S5 · Solution for organisations

Vendor Intake and AI Diligence with a method

Every new AI tool request gets the same method: the AI Vendor Risk Framework (AVRF)™ questionnaire run with the requester, the answers scored, and a gate decision drafted for a person to sign.

Status · Proposed

The problem it answers

Every new AI tool request lands on procurement with no method, and iSystematic's Vendor Intake and AI Diligence solution gives each request the same one.

What it does

It runs the AVRF questionnaire with the requester, scores the answers, and drafts the gate decision and the residual-risk line for a person to sign.

An answer without evidence is recorded as the vendor's assertion, not as a fact. The scoring step cannot give a score the evidence does not support, so unsupported answers go back to the requester.

It recommends and a person decides: the final decision and its signature stay with your procurement or risk lead.

For a federally regulated financial institution, OSFI Guideline E-23 takes effect on 1 May 2027, counts AI and machine learning methods within its definition of a model, and refers third-party models to Guideline B-10. Each completed questionnaire becomes a vendor record the model risk team can read in that work; whether a tool meets E-23 remains the institution's own determination.

Built from

It is built from one catalogue workflow, one catalogue pattern and the AVRF questionnaire.

IdNameWhat it brings
W20Research to Decision MemoSeparates evidence, assumptions, conflicting claims and unknowns; the final decision stays with a person
P05Research, Compare, DecidePrimary sources inspected and compared before a decision memo is drafted
AVRFAI Vendor Risk Framework questionnaireThe deposited due-diligence questionnaire the solution runs with each requester

What it is built on

Four parts of the framework corpus decide how diligence runs, and each leaves a record the client keeps.

FrameworkIn this solutionClient keeps
AI Vendor Risk Framework (AVRF)™The five stages (classify, diligence, contract, monitor, exit) run with the requester; an answer without evidence is recorded as the vendor's assertionCompleted questionnaire with evidence; vendor record
PEVGThe scoring step cannot assert a score the evidence does not support; the verifier sends unsupported answers backScored questionnaire with reasons
Five-Gate Deployment Model™Vendor clearance feeds G1; contract terms obtained feed G4Gate records
Sharia AI Compliance Framework (SACF)™, where it appliesA Sharia vendor screening branch at diligenceScreening attestation

Five parts apply to every build and are not repeated here: decision rights, the five gate records, a BOE Declaration per control, a vendor assessment for every vendor, and incident response. How we build sets out all of them.

About the Sharia AI Compliance Framework (SACF)™: No Sharia Supervisory Board has reviewed or endorsed this framework. It is an engineering proposal offered for scholarly and institutional review.

The evidence it leaves behind

Every request leaves records the client keeps.

  • A scored questionnaire and a decision record
  • The completed questionnaire with its evidence
  • A vendor record for each tool
  • Gate records
  • A screening attestation, where a Sharia board binds

Typical buyer

The typical buyer is a procurement, risk or IT team.

Status

Proposed, as of 9 October 2026. A solution becomes Piloting or Released only after a documented pilot, and no result is shown for it before then.

How to start

There are three ways in. Run the AVRF yourself: the specification is deposited and free to read. Run it with us: a six-week Pilot of this solution on your next AI tool requests. Or govern the whole programme through AI Governance Readiness.

A federally regulated financial institution starts with the E-23 Readiness Review, or runs it in parallel; OSFI E-23 on nabeelkhan.com explains the guideline.

Conformance is self-declared; no regulator endorses this work.

Start

Talk to us

Tell us the task and who owns it, and we will suggest one first step.