AI prepares work
A tool sorts tickets, summarizes a call, extracts invoice fields, translates text, or drafts a reply for review.
Ask for one disclosure per workflow. Record the tool, data, output, system access, human check, limits, evidence, and change-notice owner before work begins.
This is a planning and procurement worksheet, not a legal opinion, AI audit, certification, compliance finding, or universal approval standard. Do not paste secrets, credentials, live customer records, or confidential prompts into it.
"We use AI" and "we do not use AI" are both incomplete without a named service and workflow. One part of the work may use AI while another does not.
A tool sorts tickets, summarizes a call, extracts invoice fields, translates text, or drafts a reply for review.
A tool routes a case, scores an item, updates a record, sends a message, or triggers another system.
The workflow uses a provider platform, third-party SaaS feature, model API, plugin, agent, or subcontractor tool.
Keep the provider statement, dated evidence, open question, owner, and decision together. Send sensitive evidence through an approved secure channel.
PROVIDER AI-USE DISCLOSURE WORKSHEET Provider: Service or team being reviewed: Proposal, agreement, or disclosure version: Provider disclosure owner: Buyer reviewer: Review date: Next review date: Repeat this block for each AI-assisted workflow. WORKFLOW OR TASK: SERVICE STAGE: [Input, preparation, draft, recommendation, decision support, customer communication, system action, or monitoring] CURRENT STATUS: [In use, planned, optional, pilot, not used, or unclear] TOOL OR MODEL: [Product, model, provider, and version where material and available] WHO OPERATES IT: [Provider worker, provider system, subcontractor, buyer user, or another party] PURPOSE: [What the AI does in this workflow] INPUT DATA: [Data categories used; do not paste the data itself] SENSITIVE OR RESTRICTED DATA: [Customer, employee, financial, health, legal, authentication, confidential, regulated, or none identified] DATA HANDLING: [Retention, model training or product-improvement use, processing location, and deletion terms] OUTPUT OR ACTION: [What the tool produces, recommends, sends, changes, or triggers] SYSTEM ACCESS: [Connected systems, read/write permissions, and actions available] HUMAN REVIEW: [What is checked, by whom, before which action, and using what sample or rule] PROHIBITED OR HELD ACTIONS: [What the tool or provider worker must not do without approval] FAILURE AND FALLBACK: [What happens when the tool is unavailable, uncertain, or wrong] THIRD PARTIES: [Model provider, AI vendor, subprocessor, plugin, or subcontractor involved] EVIDENCE: [Data-flow note, settings record, test summary, contract section, or dated provider statement] CHANGE NOTICE: [Which changes require notice, who receives it, and the written notice term] PROVIDER OWNER: BUYER OWNER: OPEN QUESTION OR MITIGATION: NEXT REVIEW DATE: BUYER DECISION: [Confirmed for this workflow, clarify, approve with mitigation, prohibit, not applicable, or qualified review] SERVICE-WIDE QUESTIONS 1. Are any AI-assisted workflows already used or planned for this service? 2. If none are used, who confirmed that answer and on what date? 3. Will the provider give notice before adding an AI workflow or materially changing its purpose, data use, model, third party, permissions, or review rule? 4. Can the provider deliver the service through a non-AI or reduced-AI route where required? 5. Which incident, correction, complaint, and offboarding processes cover AI-related records and access? Do not include passwords, API keys, private keys, recovery codes, live customer records, confidential prompts, or other secrets. Exchange sensitive evidence through an approved secure channel.
The full template stays visible and selectable. Nothing is uploaded or saved.
Do not ask for proprietary prompts, model weights, secrets, or exploitable system details. Ask for enough information to understand the workflow and decide what needs a specialist.
Name the task, where it sits in the service, and whether the use is live, planned, optional, or still a pilot.
Record the product, model provider, material version, and the people or systems that operate it.
List data categories, not the data itself. Separate retention, logging, model-training use, product-improvement use, deletion, and processing location.
A draft is different from an action. Record what the tool can write, send, update, score, route, or approve in the purchased service.
Replace broad claims about human oversight with a named reviewer, a clear check, and the point when review happens.
Keep the provider statement separate from contract terms, test records, settings, independent reports, and buyer observations.
Agree which changes need notice, who reviews them, and which uses are confirmed, limited, prohibited, or still unclear.
This example shows the level of detail to request. It does not prove that a workflow is safe or set a control for every service.
A first pass finds missing facts. The right owner then reviews the gaps that matter for the service, data, and decisions involved.
A familiar tool name or a general policy does not answer what happens in the service you are buying.
These sources support workflow, data, third-party, testing, oversight, and change-management questions. They do not certify this worksheet or any provider.
Share the named service, workflow disclosures, dated evidence, unresolved gaps, and proposed limits. Do not send secrets through the contact form.