====== Vendor Evaluation Template ====== Use this template to evaluate a vendor, software provider, consultant, contractor, or AI platform against structured business, procurement, security, privacy, and operational criteria. ===== Vendor Record ===== **Vendor Name:** [Vendor Name] **Product or Service:** [Product or Service Name] **Evaluation Type:** [Software / AI Tool / Consultant / Contractor / Service Provider] **Requesting Department:** [Department Name] **Evaluation Lead:** [Person or Role] **Status:** Draft **Risk Level:** [Low / Moderate / High] **Last Reviewed:** [Month Year] ===== Purpose ===== This evaluation helps organizations compare vendors consistently, document due diligence, identify risks, and support procurement or purchasing decisions. ===== Business Need ===== Describe the problem the vendor is expected to solve. * [Business need] * [Expected outcome] * [Key success measure] ===== Vendor Evaluation Criteria ===== ^ Category ^ Evaluation Question ^ Score ^ Notes ^ | Business Fit | Does the vendor solve the identified business problem? | [1–5] | [Notes] | | Cost | Is the price reasonable and sustainable? | [1–5] | [Notes] | | Experience | Does the vendor have relevant experience? | [1–5] | [Notes] | | Security | Does the vendor demonstrate appropriate security controls? | [1–5] | [Notes] | | Privacy | Does the vendor protect confidential and sensitive information? | [1–5] | [Notes] | | Accessibility | Does the product or service meet accessibility expectations? | [1–5] | [Notes] | | Integration | Can the solution work with existing systems and workflows? | [1–5] | [Notes] | | Support | Does the vendor provide responsive support and training? | [1–5] | [Notes] | | Scalability | Can the solution grow with organizational needs? | [1–5] | [Notes] | | Exit Strategy | Can the organization retrieve data and transition away if needed? | [1–5] | [Notes] | ===== AI and Data Review ===== Use this section when evaluating AI tools, data platforms, or technology vendors. * What data will the vendor collect, process, store, or retain? * Will organizational data be used to train vendor models? * Can data be exported? * Can data be deleted? * Are audit logs available? * Are administrative controls available? * Does the vendor provide documentation of known limitations? * How are incidents reported and handled? ===== Required Documents ===== * Proposal or quote * Scope of work * Security documentation * Privacy documentation * Accessibility statement * References or past performance examples * Insurance certificates * Contract terms * Data-processing terms, if applicable ===== Risk and Gap Review ===== ==== Identified Risks ==== * [Risk] * [Risk] * [Risk] ==== Required Mitigations ==== * [Mitigation] * [Mitigation] * [Mitigation] ===== Recommendation ===== **Recommended Decision:** [Approve / Approve with Conditions / Decline / Request More Information] **Rationale:** Describe the recommendation and the factors that support it. ===== Approval Record ===== ^ Role ^ Name ^ Decision ^ Date ^ | Requesting Department | [Name] | [Approve / Decline] | [Date] | | Procurement | [Name] | [Approve / Decline] | [Date] | | IT / Security | [Name] | [Approve / Decline] | [Date] | | Legal / Privacy | [Name] | [Approve / Decline] | [Date] | ===== Related OKF Resources ===== * [[templates:ai_governance|AI Governance Template]] * [[templates:rfp_compliance_matrix|RFP Compliance Matrix Template]] * [[templates:knowledge_concept|OKF Knowledge Concept Template]] * [[templates:knowledge_bundle|OKF Knowledge Bundle Template]] * [[templates:start|Return to OKF Templates]]