What this is.
Position in the architecture · Operational Machinery
Specification · Deposited. 10.5281/zenodo.22170146, CC BY 4.0.
Free to issue, free to answer.
Any institution may issue this questionnaire. Any vendor may answer it. Anyone may reproduce it, embed it in a procurement process, translate it, extend it, or build tooling on it, under CC BY 4.0, with attribution and without asking permission.
The inspection problem.
The model is not visible. The training data is not disclosed. The evaluation was performed by the party selling the result. An institution’s governance machinery, however well built, stops at the contract. A general third-party security questionnaire establishes that a supplier manages information security competently, and says nothing about what a model was trained on, how it was evaluated, whether it has failed before, or what happens when it is silently replaced.
The instrument.
Fifty-six questions in seven sections. Every question carries a fixed answer format and a stated evidence expectation, which is what makes two completed responses comparable rather than merely similar. An answer submitted without evidence is recorded as a vendor assertion, and the instrument makes that structural rather than leaving it to the reader’s judgement.
Prior art, named.
FS-ISAC publishes a generative AI vendor evaluation guide. The Cloud Security Alliance publishes an AI Controls Matrix and AI-CAIQ. Two things differ here. This instrument is issued by the institution rather than self-completed by the vendor, and it is shaped by the questions a model raises rather than by control domains carried across from security.
What this does not claim.
The scoring appendix is explicitly informative. Scoring is a judgement an institution makes against its own risk appetite, and a normative scheme would be asserting an appetite on its behalf.
No institution unconnected to the author has been observed using the instrument, and no supervisor has reviewed it.
Citation.
Cite this work. AI Vendor Risk Framework (AVRF), version 1.0. 10.5281/zenodo.22170146. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.
In the practice.
- Governed production AI, the discipline this framework belongs to
- Defensible AI, the family and the register
- AI Governance and Compliance Frameworks for the Middle East, the source treatment
- Model risk, the service this framework is applied through
- AI governance in the wiring, on where governance actually lives