The Vendor AI Claim Rubric
Five questions, a scored rubric, a privacy checklist, the questionnaire to send, and a decision memo. For anyone who buys software.
Judge any "now with AI" pitch in fifteen minutes and write the decision down in a way that holds up.
Beer Bond holder? Sign in and it is already yours.
The situation you are in
Three vendors want fifteen minutes this week to show you the AI feature they added to something you already own. A fourth has a product that did not exist in March. Your finance lead wants to know why the software line moved. Someone on your team already signed up for a tool on a personal card because the official path was slower than their deadline, and they were right about that.
You are not an AI expert and you are not going to become one. You have a day job that this is a small part of. What you need is not expertise. It is a way to tell, quickly, whether the thing in front of you is worth buying, what it will actually cost, where your data ends up, and who is on the hook when it is wrong — and then a way to write that down so that in a year nobody has to reconstruct what you were told.
Right now the honest version of your process is probably this: the demo looks good, the price looks fine, the vendor says the right words about security, and you say yes because saying no requires a reason you do not have time to produce. That works until it does not.
What this kit is
A judging method and the paper to go with it. Eight chapters, about 11,400 words, and nine templates — one of which is a card that fits in a notebook.
The method is five questions, in a fixed order, that take about fifteen minutes and work on any product in any sector. Around them sits a scored rubric with a few hard gates, a one-page privacy checklist, a questionnaire you send before the demo, and a one-page memo format so the decision exists somewhere other than your memory.
It is opinionated where opinions help. It says an accuracy number without a test set is decoration. It says "a human reviews it" is only a control if that human has the time, the expertise, and the standing to say no. It says the default state of the next AI feature the vendor ships matters more than the one they are demoing. It says most of your answers should be no, and that a no with a reason costs less than a yes without one.
It is also short on purpose. A review process nobody can finish is a process nobody uses, and the tools you never saw are the ones that hurt you.
What is inside
- The guide. Eight chapters, about 11,400 words: what "AI-powered" usually means and the four kinds of claim; the five questions; data and where it actually goes; accuracy and who is accountable when it is wrong; control, logs, and exit; cost in three layers; running both the fifteen-minute review and the deeper one; and keeping a register you re-check annually.
- In the meeting. The Five Questions card — one page, the thing you will actually carry — and a demo script with the minute-by-minute, the three things to ask to see in the product, and what to leave out of the room.
- Deciding. The scored vendor rubric, weighted across data, accuracy and accountability, control and exit, cost, and fit, with pass/fail gates that a great demo cannot outscore. Plus the one-page data-privacy checklist and the vendor questionnaire you send three days before the meeting.
- On the record. A one-page decision memo format, with a filled invented example, and a tool register with the eleven columns worth keeping and four cheap ways to find the tools nobody told you about.
- Staying honest. An annual re-check checklist to run sixty days before each renewal, and a red-flags list: four that end a conversation, fourteen that make it longer.
- START-HERE. Which page to open fifteen minutes before the call, and what to read if you have an hour, a day, or a week.
Nine templates in all. Every one uses [BRACKETED PLACEHOLDERS], carries a "How to adapt" note, and is plain markdown, so it pastes into a document, a wiki, or a ticket without fighting formatting.
Who wrote it and why he can
Wayne Bridges, a public-sector solutions engineer who builds and runs AI agent systems daily.
That second half is the part that matters here. The questions in this kit about where data goes, what "we don't train on your content" leaves out, how a wrapper behaves when the model underneath it changes, and what an invoice does when adoption goes well are not questions collected from articles. They come from operating these systems, paying for them, and watching them fail in specific, unglamorous ways.
The first half matters too. He has spent years on the buying side of the table in organizations that have a purchasing office, an audit trail, and a board or council that asks questions — and where the honest answer is often "we have to decide this month with incomplete information." This kit is built for that meeting, not for a research budget.
He is not a lawyer, and every chapter that touches law, policy, HR, or procurement says so at the top.
What this is not
- Not legal or procurement advice. It tells you what to ask. Your counsel and purchasing office tell you what you may do.
- Not a product recommendation. No vendors are named anywhere. Examples are invented and labelled as such.
- Not a security review. It does not replace a SOC 2 report, a penetration test, or whatever your organization requires. It sits in front of them and tells you whether it is worth asking for them.
- Not sector-specific. The structure of the question is the same everywhere; the law on top of it is not. Where your sector adds a layer, the guide says so and points at it.
- Not anti-AI. The author builds with these tools every day. The point is to buy the good ones on terms you understand.
Who should not buy this
- Organizations with a mature vendor risk program, a security questionnaire process, and a privacy officer who already reviews every AI feature. You have this covered; you might still want the five-questions card for the managers who get pitched directly.
- Anyone looking for a list of approved tools or a vendor comparison. That list is yours to build, and the rubric is how.
- Anyone who wants the sector's policy language — board policy, council resolutions, staff acceptable use. That is what the sector kits are for. This is the judging method underneath them.
- Anyone hoping a rubric will settle an argument that is actually about something else. If leadership has already decided, the honest move is a memo saying so, not a score.
If you approve software and you are tired of nodding through AI pitches you cannot evaluate: read the five questions, take them to your next demo, and end that call on time.
- Anyone who approves software at a school, a city, a nonprofit, or a small company, usually as one of six things they are responsible for that week.
