Figure 1. Why a fixed answer format. Two completed responses become comparable rather than merely similar.
§ 02The grant
Free to issue, free to answer.
Any institution may issue this questionnaire. Any vendor may answer it. Anyone may reproduce it, embed it in a procurement process, translate it, extend it, or build tooling on it, under CC BY 4.0, with attribution and without asking permission.
§ 03The inspection problem
The inspection problem.
The model is not visible. The training data is not disclosed. The evaluation was performed by the party selling the result. An institution’s governance machinery, however well built, stops at the contract. A general third-party security questionnaire establishes that a supplier manages information security competently, and says nothing about what a model was trained on, how it was evaluated, whether it has failed before, or what happens when it is silently replaced.
Figure 2. Fifty-six questions in seven sections, each carrying a stated evidence expectation.
§ 04The instrument
The instrument.
Fifty-six questions in seven sections. Every question carries a fixed answer format and a stated evidence expectation, which is what makes two completed responses comparable rather than merely similar. An answer submitted without evidence is recorded as a vendor assertion, and the instrument makes that structural rather than leaving it to the reader’s judgement.
Figure 3. Where vendor risk enters the lifecycle.
§ 05Prior art, named
Prior art, named.
FS-ISAC publishes a generative AI vendor evaluation guide. The Cloud Security Alliance publishes an AI Controls Matrix and AI-CAIQ. Two things differ here. This instrument is issued by the institution rather than self-completed by the vendor, and it is shaped by the questions a model raises rather than by control domains carried across from security.
§ 06Where it applies
Which institutions, and on whose authority.
Any regulated institution
Vendor risk applies wherever AI arrives through a boundary the institution cannot inspect, which is now everywhere. The instrument is deliberately sector-neutral: the same fifty-six questions are asked of a model vendor serving a bank and one serving a hospital, because what is being established is what the vendor can evidence.
§ 07How it has changed
The record of its own revisions.
A framework that cannot say how it changed reads as though it never has. This is drawn from the registry entry, which versions itself independently of the specification it points at.
Change history
2026-08-30 · entry v1.0 — First registry entry, status instrument-pending
Limitations recorded in the registry
That the questionnaire structure matches supervisory expectations for third-party model risk. No supervisor has reviewed the instrument.
The questionnaire is now deposited, so the instrument exists. What remains missing is evidence that two institutions applying it independently produce comparable answers, which is a property use confers rather than publication.
Governs the assessment of the vendor. Does not govern the selection decision, the commercial negotiation or the security assessment of the vendor's infrastructure.
What would show this to be wrong. AVRF is falsified if vendors assessed under the full five stages are found to produce AI incidents in the acquiring institution at the same rate and severity as vendors assessed under a generic third-party security questionnaire. The framework's claim is that model-specific diligence changes the outcome, and evidence that it does not would make the additional stages ceremony.
§ 08Honest limits
What this does not claim.
The scoring appendix is explicitly informative. Scoring is a judgement an institution makes against its own risk appetite, and a normative scheme would be asserting an appetite on its behalf.
No institution unconnected to the author has been observed using the instrument, and no supervisor has reviewed it.
§ 09Cite
Citation.
Cite this work. AI Vendor Risk Framework (AVRF), version 1.0. 10.5281/zenodo.22170146. This is the concept DOI and it always resolves to the latest version. CC BY 4.0.
This page is a snapshot, accurate at the release it cites. The same corpus is callable, publicly and without a key, so an assistant can query it live and return an answer carrying the source it came from. For this page that is explain_this_setup and search_knowledge, which do what this page describes rather than describe it again: the first returns how this site's machine layer is actually built, component by component, and the second queries the corpus behind this page and returns matches with the URL each came from. The page states the practice; the tools are the practice.
01 · Connect
claude mcp add --transport http concylium https://mcp.nabeelkhan.com/api/mcp
Claude Desktop, ChatGPT, Cursor, VS Code and Gemini CLI take the endpoint on its own: https://mcp.nabeelkhan.com/api/mcp. No key, no account, nothing to sign. Setup for every client.
02 · Ask
“Using Concylium, call explain_this_setup and tell me whether this site actually implements what its machine-accessible-ai-expertise page claims.”
A category page that survives being audited by the reader's own assistant is doing something a brochure cannot.
A note on cookies
This site uses Google Analytics and the Meta pixel to understand what gets read and which work reaches people. Analytics loads with storage denied, so no cookie is set and nothing is kept until you choose. The Meta pixel does not load at all unless you accept. Details in the privacy & cookies notice.