Show pageOld revisionsBack to top This page is read only. You can view the source, but not change it. Ask your administrator if you think this is wrong. ====== Vendor Requirements ====== **Knowledge Bundle:** Public-Sector AI Readiness **Concept ID:** government:vendor_requirements **Concept Type:** Vendor Governance Guidance **Status:** Draft **Audience:** Procurement staff, IT teams, legal counsel, vendors, department leaders **Steward:** OKF Expert **AI Use:** Human-reviewed **Last Reviewed:** June 2026 ===== Purpose ===== Vendor requirements establish the minimum expectations an AI vendor should meet before an agency purchases, deploys, or renews an AI-enabled product or service. The goal is to ensure vendors protect agency data, support transparency, provide appropriate controls, and enable responsible oversight. ===== Core Vendor Requirements ===== * Clear description of the AI system and its intended use * Identification of all agency data collected, processed, stored, or retained * Data ownership provisions * Restrictions on using agency data for model training * Data retention and deletion requirements * Cybersecurity safeguards * Privacy and confidentiality protections * Incident notification requirements * Administrative access controls * Audit logs and activity records * Accessibility commitments * Documentation of known limitations * Export and transition support if the contract ends ===== Questions Agencies Should Ask Vendors ===== * What data does the system collect? * Where is agency data stored? * Will agency data be used to train models? * Can agency data be exported? * Can chat histories, prompts, and uploaded files be deleted? * What audit logs are available? * What security certifications or controls does the vendor maintain? * How are system changes communicated? * How does the vendor handle inaccurate or harmful outputs? * What happens if the service is discontinued? ===== Required Contract Protections ===== * Agency ownership of its data * Confidentiality obligations * Data-use restrictions * Security requirements * Breach notification timelines * Service-level expectations * Audit rights where appropriate * Exit and transition provisions * Return or deletion of agency data at contract end * Cooperation with public-records and legal obligations ===== Vendor Documentation Record ===== For each AI vendor, maintain: * Vendor name * Product name * Approved use case * Contract owner * Data categories involved * Risk level * Security review status * Privacy review status * Procurement approval status * Renewal date * Required safeguards ===== Related Concepts ===== * [[government:ai_procurement|AI Procurement]] * [[government:ai_governance|AI Governance]] * [[government:ai_risk_assessment|AI Risk Assessment]] * [[government:public_records|Public Records and AI]] * [[government:ai_readiness|Return to Public-Sector AI Readiness]] government/vendor_requirements.txt Last modified: 2026/06/22 00:32by leonidas Log In