This section captures essential information about the requester and their organizational context. All fields marked as mandatory must be completed to ensure proper routing and approval workflow.
Employee ID
Full Name
Corporate Email Address
Direct Phone Number
Job Title
Department
Business Unit
Cost Center Code
Direct Manager Full Name
Direct Manager Email
Executive Sponsor Full Name
Executive Sponsor Title
Executive Sponsor Email
Project or Initiative Name
Business Priority Level
Strategic - Critical to business survival or competitive advantage
High - Significant revenue or efficiency impact
Medium - Moderate operational improvement
Low - Experimental or exploratory
Infrastructure - Internal tooling or platform capability
Estimated Annual Budget for This Tool (USD)
Desired Implementation Date
Geographic Scope of Deployment
North America
South America
Europe
Middle East
Africa
Asia-Pacific
Global
Provide comprehensive details about the Generative AI tool or LLM you wish to adopt and its intended operational use within the organization. This information is critical for technical and risk evaluation.
Tool Name
Vendor or Provider Name
Vendor Website URL
Tool Version or Model
Tool Category
Large Language Model (LLM) - Text Generation
Large Language Model (LLM) - Code Generation
Image Generation Model
Audio/Voice Generation Model
Video Generation Model
Multimodal Model
Fine-tuned Custom Model
Embedding Model
Other
Please describe the tool category in detail:
Deployment Model
Public Cloud - Vendor Managed
Private Cloud - Vendor Managed (Dedicated Instance)
On-Premises - Self Hosted
Hybrid - Combination of Models
API-Only Access
Browser-Based SaaS
Describe your on-premises infrastructure readiness and security controls:
Explain the hybrid deployment architecture and data flow between environments:
Detailed Operational Use Case Description
Specific Business Objectives and Expected Outcomes
Expected Return on Investment (ROI) or Value Proposition
Technical Integration Points
Estimated Number of Users
User Roles or Personas
Software Engineers
Data Scientists
Product Managers
Marketing Professionals
Sales Representatives
Customer Support Agents
Legal & Compliance
Finance & Accounting
Human Resources
Executive Leadership
External Contractors
Other
Expected Usage Frequency
Real-time - Continuous production use
Daily - Regular operational use
Weekly - Periodic analysis or generation
Monthly - Reporting or campaign cycles
Ad-hoc - On-demand usage
Criticality to Business Operations
Mission Critical - Business stops without it
Business Essential - Significant impact if unavailable
Important - Moderate impact, workarounds exist
Convenience - Low impact, manual alternatives available
Experimental - No operational dependency
Dependencies on Other Systems or Tools
Has this tool been evaluated in a proof-of-concept (POC) or pilot?
Describe POC results, performance metrics, and lessons learned:
Explain the rationale for skipping POC and proceeding directly to production evaluation:
This section assesses the risk exposure of proprietary, confidential, and intellectual property data when processed by the proposed AI tool. Accurate completion is mandatory for security evaluation.
Types of Data That Will Be Processed by the Tool
Customer Personal Data
Employee Personal Data
Financial Records
Strategic Plans & Roadmaps
Source Code & Algorithms
Patent Applications & IP
Trade Secrets
Vendor Contracts
Internal Communications
Log Files & Metadata
Publicly Available Data Only
Synthetic/Anonymized Data
Other
Highest Data Classification Level Involved
Public - No restrictions
Internal Use Only
Confidential - Sensitive business data
Highly Confidential - Strategic IP
Restricted - Regulatory protected
Classified - Legal privilege
Estimated Monthly Data Volume (in GB)
Data Source Systems and Locations
Will proprietary data be used to train or fine-tune the vendor's base model?
Describe the training data, methodology, and contractual protections for your IP:
Confirm that your data will only be used for inference and will not contribute to model training per vendor documentation.
Will user prompts or inputs contain proprietary information?
Provide anonymized examples of typical prompts that contain proprietary data:
Do you have concerns about IP ownership of outputs generated by this tool?
Detail your IP ownership concerns and desired contractual protections:
Will the tool process data owned by third parties (partners, customers, vendors)?
Describe third-party data types, source contracts, and consent mechanisms in place:
Risk Assessment Matrix - Rate the likelihood and impact of potential data exposure scenarios
Very Low Risk | Low Risk | Medium Risk | High Risk | Critical Risk | |
|---|---|---|---|---|---|
Accidental data leakage through model outputs | |||||
Vendor insider threat or data breach | |||||
Model inversion attack extracting training data | |||||
Regulatory violation due to cross-border data transfer | |||||
Loss of competitive advantage through IP exposure | |||||
Customer data exposure impacting trust |
Proposed Risk Mitigation Strategies and Controls
Has a Data Protection Impact Assessment (DPIA) or equivalent been completed?
Upload the completed DPIA or risk assessment document:
A DPIA may be required before final approval. Contact the Privacy Office to initiate this process.
Legal & Compliance Review Status
Not Started
In Progress
Initial Review Complete
Contract Negotiation Phase
Fully Approved
Explain the plan and timeline for initiating legal review:
Upload final legal approval documentation:
Applicable Compliance Frameworks or Regulatory Requirements
GDPR or Equivalent Data Protection Law
Industry-Specific Regulation
Financial Services Compliance
Healthcare Data Standards
Government Contracting Requirements
Cross-Border Transfer Restrictions
Consumer Protection Laws
None
This section verifies the vendor's security posture, data handling practices, and compliance with corporate data governance standards. Incomplete information may delay approval.
