Vendor Requirements
Knowledge Bundle: Public-Sector AI Readiness Concept ID: government:vendor_requirements Concept Type: Vendor Governance Guidance Status: Draft Audience: Procurement staff, IT teams, legal counsel, vendors, department leaders Steward: OKF Expert AI Use: Human-reviewed Last Reviewed: June 2026
Purpose
Vendor requirements establish the minimum expectations an AI vendor should meet before an agency purchases, deploys, or renews an AI-enabled product or service.
The goal is to ensure vendors protect agency data, support transparency, provide appropriate controls, and enable responsible oversight.
Core Vendor Requirements
- Clear description of the AI system and its intended use
- Identification of all agency data collected, processed, stored, or retained
- Data ownership provisions
- Restrictions on using agency data for model training
- Data retention and deletion requirements
- Cybersecurity safeguards
- Privacy and confidentiality protections
- Incident notification requirements
- Administrative access controls
- Audit logs and activity records
- Accessibility commitments
- Documentation of known limitations
- Export and transition support if the contract ends
Questions Agencies Should Ask Vendors
- What data does the system collect?
- Where is agency data stored?
- Will agency data be used to train models?
- Can agency data be exported?
- Can chat histories, prompts, and uploaded files be deleted?
- What audit logs are available?
- What security certifications or controls does the vendor maintain?
- How are system changes communicated?
- How does the vendor handle inaccurate or harmful outputs?
- What happens if the service is discontinued?
Required Contract Protections
- Agency ownership of its data
- Confidentiality obligations
- Data-use restrictions
- Security requirements
- Breach notification timelines
- Service-level expectations
- Audit rights where appropriate
- Exit and transition provisions
- Return or deletion of agency data at contract end
- Cooperation with public-records and legal obligations
Vendor Documentation Record
For each AI vendor, maintain:
- Vendor name
- Product name
- Approved use case
- Contract owner
- Data categories involved
- Risk level
- Security review status
- Privacy review status
- Procurement approval status
- Renewal date
- Required safeguards