Cooperative AI Institute
AI vendor risk assessment

AI vendor risk assessment for credit unions.

Credit unions need a practical way to evaluate AI vendor claims before procurement, pilot approval, or broader rollout. This guide outlines the first-pass review questions, evidence requests, risk signals, and documentation steps that help teams move from vendor demo to defensible internal review.

Use the Vendor Risk Workspace — $99 Request walkthrough

First-pass framework

Start with the risk question, not the vendor pitch.

1. Define the use case

Write down what workflow the AI tool supports, who uses it, whether members are affected, and whether outputs influence decisions.

2. Map data exposure

Identify prompts, uploaded documents, member data, employee data, transcripts, logs, retention, and subprocessors.

3. Ask for evidence

Request security documentation, AI governance practices, model limitations, auditability, incident handling, and contractual commitments.

Common red flags

Signals that an AI vendor review should slow down.

CAI workspace

Turn the review into a packet.

CAI’s Vendor Risk Workspace helps structure intake, evidence gaps, follow-up questions, risk scoring, recommended controls, and board/risk memo language.

Preview workspace Get access — $99