Tier 4: Board and market exposure controls
AI procurement standards and contractual safeguards
Procurement requirements and contract clauses that set minimum AI governance expectations, evidence access, and liability protections for AI suppliers.
Board-defensible evidence
- Standard AI procurement checklist defining required evidence (documentation, logging, monitoring, security controls, testing results) and who must approve exceptions, including legal and risk sign-off.
- Contract templates or clause libraries covering audit rights, incident notification timelines, data use restrictions, model change notice, subcontractor controls, and termination rights tied to governance failures.
- Negotiation and exception records showing where clauses were modified, who approved deviations, what compensating controls were required, and how residual risk was accepted.
- Delivery acceptance evidence showing the vendor provided required artifacts before go-live (model documentation, security attestations, evaluation results), with acceptance sign-off dates and owners.
- Post-contract monitoring evidence showing ongoing compliance with contractual governance obligations, including periodic evidence requests and documented follow-up on gaps.
Why this matters
Contracts are the enforceable layer of governance, and weak safeguards turn vendor risk into your liability.
How ready is your board on board and market exposure controls?
Twelve questions, scored across all four tiers, with your gaps named — or take the whole framework into your next meeting.