---
title: "AI Vendor Risk Scorecard — Score Any AI Vendor in 5 Minutes | EFROS"
description: "Free 15-question AI vendor risk scorecard. Score any AI vendor (OpenAI, Anthropic, Microsoft Copilot, custom GPT) against NIST AI RMF, SOC 2, and contract-risk baselines across 5 categories."
canonical: https://efros.com/tools/ai-vendor-risk-scorecard/
---

- [Home](https://efros.com/)
- /[Tools](https://efros.com/tools/)
- /AI Vendor Risk Scorecard

Tool

# AI vendor risk scorecard

Fifteen questions across five categories (Data Handling, Model Governance, Security Controls, Vendor Maturity, and Legal/Contract) that score any AI vendor against NIST AI RMF, SOC 2, and the procurement baselines US regulated organizations need. Each answer is worth 0–3 points. You get a /45 score, a per-category breakdown, and a risk tier with concrete next steps. Use it for OpenAI, Anthropic, Microsoft Copilot, custom GPTs, or any embedded-AI SaaS your team is evaluating.

By [Stefan Efros](https://www.linkedin.com/in/stefanefros-cyberdefense/), CEO & Founder, EFROS

Updated · June 17, 2026

Vendor being scored (optional) Used only to label your result on-screen. Stays in your browser.

0 of 15 answered
- 1Data HandlingDoes the vendor process Protected Health Information (PHI) or other regulated PII?0Yes, but no DPA or BAA in place1Yes, with a generic DPA only2Yes, with a fully executed DPA and (where applicable) BAA3No — vendor processes no PHI/PII, or zero-retention mode is contractually enforced
- 2Data HandlingWhere is customer data stored and processed?0Unknown / not disclosed by vendor1Disclosed, but no US-only or US-region option available2US-region available but not the default3US-only data residency contractually enforced and documented
- 3Data HandlingIs the data retention and deletion policy clearly documented?0No documented retention policy1Retention disclosed but no deletion SLA or user-initiated deletion path2Retention disclosed with deletion SLA but no proof of deletion3Documented retention, user-initiated deletion, and attested proof of deletion
- 4Model GovernanceHas the vendor published a model card or system card for the model(s) you'll use?0No model card published1High-level marketing description only2Partial model card covering some NIST AI RMF MAP categories3Full model card aligned to NIST AI RMF MAP / ISO/IEC 42001 with eval results
- 5Model GovernanceIs bias, fairness, and harm testing documented and externally verifiable?0No testing disclosed1Self-attested testing with no methodology disclosed2Self-attested testing with methodology disclosed3Third-party audited bias/safety evaluations published
- 6Model GovernanceIs there a formal model-update notification process, including breaking-change advance notice?0No notifications — model can change silently1Changelogs only, no proactive customer notification2Proactive notifications for major versions, but no SLA on advance notice3Contractual ≥30-day advance notice for breaking changes with pinned-version option
- 7Security ControlsDoes the vendor maintain a current SOC 2 Type II report?0No SOC 2 attestation1SOC 2 Type I only, or expired Type II2Current SOC 2 Type II, narrow scope3Current SOC 2 Type II covering all in-scope services, plus ISO 27001 or FedRAMP
- 8Security ControlsDoes the vendor commission an independent penetration test at least annually?0No pen testing disclosed1Internal red-team only, no third party2Annual third-party pen test, summary letter available under NDA3Annual third-party pen test plus continuous bug bounty with public scope
- 9Security ControlsIs encryption enforced in transit AND at rest, with documented key management?0Encryption disclosed but key management opaque1TLS in transit, at-rest encryption with vendor-managed keys only2TLS 1.2+ in transit, AES-256 at rest, FIPS 140-2 validated modules3All of the above plus Customer-Managed Keys (CMK / BYOK) supported
- 10Vendor MaturityHow long has the vendor been in business operating this product line?0Less than 1 year — early stage11 to 3 years23 to 7 years3More than 7 years with continuous service
- 11Vendor MaturityIs the vendor's funding or financial position stable and publicly verifiable?0Bootstrapped or seed-only, no public financials, runway unclear1Series A-B, single recent round, runway under 18 months2Late-stage private, multiple rounds, runway over 24 months disclosed3Publicly traded or profitable with audited financials
- 12Vendor MaturityCan the vendor provide reference customers in YOUR industry at YOUR scale?0No references available, or only in adjacent industries1References in your industry but at much smaller scale2References in your industry at comparable scale3Multiple named, callable references in your industry at or above your scale
- 13Legal / ContractIs a Data Processing Agreement (DPA) available, including AI sub-processor disclosure?0No DPA offered1DPA offered, but sub-processors not disclosed2DPA with sub-processor list, but no change-notification process3DPA with full sub-processor disclosure and contractual change-notification SLA
- 14Legal / ContractWhat is the vendor's liability cap in the master agreement?0Capped at fees paid (typically Your answers stay in your browser. Nothing is submitted unless you ask for the PDF benchmark.

