AI Vendor Risk Assessment Template
Before a vendor joins the allowlist, it gets a risk pass. This template structures the review.
The assessment
Vendor: [NAME] | Category: [TYPE].
Reputation: [history, reviews, source].
Pricing model: [per-call, per-token, subscription] — and overage behavior.
Data handling: [what they receive, retention].
Spend risk: [worst-case monthly if agent loops].
Decision: [APPROVE / CONDITIONAL / REJECT].
Turning it into rules
APPROVE → allowlist with limits. CONDITIONAL → allowlist with lower caps. REJECT → absent from the allowlist (blocked by default).
Risk → rule mapping
APPROVE -> allowlist + standard limits
CONDITIONAL -> allowlist + reduced caps + FLAG threshold
REJECT -> not on allowlist (BLOCKED by default)
The assessment becomes enforcement.
FAQ
Who does the assessment?
Procurement or the budget owner — whoever owns vendor relationships.
How often to reassess?
Annually, or when pricing/behavior changes.
Related
Stop the next $12,400 night.
One API call (or MCP tool) in front of every agent transaction — APPROVED, BLOCKED, or FLAGGED, deterministic, ~5 ms, fully logged.
See plans — from $99/mo Try a live check