FrameworkAI Vendor Risk Framework (AVRF)Sheet 55

Most of your exposure arrives through a boundary you cannot inspect.

A due-diligence discipline for third-party AI.

← Defensible AI

§ 01Status

What this is.

REG-04 · AI Vendor Risk Framework (AVRF)™

Position in the architecture · Operational Machinery

Specification · Deposited. 10.5281/zenodo.22170146, CC BY 4.0.

Why a fixed answer format makes two responses comparable The same underlying question is put to two vendors in two ways. On the left, in bespoke prose, each vendor answers in its own words: one says it takes data provenance seriously and maintains rigorous internal processes, the other says its provider publishes a model card. Both are readable, neither is comparable with the other, and the institution ends up ranking the quality of the writing rather than the substance. On the right, the same question is asked with a fixed answer format and a stated evidence expectation. Vendor one answers developed and attaches a provenance record, which is recorded as answered. Vendor two answers licensed and attaches nothing, which is recorded as asserted. The difference between the two vendors is now visible in the answer itself rather than in the prose, an unevidenced answer is marked rather than presented as a finding, and a third vendor asked the same question next year produces a response that can be compared with both. Why a fixed answer format makes two responses comparable Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170146 https://doi.org/10.5281/zenodo.22170146 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/avrf ONE QUESTION, TWO VENDORS BESPOKE PROSE asked as: tell us about your approach to model provenance VENDOR ONE We take data provenance extremely seriously and maintain rigorous internal processes throughout the model development lifecycle. no attachment VENDOR TWO Our upstream provider publishes a model card covering data sources. We can share it under NDA on request. no attachment Both readable. Neither comparable with the other. The institution ends up ranking the writing. FIXED FORMAT, STATED EVIDENCE asked as A2, with four options and a stated evidence expectation VENDOR ONE A2 = developed evidence: licence naming the model source, attached ANSWERED VENDOR TWO A2 = licensed evidence: not supplied ASSERTED The difference is in the answer, not in the prose. An unevidenced answer is marked, not presented as a finding. A vendor asked the same question by many institutions answers it once, well, with evidence. A vendor asked twenty variants answers each one cheaply. That is why the instrument is published to be taken. The AI Vendor Due-Diligence Questionnaire v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/avrf · CC BY 4.0 · DOI 10.5281/zenodo.22170146
Figure 1. Why a fixed answer format. Two completed responses become comparable rather than merely similar.
§ 02The grant

Free to issue, free to answer.

Any institution may issue this questionnaire. Any vendor may answer it. Anyone may reproduce it, embed it in a procurement process, translate it, extend it, or build tooling on it, under CC BY 4.0, with attribution and without asking permission.

§ 03The inspection problem

The inspection problem.

The model is not visible. The training data is not disclosed. The evaluation was performed by the party selling the result. An institution’s governance machinery, however well built, stops at the contract. A general third-party security questionnaire establishes that a supplier manages information security competently, and says nothing about what a model was trained on, how it was evaluated, whether it has failed before, or what happens when it is silently replaced.

The seven sections of the questionnaire and what each establishes Seven sections in a deliberate order. Section A, provenance and identity, eight questions, establishes what the capability actually is, including whether the vendor controls the underlying model. Section B, training data, nine questions, establishes how the model came to behave as it does, where the most useful answer is often a candid statement of what the vendor does not know. Section C, evaluation and performance, nine questions, establishes what was measured, by whom, and whether a customer can reproduce it. Section D, incident history, eight questions, establishes what has already gone wrong, and includes a question on how the vendor defines an incident, because a vendor reporting none is either new, lucky, or not counting. Section E, subprocessors and supply chain, seven questions, establishes who else is involved, and applies to class C1 only. Section F, model change and notification, eight questions, establishes whether the institution will know when the thing it assessed is replaced, and carries the highest ratio of value to length because every other answer describes a model that can be changed without notice. Section G, exit and portability, seven questions, establishes whether the institution can leave, and asks whether an exit has ever actually been performed. Fifty-six questions in total. The order matters: a vendor unable to answer the early sections rarely needs to be asked the later ones. The seven sections of the questionnaire and what each establishes Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170146 https://doi.org/10.5281/zenodo.22170146 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/avrf THE SEVEN SECTIONS A Provenance and identity what the capability actually is, and whether the vendor controls the model underneath it 8 B Training data how it came to behave as it does. The most useful answer is often what the vendor does not know 9 C Evaluation and performance what was measured, by whom, on what, and whether a customer can reproduce any of it 9 D Incident history what has already gone wrong. A vendor reporting none is new, lucky, or not counting 8 E Subprocessors and supply chain who else is involved, and what rights exist against the party upstream. Class C1 only 7 F Model change and notification whether you will know when the thing you assessed has been replaced under you 8 G Exit and portability whether you can leave, and whether anyone ever actually has 7 a vendor that cannot answer the early sections rarely needs the later ones Fifty-six questions. Section F carries the highest ratio of value to length, because every other answer in the questionnaire describes a model that can be changed without notice. The AI Vendor Due-Diligence Questionnaire v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/avrf · CC BY 4.0 · DOI 10.5281/zenodo.22170146
Figure 2. Fifty-six questions in seven sections, each carrying a stated evidence expectation.
§ 04The instrument

