to our Terms and Conditions.