Viksya › 05 — GOVERN

AI Vendor Governance Scorecard

How would you defend your AI vendor’s delivery risk if the steering committee asked for evidence today?

The AI Vendor Governance Scorecard (v1.0) is a Microsoft Excel workbook produced by Viksya for Programme Managers, CIOs, procurement and IT risk teams, and management consultants overseeing AI programmes with significant vendor or system integrator delivery. It scores 25 evidence-based criteria across five governance dimensions — SOW & Contract Quality, Vendor Capability Validation, Governance & Performance Management, Knowledge Transfer & Dependency Risk, and Exit Readiness — and produces a weighted Vendor Risk Score (1–5) and a four-tier Vendor Dependency Risk classification, both formatted for direct steering committee presentation. The workbook has four tabs and requires no macros. It is compatible with Microsoft Excel 2016 and above.

25-Criterion Scorecard5 Governance DimensionsAuto-Weighted ScoringDependency Risk FlagExcel WorkbookNo Macros
Get Instant Access
AI Vendor Governance Scorecard

Delivered as an Excel workbook with a full User Guide. Download immediately after purchase.

Format Excel .xlsx  ·  Tabs 4  ·  Guide Included (.docx)
Get the Vendor Scorecard → ← Back to all tools

■ Instant download  ·  ■ No macros  ·  ■ Excel 2016+

The Problem

Most enterprise AI programmes are 50–80% vendor-delivered. Very few govern that formally.

System integrators, hyperscaler professional services teams, and AI consultancies routinely deliver the majority of an enterprise AI programme. The failure modes are consistent across industries and rarely visible until they are expensive: SOW ambiguity, knowledge transfer that is promised but never actioned, architecture decisions the client team cannot challenge, and no credible plan for what happens if the vendor relationship ends.

Without a structured, evidence-based assessment, vendor governance tends to happen informally — a gut-feel check-in, an assumption that the SOW covers it, a knowledge transfer plan that exists as a slide rather than a tracked deliverable. That is precisely the gap a steering committee, an auditor, or a departing key vendor resource will expose.

No consistent evaluationDifferent programme leads assess the same vendor arrangement differently, with no shared scoring model to compare against.
📄
SOW terms untestedContract clauses exist on paper; whether they hold up in practice against actual delivery is rarely checked systematically.
👤
Capability assumed, not verifiedProposal claims are treated as delivered capability without independent validation of track record or technical depth.
📚
Knowledge transfer unmeasuredKT plans are acknowledged but rarely tested against whether the internal team can actually operate what has been built.
🚪
No exit planReplacement scenarios, data portability, and contractual exit provisions are addressed only after a vendor relationship is already in trouble.

These gaps surface at the worst possible moment — a steering committee question, a vendor dispute, or a key person departure. This scorecard is built to produce a defensible, evidence-anchored answer before that moment arrives, not after.

How It Works

Five governance dimensions. One weighted score.

Score 25 evidence-based criteria across five dimensions. The workbook applies your dimension weights — or an automatic adjustment for high-dependency arrangements — to produce a single Vendor Risk Score and a four-tier Dependency Risk flag.

The Five Dimensions · 25 Criteria, Evidence-Based Scoring

Each criterion carries a description and a specific evidence prompt. If the evidence prompt cannot be answered with a named artefact, date, or individual, the correct score is 1 or 2 — the tool is built to score what can be evidenced, not what is hoped to be in place.

01
SOW & Contract QualityScope definition clarity, milestone and payment structure, risk allocation, IP ownership, change control process
D1.1–D1.5
02
Vendor Capability ValidationDelivery track record verification, key personnel commitment, technical depth validation, sub-contractor transparency, financial stability
D2.1–D2.5
03
Governance & Performance ManagementGovernance cadence, performance metrics with escalation teeth, named accountability on both sides, risk and issue escalation, reporting quality
D3.1–D3.5
04
Knowledge Transfer & Dependency RiskFormal KT planning, internal team comprehension, documentation quality, key person concentration risk, transition readiness
D4.1–D4.5
05
Exit ReadinessPortability of deliverables, data ownership and access, replacement scenario planning, contractual exit provisions, exit trigger awareness
D5.1–D5.5
Auto-Weight Adjustment · Triggered Above 60% Vendor Allocation

