Vendor Requirements

Knowledge Bundle: Public-Sector AI Readiness Concept ID: government:vendor_requirements Concept Type: Vendor Governance Guidance Status: Draft Audience: Procurement staff, IT teams, legal counsel, vendors, department leaders Steward: OKF Expert AI Use: Human-reviewed Last Reviewed: June 2026

Vendor requirements establish the minimum expectations an AI vendor should meet before an agency purchases, deploys, or renews an AI-enabled product or service.

The goal is to ensure vendors protect agency data, support transparency, provide appropriate controls, and enable responsible oversight.

  • Clear description of the AI system and its intended use
  • Identification of all agency data collected, processed, stored, or retained
  • Data ownership provisions
  • Restrictions on using agency data for model training
  • Data retention and deletion requirements
  • Cybersecurity safeguards
  • Privacy and confidentiality protections
  • Incident notification requirements
  • Administrative access controls
  • Audit logs and activity records
  • Accessibility commitments
  • Documentation of known limitations
  • Export and transition support if the contract ends
  • What data does the system collect?
  • Where is agency data stored?
  • Will agency data be used to train models?
  • Can agency data be exported?
  • Can chat histories, prompts, and uploaded files be deleted?
  • What audit logs are available?
  • What security certifications or controls does the vendor maintain?
  • How are system changes communicated?
  • How does the vendor handle inaccurate or harmful outputs?
  • What happens if the service is discontinued?
  • Agency ownership of its data
  • Confidentiality obligations
  • Data-use restrictions
  • Security requirements
  • Breach notification timelines
  • Service-level expectations
  • Audit rights where appropriate
  • Exit and transition provisions
  • Return or deletion of agency data at contract end
  • Cooperation with public-records and legal obligations

For each AI vendor, maintain:

  • Vendor name
  • Product name
  • Approved use case
  • Contract owner
  • Data categories involved
  • Risk level
  • Security review status
  • Privacy review status
  • Procurement approval status
  • Renewal date
  • Required safeguards
  • government/vendor_requirements.txt
  • Last modified: 2026/06/22 00:32
  • by leonidas