Request for Clearance: Non-Standard Generative AI & Third-Party LLM Adoption

1. Requester & Business Unit Metadata

This section captures essential information about the requester and their organizational context. All fields marked as mandatory must be completed to ensure proper routing and approval workflow.

 

Employee ID

Full Name

Corporate Email Address

Direct Phone Number

Job Title

Department

Business Unit

Cost Center Code

Direct Manager Full Name

Direct Manager Email

Executive Sponsor Full Name

Executive Sponsor Title

Executive Sponsor Email

Project or Initiative Name

Business Priority Level

Estimated Annual Budget for This Tool (USD)

Desired Implementation Date

Geographic Scope of Deployment

2. Tool Description & Proposed Operational Use Case

Provide comprehensive details about the Generative AI tool or LLM you wish to adopt and its intended operational use within the organization. This information is critical for technical and risk evaluation.

 

Tool Name

Vendor or Provider Name

Vendor Website URL

Tool Version or Model

Tool Category

 

Please describe the tool category in detail:

Deployment Model

 

Describe your on-premises infrastructure readiness and security controls:

 

Explain the hybrid deployment architecture and data flow between environments:

Detailed Operational Use Case Description

Specific Business Objectives and Expected Outcomes

Expected Return on Investment (ROI) or Value Proposition

Technical Integration Points

Estimated Number of Users

User Roles or Personas

Expected Usage Frequency

Criticality to Business Operations

Dependencies on Other Systems or Tools

Has this tool been evaluated in a proof-of-concept (POC) or pilot?

 

Describe POC results, performance metrics, and lessons learned:

 

Explain the rationale for skipping POC and proceeding directly to production evaluation:

3. Proprietary Data & IP Exposure Risk Assessment

This section assesses the risk exposure of proprietary, confidential, and intellectual property data when processed by the proposed AI tool. Accurate completion is mandatory for security evaluation.

 

Types of Data That Will Be Processed by the Tool

Highest Data Classification Level Involved

Estimated Monthly Data Volume (in GB)

Data Source Systems and Locations

Will proprietary data be used to train or fine-tune the vendor's base model?

 

Describe the training data, methodology, and contractual protections for your IP:

 

Confirm that your data will only be used for inference and will not contribute to model training per vendor documentation.

Will user prompts or inputs contain proprietary information?

 

Provide anonymized examples of typical prompts that contain proprietary data:

Do you have concerns about IP ownership of outputs generated by this tool?

 

Detail your IP ownership concerns and desired contractual protections:

Will the tool process data owned by third parties (partners, customers, vendors)?

 

Describe third-party data types, source contracts, and consent mechanisms in place:

Risk Assessment Matrix - Rate the likelihood and impact of potential data exposure scenarios

Very Low Risk

Low Risk

Medium Risk

High Risk

Critical Risk

Accidental data leakage through model outputs

Vendor insider threat or data breach

Model inversion attack extracting training data

Regulatory violation due to cross-border data transfer

Loss of competitive advantage through IP exposure

Customer data exposure impacting trust

Proposed Risk Mitigation Strategies and Controls

Has a Data Protection Impact Assessment (DPIA) or equivalent been completed?

 

Upload the completed DPIA or risk assessment document:

Choose a file or drop it here
 
 

A DPIA may be required before final approval. Contact the Privacy Office to initiate this process.

Legal & Compliance Review Status

 

Explain the plan and timeline for initiating legal review:

 

Upload final legal approval documentation:

Choose a file or drop it here
 

Applicable Compliance Frameworks or Regulatory Requirements

4. Data Retention, Privacy & Vendor Security Verification

This section verifies the vendor's security posture, data handling practices, and compliance with corporate data governance standards. Incomplete information may delay approval.

 

Vendor Security Certifications and Audits (Select All That Apply)

Has the vendor completed our organization's security questionnaire?

 

Upload the completed vendor security assessment:

Choose a file or drop it here
 
 

The vendor must complete the security questionnaire before proceeding. Contact the Information Security team to initiate this process.

Data Residency and Geographic Storage Location

 

Explain the business justification for accepting unknown data residency and associated risks:

Data Retention Period for Inputs and Outputs

 

Describe the retention policy configuration and enforcement mechanisms:

Does the vendor guarantee data deletion upon service termination or request?

 

Specify the deletion timeframe and certification process:

 

Explain the business risk of non-guaranteed deletion and compensating controls:

Encryption in Transit Standard

Encryption at Rest Standard

Access Control Mechanisms Implemented by Vendor

Primary Authentication Method

Does the vendor provide comprehensive audit logs of all data access and model interactions?

 

Describe log retention, format, and availability for SIEM integration:

 

Limited auditability may be a compliance risk. Discuss with Security Operations team.

Has the vendor experienced any data breaches or security incidents in the past 24 months?

 

Describe each incident, impact, and vendor's remediation actions:

Does the vendor use subprocessors or third-party services that will have access to your data?

 

List subprocessors, their functions, and their security certifications:

Is a Data Processing Agreement (DPA) or equivalent contract in place?

 

Upload executed DPA or relevant contract addendum:

Choose a file or drop it here
 
 

Legal must execute a DPA before any data processing begins. This is a mandatory prerequisite.

Vendor Security Contact Email

Describe Vendor's AI Ethics and Responsible Use Policies

5. Chief Information Security Officer (CISO) & Data Governance Board Clearance

This final section is reserved for risk rating, approval workflow, and governance board review. The requester must complete all prior sections before submission. Incomplete requests will be returned without review.

 

Overall Risk Rating (as assessed by requester)

Required Approval Matrix

Approval Authority

Name

Title

Approval Required?

Approved?

Approval Date/Time

A
B
C
D
E
F
1
Direct Manager
 
 
Yes
 
 
2
Business Unit Head
 
 
Yes
 
 
3
Information Security
 
 
Yes
 
 
4
Privacy Officer
 
 
 
 
 
5
Legal & Compliance
 
 
 
 
 
6
Procurement
 
 
Yes
 
 
7
CISO
 
 
Yes
 
 
8
Data Governance Board
 
 
 
 
 
9
 
 
 
 
 
 
10
 
 
 
 
 
 

Recommended Approval Path Based on Risk

Proposed Implementation Date

Post-Implementation Review Frequency

Monitoring and Oversight Requirements

Upload Supporting Documentation (Architecture Diagrams, Vendor Assessments, POC Results)

Choose a file or drop it here
 

Additional Comments or Special Considerations

I certify that all information provided is accurate and complete to the best of my knowledge. I understand that any misrepresentation may result in immediate revocation of approval and disciplinary action.

I acknowledge that I have read and agree to comply with the organization's AI Acceptable Use Policy, Data Protection Policy, and Information Security Standards.

Requester Digital Signature

Chief Information Security Officer (CISO) Approval Signature

Data Governance Board Chair Approval Signature

To configure an element, select it on the form.

To add a new question or element, click the Question & Element button in the vertical toolbar on the left.