Decision Desk · Issue 10 · complete public learning edition

What to Check Before Buying an AI Tool

Decide whether one exact AI product, tier, configuration, contract, implementation plan, and exit path can meet a defined organizational need better than the current process or a nonpurchase alternative.

Learning time90 minutes
Teaching12 cumulative lessons
InstrumentEvidence + contract
DefaultDo not advance

Need → product → evidence → terms → operation → exit.

A vendor decision is only as sound as the current-process baseline, exact configuration evidence, binding documents, implementation conditions, and tested continuity plan.

01

Document the current process and alternatives

Gate
02

Freeze the exact product and configuration

Gate
03

Test claims, controls, access, and failure

Gate
04

Reconcile every binding term and total cost

Gate
05

Bound implementation and ongoing ownership

Gate
06

Prove export, deletion, exit, and continuity

Gate

Twelve cumulative lessons.

Use supplied fictional vendors only. Never enter confidential proposals, security materials, contract text, pricing, credentials, or personal data.

01
Issue 10

Start with the current process

Open

Document the existing workflow, people, volume, delays, errors, costs, workarounds, affected parties, and baseline before deciding that software is the answer.

02
Issue 10

Define the governed need

Open

State the specific outcome, authorized users, affected people, exclusions, measures, constraints, and nonpurchase alternatives. Avoid buying a category in search of a problem.

03
Issue 10

Identify the exact vendor and product

Open

Record the contracting entity, product, tier, version, region, hosting, enabled features, model providers, integrations, limits, and dependencies. Evidence for another tier or configuration does not transfer.

04
Issue 10

Test claims against real conditions

Open

Separate demonstrations, marketing, roadmaps, and certifications from current evidence. Test representative tasks, edge cases, failure behavior, accessibility, human effort, and disconfirming conditions.

05
Issue 10

Map data and model terms

Open

Trace collection, inputs, outputs, metadata, retention, deletion, location, training/reuse, model improvement, subprocessors, disclosure, legal demands, ownership, and use after termination.

06
Issue 10

Review security and operational resilience

Open

Evaluate identity, access, encryption, tenant separation, logging, vulnerability management, incidents, backups, recovery, service dependencies, change control, support, and customer responsibilities.

07
Issue 10

Evaluate accessibility and unequal impact

Open

Require product-specific evidence for keyboard, screen-reader, visual, hearing, cognitive, language, device, and accommodation access—and test with affected users rather than accepting a generic statement.

08
Issue 10

Calculate total cost and implementation burden

Open

Include licenses, usage, minimums, overages, integrations, migration, configuration, training, administration, review, support, accessibility remediation, security work, change management, and exit.

09
Issue 10

Negotiate the operating contract

Open

Align order form, terms, data terms, service levels, security exhibits, acceptable use, support, warranties, indemnity, liability, insurance, audit evidence, change notice, renewal, price protection, and termination.

10
Issue 10

Design the implementation decision

Open

Use a bounded evaluation with owners, baseline, acceptance criteria, affected-party input, data limits, support, incident paths, stop conditions, and a firewall against automatic rollout.

11
Issue 10

Prove exit, portability, and continuity

Open

Test usable export, format, completeness, deletion, verification, transition assistance, model/configuration portability, integration removal, credential revocation, replacement workflow, and operation during vendor failure.

12
Issue 10

Issue a procurement-specific disposition

Open

Do not advance, resolve gaps, run a bounded evaluation, or advance to qualified review. The dossier organizes evidence; it never selects, certifies, contracts for, or approves a vendor.

The contract—not the demo—governs.

  • the current process, governed need, baseline, owner, or affected people are unresolved
  • the exact legal entity, product, tier, configuration, model, region, or integration is unknown
  • marketing, a demo, roadmap, or generic certification substitutes for current product evidence
  • data retention, training/reuse, subprocessors, deletion, or post-termination rights remain unclear
  • security, accessibility, human fallback, support, or incident responsibilities lack product-specific evidence
  • total cost omits implementation, oversight, remediation, usage growth, or exit labor
  • binding documents conflict with sales promises or permit material unilateral change without control
  • usable export, verified deletion, transition, credential revocation, or failure continuity is unproven

AI Vendor Evidence and Contract Dossier

Use fictional vendors only. Do not enter proposals, credentials, security reports, personal data, contract text, pricing marked confidential, or other protected information.

0/30procurement gates evaluated
A strong demo is not procurement evidence.
Evaluate the exact product, tier, configuration, terms, operating conditions, total cost, and exit—not the vendor category or sales narrative.
Fictional diligence domainEvidence currentExact tier/configTerms bindingFailure testedOwner assignedExit workable
Current process and product fit
Data, privacy, and security
Accessibility and affected people
Price, implementation, and support
Contract, exit, and continuity
Bounded disposition

Restoring your local dossier…

The educational product and reusable Vendor Evidence and Contract Dossier are complete.

Real procurement still requires current vendor evidence, exact configuration testing, affected-party input, qualified functional/security/privacy/accessibility/legal/financial review, negotiated binding documents, implementation and incident readiness, tested exit and continuity, budget authority, and organizational approval.