Decision inputs
Facts that change the policy answer
Here the tool receives supplier questionnaires, evidence and unresolved issues, while someone ultimately relies on a due-diligence summary. The policy must evaluate the whole path between them.
- 1Task and owner
- Procurement risk analyst wants to summarise vendor due diligence. The policy check should identify who can approve, correct or withdraw a due-diligence summary.
- 2Information involved
- Supplier questionnaires, evidence and unresolved issues. Account for every route by which the tool receives the material, including plug-ins and linked storage.
- 3Tool and account
- An approved company account. Confirm the approved account, retention setting and any connected service before the request begins.
- 4Intended result
- The expected result is a due-diligence summary. Record the audience and the next system in the chain, rather than describing the output only as a draft.
- 5Consequence if it is wrong
- A concise result can hide absent evidence or a condition that matters to approval. That risk sets the level of review and the person who should receive an exception.
- 6Human review
- vendor risk owner should inspect, change, reject or stop the result. Their role should include checking source facts, correcting errors and refusing the proposed use.
Possible policy routes
The task name alone cannot decide it.
A published workplace policy can return different answers for the same task. These are the practical branches worth encoding.
A routine policy route may be possible
The company can consider a standard route where the exact account is approved, only the minimum confidential supplier information is used, a due-diligence summary remains within the stated purpose, and vendor risk owner reviews it before use.
Approval may be required
Send the request for approval if the account or data handling is uncertain, a concise result can hide absent evidence or a condition that matters to approval, or a due-diligence summary reaches people or systems beyond the requester’s authority.
The request may need to stop or change
The company may need a safer design when restricted information would enter an unapproved service, the output would act before vendor risk owner can intervene, or link conclusions to evidence and preserve open risks and conditions cannot be maintained. Consider less information, a controlled account or a non-AI process.
Request checklist
Questions to ask before using the tool
- 01
Which approved account will perform summarise vendor due diligence, and what external connections can it reach?
- 02
Does the proposed input include more of supplier questionnaires, evidence and unresolved issues than the result actually requires?
- 03
Will a due-diligence summary remain working material, reach another person or make another system act?
- 04
Does vendor risk owner have enough authority and time to stop the result?
- 05
Does the intended use extend beyond the region and audience covered by the current policy?
Worked request
What the employee should submit
This example supplies decision facts without pasting the underlying material into the approval record.
- requester
- procurement risk analyst
- task
- Use AI to summarise vendor due diligence.
- information
- supplier questionnaires, evidence and unresolved issues
- tool
- An approved company account
- frequency
- Recurring work
- region
- Where the work and affected people are located
- purpose
- Analyse
- impact
- Vendor approval
- review
- Complete human review
- owner
- vendor risk owner
Useful safeguards
Controls that fit this request
- ✓
Link conclusions to evidence and preserve open risks and conditions
- ✓
Reduce supplier questionnaires, evidence and unresolved issues to the smallest useful extract and remove fields unrelated to a due-diligence summary.
- ✓
Write the boundary around a due-diligence summary clearly so later users do not expand the approval by assumption.
- ✓
Preserve who accepted a due-diligence summary, when they did so and which rule version they applied.
Questions people ask
About this AI use
Is using AI to summarise vendor due diligence automatically allowed?
The task name cannot settle the answer. Apply the company’s published rules to supplier questionnaires, evidence and unresolved issues, the exact account, a due-diligence summary, its audience and the proposed review.
How specific should the workplace AI request be?
Describe a due-diligence summary, identify supplier questionnaires, evidence and unresolved issues, name the exact tool and account, explain who will receive or rely on the output, and state how vendor risk owner will review it.
Which evidence makes the answer reproducible?
Preserve who accepted a due-diligence summary, when they did so and which rule version they applied. A classification and controlled reference may be enough when copying supplier questionnaires, evidence and unresolved issues would create unnecessary risk.