Vendor Assessment

Evaluation criteria for AI vendors and embedded platform features in advancement operations.

Vendor and supply chain assessment

Most advancement AI arrives embedded in existing platforms. CRM vendors ship scoring, recommendation, and content generation features in product updates, often enabled by default or by admin configuration. These embedded features require the same governance assessment as standalone tools.

Model and data

  • What data does the model train on? Your institution's data only, aggregated anonymized data from multiple clients, or a pre-trained foundation model?
  • If training on aggregated data: is your institution's data included in training sets available to other clients? Can you opt out?
  • Where is data processed and stored? What is the data residency (country, region, cloud provider)?
  • Does the vendor retain prompts, inputs, or outputs? For how long? Under what terms?
  • What is the model's retraining cadence? Are you notified when the model changes?
  • Is the model validated against advancement-specific outcomes (giving, engagement, retention), or is it a general-purpose model applied to your data?

Transparency and explainability

  • Can the vendor explain how the model produces its outputs at a level sufficient for your governance committee to evaluate?
  • Are feature importances or model explanations available for individual predictions (e.g., which factors drove a prospect's score)?
  • Can you audit the model's performance on your own data? Does the vendor provide performance metrics specific to your instance?
  • Does the vendor publish model cards or equivalent documentation?
  • For generative AI: does the vendor provide content provenance or attribution for generated outputs?

Bias and fairness

  • Has the vendor tested for demographic bias in model outputs? Can they share the methodology and results?
  • Are protected class attributes (race, gender, age, religion, disability status) used as model inputs? If so, what safeguards are in place?
  • Can you test the model's outputs for disparate impact on subsets of your own constituent base?
  • Does the vendor provide tools for fairness evaluation, or must you build your own?

Security and compliance

  • What certifications does the AI service hold (SOC 2 Type II, ISO 27001, FedRAMP)?
  • Is AI processing covered under your existing data processing agreement, or does it require a separate AI-specific addendum?
  • Has the vendor completed a HECVAT assessment? HECVAT 4 (released February 2025) includes a dedicated AI/ML module with 32 questions covering generative AI practices, training data provenance, and output transparency.
  • How does the vendor handle AI-specific security threats (prompt injection, data poisoning, model extraction, adversarial inputs)?
  • Does the vendor's data masking or PII redaction cover advancement-specific sensitive fields (giving amounts, bequest intentions, wealth estimates)?
  • What is the vendor's incident notification timeline for AI-specific events (model errors, data exposure through model outputs)?

Contract terms

  • Do you retain ownership of your data and outputs derived from it?
  • Can you export model outputs (scores, segments, predictions) in a portable format?
  • What happens to your data and trained models on contract termination?
  • Does the contract address AI-specific liability (harm from biased outputs, regulatory exposure from automated decisions)?
  • Does the contract include audit rights for AI processing?
  • Are there restrictions on using AI outputs outside the vendor's platform?

Embedded AI feature governance

CRM vendors release AI features in product updates. These features may be enabled by default or available for admin activation. Governance controls for embedded features:

  • Subscribe to vendor release notes and flag AI-related changes for committee review at each quarterly meeting.
  • Maintain a list of AI features enabled in your CRM instance. Review admin settings to identify features that may have been activated without formal approval.
  • When a new AI feature is released by your CRM vendor, run the risk classification assessment before enabling it.
  • Document which AI features are intentionally disabled and the rationale for keeping them off.

Need help implementing AI governance for your advancement program?

Start a conversation