- IT and procurement staff who get three AI pitches a week and need a repeatable answer that is faster than a meeting and better than a shrug.
- Managers whose team asks "can we use this?" and who have ninety seconds, no budget authority, and no desire to become an AI expert first.
- The five questions that expose a weak AI claim, with what a good answer sounds like, what a bad one sounds like, and the follow-up that settles it.
- A scored, weighted rubric with pass/fail gates covering data, accuracy, control, cost, and exit, so two vendors can be compared on something other than the demo.
- A data-privacy checklist that fits on one page and gets used, because a two-page checklist does not.
- A vendor questionnaire you send before the demo, which filters out the vendors who cannot answer it before they take a room's worth of calendar time.
- A one-page decision memo format so every yes and every no is on file, with the reason, the scope, the owner, and the re-check date.
- 8-chapter guide, about 11,400 words, from what "AI-powered" actually means through the annual re-check
- 9 editable templates in plain markdown: the Five Questions card, the scored vendor rubric, data-privacy checklist, vendor questionnaire, demo script, decision memo, tool register, annual re-check checklist, red-flags list
- In the meeting: the Five Questions card, one page, and a demo script with the minute-by-minute and what to leave out of the room
- Deciding: the scored vendor rubric with weighting and pass/fail gates, plus a one-page data-privacy checklist
- Before the meeting: a vendor questionnaire you send three days ahead, which filters more than anything else in the kit
- On the record: a one-page decision memo format and a tool register you can keep in a spreadsheet or a markdown file
- Staying honest: an annual re-check checklist and a red-flags list — four that end a conversation, fourteen that make it longer
- The Five Questions, the free one-page piece, included in the kit as well
- A START-HERE map that tells you which page to open fifteen minutes before the call
8 chapters · 9 template files · read on the site or download the zip.
The Five Questions
One page you can take into any AI pitch. Free, no login.
- What "AI-powered" usually means, and the four kinds of claim — The phrase on the slide covers four very different products with four very different risk profiles. Learning to tell them apart in the first five minutes of a demo is most of the job.
- The five questions — Five questions that expose a weak AI claim in about fifteen minutes, with what a good answer sounds like, what a bad one sounds like, and the follow-up that settles it.
- Data: where it goes, who trains on it, how it leaves — The full path your data takes through an AI feature, the six commitments worth having in writing, and how to read the phrase "we don't train on your data" so it means what you think it means.
- Accuracy and accountability: who is responsible when it is wrong — How to read an accuracy claim, why the cost of a wrong answer is asymmetric, and how to write the one sentence that decides whether a tool is safe to deploy.
- Control and exit: switches, logs, and getting out — The three switches every AI feature should have, the log that lets you prove what happened, and how to find out what leaving costs before you are trying to leave.
- Cost: the seat, the usage, the surprise — AI pricing has three layers and the third one is where budgets break. How to model three times your expected use, spot the renewal jump early, and put a real total on the memo.
- Running the fifteen-minute review and the deeper one — Two review depths, when each applies, a minute-by-minute script for the fast one, what to say and not say in the vendor meeting, and how to write the decision down the same day.
- Keeping a register and re-checking annually — The one-file list of every AI tool you have approved, how to find the ones nobody told you about, what triggers a re-check between annual reviews, and how to retire a tool on purpose.
Is this legal or procurement advice?
No. The author is a public-sector solutions engineer, not an attorney. Your counsel owns the contract questions, your purchasing office owns how you are permitted to buy, and your sector's privacy law governs what you may put into a tool. Chapters that touch law, policy, HR, or procurement say so at the top. The kit makes you a better-prepared buyer, not a substitute for the people whose job this is.
Do I need to be technical to use it?
No. The five questions are written for someone who approves software, not someone who builds it. Nothing in the kit asks you to evaluate a model, read an architecture diagram unaided, or know what a token is before chapter 6 explains why it is on your invoice. If you can run a fifteen-minute meeting and write a paragraph, you can run this review.
Does it name specific vendors or tools?
No, deliberately. Tools change monthly and any list would be wrong by the time you read it. The rubric for judging them does not change. Worked examples in the guide are invented and labelled as invented, for the same reason.
We already have a procurement process. Does this replace it?
No, it runs alongside it. Your process answers "are we permitted to buy this, and how." This answers "is it a good idea, and on what terms." The two meet at the decision memo, which is written to drop into whatever file your process already keeps.
How is this different from the sector policy kits?
This one is horizontal. It is the judging method for any AI claim, in any sector, and it is the piece a school district, a city department, and a twelve-person company all need identically. The K-12 and city/county kits add the sector's law, the board or council politics, and the policy language on top. If you work in one of those sectors and need adoptable policy documents, buy that kit; this one is the part of it that travels.
What is the refund policy?
30 days, no questions. If it does not save you a week, email and you get your money back.
Can I share it with my team and my purchasing office?
Yes. The license covers organization-internal use: your team, leadership, counsel, purchasing office, and staff. It does not cover reselling it, posting it publicly, or distributing it to other organizations. If a peer organization wants it, send them the link.
The Vendor AI Claim Rubric. $29, once.
Card through Stripe. Yours the moment it lands: read it here, download the zip, keep it. Or a Beer Bond: every deal and every product, for life.