Name the object being reviewed
Record the seller, contracting entity, product surface, account or endpoint, exact model or alias, region, administrators, intended users and the order form or incorporated terms. A consumer chat, API organization, cloud marketplace and embedded workspace feature may sit under different documents and controls even when the provider name is the same.
Describe one workflow: input, transformation, tools, output, destination and accountable reviewer. Classify the data and consequence. This narrow object prevents a broad security statement from being reused as if it covered every product route.
Trace the data path
Separate customer content, prompts, files, outputs, feedback, telemetry, abuse or safety logs, caches, retrieval indexes and downstream copies. Ask where each category is processed, who can access it, which subprocessors receive it and how deletion is tested. A no-training statement answers one question; it does not prove retention, human access or connector behavior.
| Data field | Question | Evidence to keep |
|---|---|---|
| Content and files | Where are they processed, retained and deleted? | Product terms, settings and deletion test |
| Tools and destinations | Can a connector read, write or send? | Permission map and canary run |
| Logs and support | Who can access operational copies? | Retention, access and incident record |
Test identity, authority and audit
Record managed identities, least privilege, key ownership, offboarding and administrator roles. For each tool, list allowed sources and destinations, payloads, write permissions, preview or approval points and stop conditions. Run non-sensitive canaries for denied access, denied write, required approval, credential revocation and destination verification.
Request a reconstruction record containing actor, model, input reference, source set, tool request, permission decision, approval, result, destination, error and final disposition. Keep the decisive facts in the buyer record; the public article explains the method.
Make incidents and model changes operational
Ask for stable event identifiers, support escalation, containment options, evidence preservation, notification commitments and post-incident review. Do not insert one universal deadline: contract, law, client instructions and the event determine the analysis.
For model or safeguard changes, request notice, exact identifiers, lifecycle, regression time, rollback, suspension and exit. Preserve the prior route until the observation window passes. OpenAI’s Astra material shows why capability, safeguards and access can change together; the buyer still needs route-specific evidence.
Close with a narrow state
Use approve, restrict, remediate and retest, reject or Unknown. Name the workflow, data, users, tools, duration, owner and review trigger. A missing material answer stays Unknown; it is not a green light. Re-open when the model, terms, connectors, region, data class or external action changes.
FAQ
Does a completed vendor questionnaire prove compliance?
No. It organizes evidence for a scoped decision. Legal, professional, client and security conclusions remain with the responsible reviewers.
Can one provider answer cover every model and marketplace?
No. Contracts, hosting, identity, retention, safeguards and support can differ by surface.
What should happen when the vendor cannot answer?
Record Unknown, identify the affected decision and restrict or hold the workflow when the missing evidence is material.
Sources checked
- AI Risk Management Framework, checked 2026-09-03.
- ABA Formal Opinion 512, checked 2026-09-03.
- OpenAI business data privacy, security and compliance, checked 2026-09-03.
- OpenAI Services Agreement, checked 2026-09-03.
- Gemini API Additional Terms, checked 2026-09-03.
Operational information, not legal advice. Verify current terms, account configuration and applicable professional duties before use.