Vendor Intake and AI Diligence with a method
Every new AI tool request gets the same method: the AI Vendor Risk Framework (AVRF)™ questionnaire run with the requester, the answers scored, and a gate decision drafted for a person to sign.
The problem it answers
Every new AI tool request lands on procurement with no method, and iSystematic's Vendor Intake and AI Diligence solution gives each request the same one.
What it does
It runs the AVRF questionnaire with the requester, scores the answers, and drafts the gate decision and the residual-risk line for a person to sign.
An answer without evidence is recorded as the vendor's assertion, not as a fact. The scoring step cannot give a score the evidence does not support, so unsupported answers go back to the requester.
It recommends and a person decides: the final decision and its signature stay with your procurement or risk lead.
For a regulated organisation, each completed questionnaire becomes a vendor record that its risk function can read alongside its own third-party reviews.
Built from
It is built from one catalogue workflow, one catalogue pattern and the AVRF questionnaire.
| Id | Name | What it brings |
|---|---|---|
| W20 | Research to Decision Memo | Separates evidence, assumptions, conflicting claims and unknowns; the final decision stays with a person |
| P05 | Research, Compare, Decide | Primary sources inspected and compared before a decision memo is drafted |
| AVRF | AI Vendor Risk Framework questionnaire | The deposited due-diligence questionnaire the solution runs with each requester |
What it is built on
Four parts of the framework corpus decide how diligence runs, and each leaves a record the client keeps.
| Framework | In this solution | Client keeps |
|---|---|---|
| AI Vendor Risk Framework (AVRF)™ | The five stages (classify, diligence, contract, monitor, exit) run with the requester; an answer without evidence is recorded as the vendor's assertion | Completed questionnaire with evidence; vendor record |
| PEVG | The scoring step cannot assert a score the evidence does not support; the verifier sends unsupported answers back | Scored questionnaire with reasons |
| Five-Gate Deployment Model™ | Vendor clearance feeds G1; contract terms obtained feed G4 | Gate records |
| Sharia AI Compliance Framework (SACF)™, where it applies | A Sharia vendor screening branch at diligence | Screening attestation |
Five parts apply to every build and are not repeated here: decision rights, the five gate records, a BOE Declaration per control, a vendor assessment for every vendor, and incident response. How we build sets out all of them.
About the Sharia AI Compliance Framework (SACF)™: No Sharia Supervisory Board has reviewed or endorsed this framework. It is an engineering proposal offered for scholarly and institutional review.
The evidence it leaves behind
Every request leaves records the client keeps.
- A scored questionnaire and a decision record
- The completed questionnaire with its evidence
- A vendor record for each tool
- Gate records
- A screening attestation, where a Sharia board binds
Typical buyer
The typical buyer is a procurement, risk or IT team.
Status
Proposed, as of 9 October 2026. A solution becomes Piloting or Released only after a documented pilot, and no result is shown for it before then.
How to start
There are three ways in. Run the AVRF yourself: the specification is deposited and free to read. Run it with us: a six-week Pilot of this solution on your next AI tool requests. Or govern the whole programme through AI Governance Readiness.
Organisations still choosing their first task start with the Automation Assessment.
Where to go next
Compliance and procurement
Compliance and procurement leads: run the AVRF vendor questionnaire yourself for free, run it with iSystematic, or govern the AI programme through readiness.
Policy and Regulation Watch
Policy and Regulation Watch checks the official sources you name, records each version and reports real changes, never “no change” when a source failed.
Knowledge Desk
The Knowledge Desk answers staff questions only from approved, versioned documents, cites the section, and refuses when the source is missing or retired.
Governed Agent Factory
The Governed Agent Factory is one build line for every agent: PEVG contracts, BOE-shaped evidence and five gate records, ready for second-line review.
How we build
How iSystematic builds: every solution uses the same deposited frameworks. See what each part decides, what the client keeps, and each specification's DOI.
Conformance is self-declared; no regulator endorses this work.
Talk to us
Tell us the task and who owns it, and we will suggest one first step.