The Entry Point · Fixed Scope · Fixed Price

One AI vendor. Torn down. $2,500.

The AI Vendor Risk Snapshot is a fixed-scope governance teardown of one AI vendor already in your stack — or one you're about to sign. You get a written risk memo and an executive readout call. Findings in days, not quarters. Priced so a manager can approve it without a procurement committee.

30-minute scoping call first. If the Snapshot isn't the right fit, you'll know in that call.

What You Get

The Deliverables.

Two artifacts, one decision-ready picture of a single vendor relationship.

Deliverable 01

The Written Risk Memo

A teardown memo your procurement, legal, and security stakeholders can all act on:

  • What the vendor's AI actually does with your data — mapped in plain language
  • Training rights, retention, and subprocessor exposure — what the terms really say
  • Contract gap analysis — what your current MSA/DPA covers, and what it doesn't
  • Risk tier assignment with rationale — where this vendor sits and why
  • The questions to ask the vendor next — specific, sequenced, and hard to dodge
  • Framework mapping — findings referenced to NIST AI RMF and EU AI Act obligations where they apply
Deliverable 02

The Executive Readout

A live working session, not a slide recital:

  • Walkthrough of findings with the stakeholders you choose
  • Prioritization — which gaps are urgent, which can wait for renewal
  • Recommended next actions your team can run without Clarevon
  • Open Q&A on the vendor, the contract, and the tier

You keep everything. The memo is written to be forwarded — to legal, to the vendor, to the board.

Who It's For

Built for the People Who Have to Answer for It.

Procurement & VMO

You're being asked to approve AI tools with a questionnaire built for SaaS. The Snapshot gives you an independent assessment you didn't have to build a program to get.

Legal & Compliance

You're reviewing AI clauses with no precedent and an EU AI Act clock running. The Snapshot translates one vendor's terms into concrete gaps and specific redline priorities.

CISO & Security

You own the risk but not the relationship. The Snapshot defines what technical evidence the vendor owes you — so your team validates the right things, not everything.

Clarevon is the governance architect, not the technical validator. The Snapshot tells you what to demand, what it means, and where it fits — deep technical validation of model security architecture stays with your security team, guided by the framework.

How It Works

Four Steps. Days, Not Quarters.

01

Scope

30-minute call

  • Pick the vendor
  • Confirm what documentation exists
  • Identify your stakeholders
02

Gather

You send, we dig

  • Contract, DPA, order forms
  • Vendor security & AI documentation
  • How the tool is actually used
03

Tear Down

The analysis

  • Data flow & training rights review
  • Contract gap analysis
  • Risk tiering with rationale
04

Read Out

Memo + live session

  • Written memo delivered
  • Executive readout call
  • Next actions, prioritized
Questions

Asked Often.

Why one vendor instead of the whole stack?

Because one vendor, done deeply, changes how your team looks at every vendor. The Snapshot is designed to produce a concrete, forwardable artifact fast — and to show you what a full program would look like before you commit to building one. Organizations that need the full picture move to the AI Vendor Readiness Assessment next.

Why $2,500?

Deliberately. The price is set so a director or senior manager can approve it inside normal spending authority — no procurement committee, no RFP, no quarter-long buying cycle. It's the fastest honest way for both of us to find out if there's a bigger engagement worth doing.

What do you need from us?

The vendor contract and DPA, any security or AI documentation the vendor has provided, and a short conversation about how the tool is used. If documentation is thin, that's a finding, not a blocker.

Does this replace a security review?

No — it directs one. The Snapshot is a governance assessment: data rights, contract terms, risk tier, accountability. Where technical evidence is required, the memo specifies exactly what your security team should demand and validate. Governance architecture and technical validation are different jobs, and the Snapshot is honest about which one it does.

What happens after the readout?

Whatever you decide. Many teams run the recommended actions themselves. Some scope a Readiness Assessment across the wider vendor portfolio. Some bring Clarevon in fractionally. There's no bundled upsell inside the Snapshot — the memo stands on its own.

What kinds of vendors qualify?

Any third party with AI in the product or the delivery: AI-native tools, SaaS platforms that added AI features mid-contract, or BPO/outsourcing vendors deploying AI inside your operations. If you're unsure whether a vendor is worth a Snapshot, that's exactly what the scoping call is for.

Pick the vendor that worries you most.

That's the one to start with. Book the scoping call — if the Snapshot isn't the right fit, you'll know in 30 minutes.

Book Your Snapshot — $2,500

Or email brittany@clarevonconsultinggroup.com