The Vendor Approval Kit
Review external software vendors and control how third-party tools handle your data.
If your small business relies on external software, automated services, or dedicated artificial intelligence platforms, you are responsible for the security of the data you share with them. However, without a practical evaluation process, it is easy to bring on tools that expose your proprietary files, customer names, or financial records to unknown third-party training models.
The Vendor Approval Kit gives you a straightforward, non-technical toolkit designed for everyday business owners to evaluate external software vendors and traditional tools that have recently introduced automated AI features. It requires no complex legal background or IT expertise to implement.
What is inside this kit?
- The Vendor Filter & Risk Guide Includes an internal request form to define business needs, data touchpoints, and a non-AI alternative check, alongside a clear Vendor Risk Matrix categorizing tools into Green (low risk), Yellow (medium risk), and Red (high risk) lights.
- Existing Vendor Update Audit A structured review process for evaluating legacy software vendors that suddenly roll out background AI processing or automated features.
- Copy-and-Paste Vendor Questionnaires Direct, professional communication templates to ask software providers crucial questions regarding data retention, privacy policies, and security practices.
- The Dealbreaker Index An automated checklist of red flags that instantly disqualifies a vendor before they compromise your corporate safety.
- Vendor Contract Rider A ready-to-use legal agreement outline covering strict data separation, prohibitions on model training, and mandatory 30-day permanent data deletion policies.
Why use this kit?
- Zero Complex Terminology: Written in plain, straightforward English so leadership or operations teams can evaluate software providers immediately.
- Built for All Third-Party Software: Broadly applicable to dedicated AI startups as well as established software providers implementing automated background features.
- Informed by Industry Standards: Built using structural principles consistent with the NIST AI Risk Management Framework (AI RMF 1.0).
Frequently Asked Questions
- Do I need an attorney to use the Vendor Contract Rider? Yes, this kit provides practical operational templates and contract addenda, but you should always have a qualified attorney review agreements before enforcing them.
- How do I know if a vendor is using my data to train models? The kit includes specific questionnaire templates that force vendors to declare whether your inputs, files, or chat histories are used to train public or shared artificial intelligence networks.