# AI Vendor Content Data Check

Evaluate what an AI writing vendor receives, retains, shares, uses for training, secures, exports, and deletes before approving content workflows.

## Usage note

Use current contracts, product configuration, official documentation, and direct vendor answers. This worksheet organizes evidence but does not replace privacy, security, legal, procurement, or regulatory review.

## How to use this template

1. Define the exact service, plan, configuration, integration, region, and proposed content workflows.
2. Map all inputs, outputs, logs, people, systems, subprocessors, retention, and deletion paths.
3. Collect dated evidence from contracts, official documents, settings, tests, and direct answers.
4. Obtain privacy, security, legal, procurement, and operational decisions for the stated scope.
5. Document approved data and use cases, configure controls, monitor changes, and plan exit.

## Blank template

### Vendor and scope

- **Vendor, service, feature, and plan:** [Enter]
- **Contracting entity and region:** [Enter]
- **Account or tenant type:** [Enter]
- **Proposed use cases:** [List]
- **Proposed data classes:** [List]
- **Integrations and connected sources:** [List]
- **Assessment owners and date:** [Enter]
- **Evidence cutoff date:** [YYYY-MM-DD]

### Data flow and purpose

- **Prompt and file inputs:** [What enters?]
- **Account and usage metadata:** [What is collected?]
- **Generated output storage:** [Where/how long?]
- **Human access by vendor:** [Purpose/control]
- **Subprocessors:** [Reference/version]
- **Storage and processing locations:** [Enter or Unknown]
- **Training or model improvement:** [Default, opt-out, evidence]
- **Safety, abuse, or service monitoring:** [Purpose/retention]

### Control and lifecycle checks

- **Retention periods by data type:** [Enter]
- **Deletion behavior and backup expiry:** [Enter]
- **Export and portability:** [Enter]
- **Identity, roles, and administrator controls:** [Enter]
- **Encryption evidence:** [In transit/at rest/other]
- **Audit and activity logs:** [Availability/retention]
- **Incident notice and response:** [Contract/evidence]
- **Independent assurance:** [Scope/date, without overgeneralizing]
- **Customer configuration verified:** [Owner/date/evidence]

### Decision

- **Unresolved questions:** [List]
- **Permitted data classes:** [Exact scope]
- **Prohibited data classes:** [Exact scope]
- **Approved use cases:** [List]
- **Required controls:** [Configuration, redaction, review, logging]
- **Specialist decisions:** [Privacy/security/legal/procurement]
- **Exit and deletion plan:** [Describe]
- **Decision, owner, and expiry:** [Approve / Conditional / Reject]
- **Reassessment triggers:** [Terms, subprocessors, incident, feature, region]