Vendor Security Certifications and Audits (Select All That Apply)
ISO 27001 Certified
SOC 2 Type II Audited
SOC 3 Available
FedRAMP Authorized
PCI DSS Compliant
CSA STAR Certification
Penetration Tested (Third-Party)
ISO 42001 (AI Management)
None of the Above
Unknown
Has the vendor completed our organization's security questionnaire?
Upload the completed vendor security assessment:
The vendor must complete the security questionnaire before proceeding. Contact the Information Security team to initiate this process.
Data Residency and Geographic Storage Location
Data remains in primary region only
Data may be stored in multiple approved regions
Data residency unknown or vendor refuses to specify
Data stored in vendor's global infrastructure with controls
On-premises only - no vendor cloud storage
Explain the business justification for accepting unknown data residency and associated risks:
Data Retention Period for Inputs and Outputs
30 days or less
31-90 days
91-365 days
More than 1 year
Indefinite - No automatic deletion
Retention controlled by customer policy
Describe the retention policy configuration and enforcement mechanisms:
Does the vendor guarantee data deletion upon service termination or request?
Specify the deletion timeframe and certification process:
Explain the business risk of non-guaranteed deletion and compensating controls:
Encryption in Transit Standard
TLS 1.3 or higher
TLS 1.2 with strong ciphers
TLS 1.1 or lower
Proprietary encryption
Unknown or not disclosed
Encryption at Rest Standard
AES-256 or stronger
AES-128
Proprietary algorithm
Encryption not applied
Unknown or not disclosed
Access Control Mechanisms Implemented by Vendor
Role-Based Access Control (RBAC)
Attribute-Based Access Control (ABAC)
Multi-Factor Authentication (MFA)
Single Sign-On (SSO) Integration
IP Whitelisting
API Key Management
Zero Standing Privileges
Customer-managed encryption keys
None of the Above
Primary Authentication Method
Corporate SSO (SAML/OIDC)
Corporate SSO with MFA
Vendor-managed credentials
API Keys
Token-based authentication
Biometric authentication
Does the vendor provide comprehensive audit logs of all data access and model interactions?
Describe log retention, format, and availability for SIEM integration:
Limited auditability may be a compliance risk. Discuss with Security Operations team.
Has the vendor experienced any data breaches or security incidents in the past 24 months?
Describe each incident, impact, and vendor's remediation actions:
Does the vendor use subprocessors or third-party services that will have access to your data?
List subprocessors, their functions, and their security certifications:
Is a Data Processing Agreement (DPA) or equivalent contract in place?
Upload executed DPA or relevant contract addendum:
Legal must execute a DPA before any data processing begins. This is a mandatory prerequisite.
Vendor Security Contact Email
Describe Vendor's AI Ethics and Responsible Use Policies
This final section is reserved for risk rating, approval workflow, and governance board review. The requester must complete all prior sections before submission. Incomplete requests will be returned without review.
Overall Risk Rating (as assessed by requester)
Low Risk - Public data, no IP concerns, standard SaaS
Medium Risk - Internal data, moderate IP, certified vendor
High Risk - Confidential data, significant IP, emerging vendor
Critical Risk - Highly confidential, mission critical, unproven vendor
Required Approval Matrix
Approval Authority | Name | Title | Approval Required? | Approved? | Approval Date/Time | ||
|---|---|---|---|---|---|---|---|
A | B | C | D | E | F | ||
1 | Direct Manager | Yes | |||||
2 | Business Unit Head | Yes | |||||
3 | Information Security | Yes | |||||
4 | Privacy Officer | ||||||
5 | Legal & Compliance | ||||||
6 | Procurement | Yes | |||||
7 | CISO | Yes | |||||
8 | Data Governance Board | ||||||
9 | |||||||
10 |
Recommended Approval Path Based on Risk
Fast Track - Low risk, standard tool, pre-approved vendor
Standard - Medium risk, requires InfoSec and Legal review
Enhanced - High risk, requires CISO and Data Governance Board
Executive - Critical risk, requires CISO, Board, and CEO approval
Proposed Implementation Date
Post-Implementation Review Frequency
Monthly for first quarter, then quarterly
Quarterly for first year, then annually
Bi-annually
Annually
Only upon significant change or incident
Monitoring and Oversight Requirements
Automated usage logging to SIEM
Manual monthly usage reports
Quarterly access reviews
Prompt and output sampling for compliance
Vendor security scorecard tracking
Cost and ROI tracking
Model drift and performance monitoring
Bias and fairness audits
Upload Supporting Documentation (Architecture Diagrams, Vendor Assessments, POC Results)
Additional Comments or Special Considerations
I certify that all information provided is accurate and complete to the best of my knowledge. I understand that any misrepresentation may result in immediate revocation of approval and disciplinary action.
I acknowledge that I have read and agree to comply with the organization's AI Acceptable Use Policy, Data Protection Policy, and Information Security Standards.
Requester Digital Signature
Chief Information Security Officer (CISO) Approval Signature
Data Governance Board Chair Approval Signature
To configure an element, select it on the form.