Score this vendor

## Why a vendor scorecard, not a vendor questionnaire

Standard vendor questionnaires (SIG Lite, CAIQ, NIST SP 800-171 assessor packets) are calibrated for traditional SaaS. They ask about hosting, access control, and incident response, but they don't catch the model-governance, training-data-lineage, and update-cadence questions that decide whether an AI vendor is safe to deploy in a regulated environment. This scorecard layers the AI-specific dimensions on top of the procurement basics so you end up with a single defensible score you can take to your CISO, GC, and executive sponsor.

It is anchored to NIST AI RMF (GOVERN, MAP, MEASURE, MANAGE), the NIST AI RMF GPAI Profile (2024) for foundation models, SOC 2 Trust Services Criteria, and ISO/IEC 42001:2023. Where vendor contracts are typical for US enterprise AI procurement (DPA, BAA, sub-processor disclosure, liability caps, termination rights), the scoring reflects the negotiating ranges we see in client engagements.

## How the five categories are weighted

All five categories carry equal weight (3 questions × 3 max points = 9 points per category, 45 points total). That is deliberate. Over-weighting any single dimension (e.g. security controls) creates blind spots in the others. A vendor with a flawless SOC 2 Type II report but no model card, no BAA, and a $50K liability cap is not actually a safe procurement, and the equal-weight scoring catches that pattern.

If your specific risk environment justifies different weighting (e.g. a clinical AI deployment should over-weight Data Handling and Model Governance), the per-category breakdown lets you re-prioritize the next steps without redoing the scorecard.

## What the risk tiers actually mean

**Low risk (36–45)** means standard procurement controls apply: add to AI inventory, document the use case in your AUP, set a 12-month review cadence. **Medium risk (25–35)**means additional safeguards are required: close every 0–1 gap with a contractual rider, layer human-in-the-loop on high-stakes outputs, and time-box the pilot. **High risk (15–24)** means a formal AI risk assessment is required before contract execution: engage legal counsel, commission an independent vendor security assessment, and document an exit plan with data-portability proof BEFORE you deploy. **Critical risk (0–14)** means do not proceed without major remediation or substitution: pause procurement, evaluate alternatives, and if the business need is real, require a formal risk-acceptance memo signed by GC and CISO.

## What this scorecard does not cover

This is a 15-question self-assessment. It is not a substitute for a formal vendor security assessment, a SOC 2 deep-dive, a training-data lineage review, or counsel-led DPA negotiation. If you score a vendor in the High or Critical tier and the business still needs the relationship, the next step is a paid assessment, not a re-scored questionnaire. The scorecard also does not evaluate your own organization's readiness to use the vendor (your AUP, your AI inventory, your monitoring); for that, run the [Free AI Risk Score](https://efros.com/tools/ai-risk-score/).

[Get a detailed vendor assessment](https://efros.com/contact/)

Related EFROS resources

## From scorecard to AI governance program

[### Free AI Risk Score Score your own organization against NIST AI RMF and Colorado SB 26-189 (amended AI law).Open→](https://efros.com/tools/ai-risk-score/) [### AI Vendor Governance Index 30 enterprise AI vendors scored across 12 governance axes.Open→](https://efros.com/research/us-ai-vendor-governance-index/) [### EFROS AI Governance service NIST AI RMF, Colorado SB 26-189, SR 11-7 operating program.Open→](https://efros.com/services/ai-governance/) [### NIST AI RMF practical guide Framework-to-operations translation with 90-day runbook.Open→](https://efros.com/resources/nist-ai-rmf-implementation-guide/) [### AI Governance for law firms ABA Formal Opinion 512 operationalized.Open→](https://efros.com/resources/ai-governance-for-law-firms/) [### Vendor assessment call Book 20 minutes to walk through a specific vendor scorecard.Open→](https://efros.com/contact/)
