The Enterprise AI Vendor Risk Assessment, From Both Sides
A practical enterprise AI vendor risk assessment: the questions buyers use to decide, and the answers vendors should pre-package to clear the review and get to yes.
A vendor risk assessment is the same document read two ways. The buyer uses it to decide whether trusting you is defensible. The vendor should use it to know exactly what to prove before anyone asks. Most AI vendors treat the risk assessment as an ambush that arrives late in the deal. It is not an ambush if you already have the answers, and having the answers is entirely within your control.
Here is the assessment I would run as a buyer, and pre-answer as a vendor. Same list, both directions. Work through it before your deal reaches the risk owner, and the review stops being the thing that kills your momentum.
Can the system take a harmful action on its own
This is the first question and it can end the review by itself. Can the AI move money, delete records, send external communication, or expose data without a human in the loop. If the answer is yes, most enterprise buyers stop here, because the worst case is unbounded and no committee will own that.
The answer that clears the gate: high-stakes actions are blocked by construction and routed to a human. As a vendor, make this the first thing you volunteer, because it converts your worst-looking risk into your strongest proof. As a buyer, do not accept a policy answer; ask to see the constraint in the architecture. This is the difference between a system that promises good behavior and one that makes bad behavior impossible.
Can you reconstruct what happened after the fact
The second question is accountability. When something goes wrong six months from now, can the incident be reconstructed: what was asked, what the model proposed, which checks ran, and what finally happened. A system that cannot be reviewed is a black box, and a compliance team cannot approve a black box.
As a vendor, show the audit trail as a core artifact, not a footnote. As a buyer, treat the absence of one as disqualifying, because without it you are trusting the vendor's word instead of your own ability to verify. Reviewability is what lets a risk owner sign, because it means their trust is checkable rather than blind.
Where does the data go and does it train the model
The data questions decide whether the buyer can meet their own obligations. Where is data stored, does it stay in the required region, does it leave your boundary to a model provider, and is it used for training. Vague answers here read as unmanaged risk.
As a vendor, answer with specifics: residency, the subprocessor list, and an unambiguous no-training, no-retention commitment where true. As a buyer, ask for the full data path and the provider terms, not a reassuring summary. I cover the full version of this in where does our data go, because it is the single most common blocker in an enterprise AI deal.
How reliable is it, measured honestly
Capability claims are not evidence. The assessment needs a real measurement: how the system performs on cases like the buyer's, including the hard ones, with the failure rate visible and the methodology open.
As a vendor, present evals that show where it breaks, not a perfect record, because the perfect record reads as concealment. As a buyer, distrust any accuracy number you cannot scrutinize, and ask what happens when the system is uncertain. Reliability you can inspect beats reliability you are asked to believe, which is why measuring it honestly is a competitive advantage, not a liability.
Is the vendor operationally sound and honest
The last section is about the company, not the model. Do you have basic security controls (SOC 2 or equivalent), an incident response process, and a track record of stating only what you can defend. A vendor who oversells one thing has told you how they will handle the next problem.
As a vendor, run tight claims discipline through the entire assessment, because one overstatement that falls apart makes every other answer suspect. As a buyer, probe one claim hard; how the vendor handles being pressed tells you more than the answer itself.
Same list, opposite intent
The buyer runs this assessment to find the reason to say no. The vendor should run it to remove every reason in advance. Same five areas: autonomous action, reviewability, data handling, honest reliability, and operational integrity. A vendor who arrives with all five pre-answered turns a weeks-long risk review into a formality, and a buyer who insists on all five avoids the vendors who cannot deliver them.
That is how I build the enterprise ventures in my portfolio, from Agency Script to CaseSolo. Know the assessment the buyer will run, and be the vendor who already answered it. The review is only an obstacle if you show up without the evidence.