Data exposure
What data enters the tool, where it may go, and what internal workflows become exposed.
AI PROCUREMENT · VENDOR RISK · 24–48H
Before you put an AI tool into HR, sales, support, operations, or internal data workflows, get a technical risk memo.
WHAT I LOOK AT
I review the tool, use case, data path and vendor claims so you can decide whether to buy, delay, constrain or reject the rollout.
What data enters the tool, where it may go, and what internal workflows become exposed.
Export paths, switching costs, opaque workflows and dependency on proprietary behaviour.
A practical hypothesis for whether you are acting as deployer, provider or another role.
Logging, access control, escalation paths, monitoring and failure handling.
Where people remain accountable and what decisions should not be automated blindly.
The questions to ask the vendor before signature, rollout or renewal.
WHAT YOU GET
SAMPLES
The public kit includes reproducible templates and generated examples for real-world AI vendor review scenarios.
Sample review for a broad productivity rollout touching internal documents and collaboration workflows.
https://github.com/josediegorobles/ai-vendor-risk-review-kit/blob/main/reports/microsoft-365-copilot.mdSample review for teams adopting a general-purpose AI assistant across knowledge work.
https://github.com/josediegorobles/ai-vendor-risk-review-kit/blob/main/reports/chatgpt-team.mdSample review for AI-assisted workspace search, writing and internal knowledge management.
https://github.com/josediegorobles/ai-vendor-risk-review-kit/blob/main/reports/notion-ai.mdFOR PARTNERS
I can deliver the technical memo behind the scenes for lawyers, HR consultancies, IT consultancies and trusted advisors who need a sober technical layer before their client buys or deploys an AI tool.
Law firmsHR consultanciesIT consultanciesBusiness advisors
SCOPE
This is not legal advice, not certification and not a pentest. It is a technical and procurement risk review to support a better buying or deployment decision.
Send me the tool name, intended use case and the workflow it will touch. I will tell you quickly whether a 24–48h memo makes sense.