PublishedGuidanceLAST REVIEWED · 30 AUG 2026
Vendor Trust
Request precise, verifiable AI system claims from vendors.
Overview
A vendor's future Trust Passport should identify the product/version and assessed deployment boundary, rather than imply that all installations or models share one result.
- Ask which data classes, providers, tools, and regions are in scope.
- Verify assessor identity, certificate class, status, and expiry.
- Recheck after material configuration changes.
- Protect private evidence while allowing procurement review.
Production checklist
- Keep credentials in a server-side secret store.
- Set explicit cost, latency, privacy, provider, and regional constraints.
- Capture route and evaluation evidence for incident review.
- Test timeouts, cancellation, fallback, and denied-policy paths before rollout.
Was this page helpful?