Two weeks (single vendor)

Nine dimensions, seven Stop Conditions

Seven documents including Board Report

How Assurance works


Assessed before dimensional scoring begins. Each is binary. Any Hard Stop triggers immediate board notification regardless of dimension scores. A Stop Condition means the relationship is structurally ungovernable in its current state. Most require renegotiation, not replacement.

  • S1 Undisclosed Training Data Use
  • S2 No Deletion Clause
  • S3 Unlimited Subprocessor Rights
  • S4 Unlawful Personal Data in AI
  • S5 Blanket AI Liability Exclusion
  • S6 No Audit Rights Over AI Outputs
  • S7 Agentic AI With No Scope Limitation

S5 is the structural default of the vendor contract market. Finding it does not indicate bad faith. It means the contract needs renegotiation.

  • D1 Data Flow Exposure — where your data actually goes
  • D2 Contractual Gap Analysis — 40-point checklist
  • D3 Deletion Incompleteness — can you actually discharge deletion obligations
  • D4 Regulatory Exposure Mapping — what you can’t demonstrate to regulators
  • D5 Privacy Misalignment — do DPAs match actual AI processing
  • D6 Executive Accountability Mapping — who approved what
  • D7 Model Change and Continuity — governing what you contracted for
  • D8 Employee AI Processing — HR and workforce AI tools
  • D9 Agentic and Autonomous AI — AI that acts on its own
  1. Board Report — up to 12 pages. Stop Condition verdicts, accountability map, immediate actions.
  2. Contract Redline Pack — clause-level redlines. GC-ready.
  3. Regulatory Exposure Matrix — what you can’t demonstrate, jurisdiction by jurisdiction.
  4. Vendor Risk Register — dimension scores, Criticality Class, Assessment Confidence.
  5. Remediation Roadmap — 30, 60, 90-day actions by role.
  6. Residual Risk Acceptance Register — decision, approver, compensating controls, review date.
  7. Insurance Alignment Memo — gap between liability and insurance tower.

Single Vendor — one vendor, all nine dimensions, all seven documents. Two weeks.

Portfolio — up to ten vendors. Four weeks. Identifies concentration risk.

Enterprise — complete AI vendor landscape. Six to eight weeks.

Retained Advisory — ongoing contract reviews and quarterly register updates.

Assurance findings are the baseline for IAIL Monitor. Monitor watches whether the conditions under which the assessment was produced remain current. Assurance findings also inform IAIL Exit when vendor relationships are terminated — the assessed position determines what the enterprise needs to verify at termination.

See what you're already carrying

Start with one vendor. Two weeks. All nine dimensions. All seven output documents.

Request a Briefing Read the White Paper