The instrument.

Fifty-six questions in seven sections. Every question carries a fixed answer format and a stated evidence expectation, which is what makes two completed responses comparable rather than merely similar. An answer submitted without evidence is recorded as a vendor assertion, and the instrument makes that structural rather than leaving it to the reader’s judgement.

Where the questionnaire sits in the vendor lifecycle The capability is classified first, as class C1, C2 or C3, and the classification determines which of the seven sections are issued. The questionnaire is then issued and the vendor responds. The response and its evidence are recorded per question, with each answer marked as answered, asserted, declined or not applicable, and become vendor risk records. Those records are entry evidence at gate one, Data and Design, and again at gate four, Deployment, of the Five-Gate Deployment Model. Four triggers re-issue the questionnaire: contract renewal, a material model change notified or discovered, an incident at the vendor or at the institution, and a change of classification. The prior response is retained rather than replaced, because a response is a dated artifact and not a permanent property of the vendor. Where the questionnaire sits in the vendor lifecycle Nabeel Khan 2026 https://doi.org/10.5281/zenodo.22170146 https://doi.org/10.5281/zenodo.22170146 Copyright 2026 Nabeel A. Khan. Licensed CC BY 4.0. Nabeel Khan https://nabeelkhan.com/frameworks/avrf WHERE THE QUESTIONNAIRE SITS Classify C1, C2 or C3 any doubt means C1 sets the sections Issue every question in every section issued Vendor responds answered · asserted declined · not-applicable Vendor risk records per question: the answer, and whether the evidence was supplied entry evidence Five-Gate G1 Data and Design Five-Gate G4 Deployment FOUR TRIGGERS RE-ISSUE THE QUESTIONNAIRE contract renewal a material model change an incident, at the vendor a change of notified or discovered or at the institution classification the prior response is retained, never replaced A response is a dated artifact, identified by questionnaire version, vendor, capability and date. It is not a permanent property of the vendor. The AI Vendor Due-Diligence Questionnaire v1.0 · Nabeel Khan · nabeelkhan.com/frameworks/avrf · CC BY 4.0 · DOI 10.5281/zenodo.22170146
Figure 3. Where vendor risk enters the lifecycle.
§ 05Prior art, named

Prior art, named.

FS-ISAC publishes a generative AI vendor evaluation guide. The Cloud Security Alliance publishes an AI Controls Matrix and AI-CAIQ. Two things differ here. This instrument is issued by the institution rather than self-completed by the vendor, and it is shaped by the questions a model raises rather than by control domains carried across from security.

§ 06Honest limits

What this does not claim.

The scoring appendix is explicitly informative. Scoring is a judgement an institution makes against its own risk appetite, and a normative scheme would be asserting an appetite on its behalf.

No institution unconnected to the author has been observed using the instrument, and no supervisor has reviewed it.

§ 07Cite

Citation.

Cite this work. AI Vendor Risk Framework (AVRF), version 1.0. 10.5281/zenodo.22170146. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.

§ 08Where this sits

In the practice.

§ 10Ask an assistantLive, no key

Ask your AI assistant instead.

This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.

01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp

Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.

02 · Ask

“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”

A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.

Fin · Machine-Accessible Expertise
Point your assistant at the endpoint →