Sample approval record. Illustrative data for a fictional AI meeting assistant, not a real vendor or assessment.
See it on your vendors →
Approval record Generated 30 Jun 2026
Record ID: VG-SAMPLE-0042
Northwind Notetaker AI
AI meeting assistant · transcription & summarisation · reviewed against AI & vendor security controls
Assessment overview
Northwind Notetaker AI
AI meeting assistant (SaaS)
AI Tool Security Review
Operations Manager
Up to Confidential
Decision recorded
Overall posture
● Conditional · Proceed with conditions
1 Red · material gap 2 Amber · condition required 2 Grey · insufficient evidence

The tool is usable for its stated purpose, but vendor disclosure is incomplete. Approval is conditional on closing the data-training, residency, access-control and contract gaps below before customer conversations are processed.

AI tool profile
AI use caseReal-time meeting transcription and summary generation
Model / providerThird-party LLM (provider not disclosed)
Data categories touchedMeeting audio, transcripts, customer conversations, attendee names
Highest data classification permittedConfidential
Uses customer data to train modelsUnknown
Data stored & processed only in AustraliaUnknown
Human validation of outputsYes
Prompt-injection controlsUnknown
Output / hallucination filteringUnknown
Logs prompts & outputsUnknown
MFA enforcedUnknown
RBAC / least privilegeNo
AI-specific contract clausesNo
Next review31 Dec 2026
Findings
RedCustomer data may be used for model training with no opt-out
The vendor could not confirm whether prompts, transcripts or outputs are used to train or improve models. For a tool processing customer conversations, this is a material gap until contractually excluded.
Evidence: vendor statement only · not contractually confirmed
AmberAustralian data residency not confirmed
Storage and processing locations were not disclosed. Acceptable to proceed only with written confirmation, or with data limited to a lower classification.
Evidence: not provided
AmberAccess controls not evidenced (RBAC / MFA)
No confirmation of role-based access, least privilege, or MFA for privileged accounts. Condition: vendor to provide access-control documentation before rollout.
Evidence: vendor statement only
GreyInteraction logging and retention unconfirmed
It is unknown whether prompts/outputs are logged, how long they are retained, or whether logs are protected from tampering. Insufficient evidence to assess.
Evidence: none; clarification requested
GreyOutput safety controls not specified
No detail on controls against inaccurate or harmful output. Mitigated in practice by the human-validation step, but the vendor control itself is unevidenced.
Evidence: none
Evidence basis

Each finding records how strong its evidence is, so a vendor statement never looks like independent proof.

1StatementVendor's word
2DocumentPolicy / screenshot
3ContractClause / DPA
4AssuranceSOC 2 / ISO / test
5VerifiedConfirmed in context
Decision
Approved with conditions
Limited rollout permitted for internal meetings up to Confidential, subject to the following conditions being met before wider use.
  1. Complete a Privacy Impact Assessment before processing customer conversations.
  2. Obtain written confirmation of Australian data residency and processing locations.
  3. Add a contractual restriction preventing customer inputs from being used to train or improve the model.
  4. Vendor to provide and enforce role-based access control (RBAC) and least-privilege access.
  5. Retain human validation of AI-generated summaries before they are relied upon.
  6. Include AI-specific contract clauses covering liability, transparency and audit rights.
Approve with conditions
Head of Operations
Security Reviewer
30 Jun 2026
31 Dec 2026
6 tracked

This is an illustrative sample using fictional data to show the structure of a VendorGuard approval record. It is not a real assessment of any vendor and does not constitute legal, security or compliance advice.