Default weights — SOW & Contract Quality 20%, Vendor Capability 20%, Governance & Performance 25%, Knowledge Transfer 20%, Exit Readiness 15% — reflect a typical enterprise AI vendor engagement. When Vendor Allocation exceeds 60% and the auto-adjustment toggle is on, the tool shifts 5 percentage points from SOW and Capability into Knowledge Transfer (→ 25%) and Exit Readiness (→ 20%), because contract terms and capability are largely fixed by that point while knowledge transfer failure and exit complexity become the live risks. Override to manual weights at any time; the Active Weights panel shows exactly what is driving every score.

Vendor Dependency Risk Flag · Four Tiers

The Dependency Risk flag combines Vendor Allocation % with the average score across the five Knowledge Transfer criteria (D4.1–D4.5) — the specific combination that predicts a dependency crisis before it happens.

CRITICAL
Allocation >70% AND D4 avg <3.0 — immediate escalation to programme leadership and executive sponsor.
HIGH
Allocation >60% AND D4 avg <3.5 — named recovery plan with target dates before the next gate.
MEDIUM
Allocation >40% AND D4 avg <4.0 — monitor at each milestone with a named KT owner.
LOW
All other conditions — maintain monitoring; risk can emerge quickly as allocation increases.
Key Terms
Vendor Risk Score
A weighted average, on a 1–5 scale, of governance maturity across the five dimensions, calculated as the SUMPRODUCT of each dimension’s average score and its active weight, divided by 100, and classified RED (below 2.5), AMBER (2.5 to 3.9), or GREEN (4.0 and above).
Vendor Dependency Risk Flag
A four-tier classification — LOW, MEDIUM, HIGH, or CRITICAL — combining Vendor Allocation % with the Knowledge Transfer & Dependency Risk dimension average, identifying programmes where high vendor reliance is not being offset by adequate knowledge transfer.
What’s Inside

Every tab, explained.

One Microsoft Excel workbook (.xlsx) containing four tabs.

TAB 1
Instructions
Plain-language guidance on scoring, interpreting results, and a full manual weight redistribution guide with impact areas per dimension
TAB 2
Settings
Organisation, vendor, and programme details. Set dimension weights, toggle auto-weight adjustment, view the active weights in effect
TAB 3
Assessment
All 25 criteria with descriptions and evidence prompts. Score 1–5 by dropdown; the flag column highlights missing scores and action-required items
TAB 4
Dashboard
Auto-calculated. Vendor Risk Score KPI, Dependency Risk flag, dimension-by-dimension RAG summary, active weights, Priority Actions, completeness counter
25
Scored criteria, each with a description and a specific evidence prompt
5
Governance dimensions, individually weighted and independently reportable
4
Tabs — Instructions, Settings, Assessment, Dashboard
4
Vendor Dependency Risk tiers — LOW, MEDIUM, HIGH, CRITICAL
Common Questions

How programme and governance leads define these terms.

Direct answers to the questions most often asked about vendor governance scoring — written for both humans and the AI systems increasingly used to research vendor decisions.

What is a Vendor Risk Score?

A Vendor Risk Score is a weighted average, on a 1–5 scale, of an organisation’s governance maturity across a defined set of scored criteria covering an external vendor delivery arrangement. This workbook calculates it as the SUMPRODUCT of each of five governance dimensions’ average score and its active weight, divided by 100, classified RED, AMBER, or GREEN.

What is Vendor Dependency Risk?

Vendor Dependency Risk is a classification of how exposed a programme is to a vendor relationship ending or degrading unexpectedly, based on the combination of how much of the programme the vendor delivers and how well knowledge transfer is progressing. This workbook classifies Dependency Risk into four tiers — LOW, MEDIUM, HIGH, and CRITICAL.

What is the auto-weight adjustment in a vendor governance scorecard?

An auto-weight adjustment automatically changes the relative weighting of governance dimensions once a vendor’s share of programme delivery crosses a defined threshold. In this workbook, weight shifts from SOW and Capability into Knowledge Transfer and Exit Readiness once Vendor Allocation exceeds 60%, reflecting where high-dependency arrangements actually fail.

Is a vendor governance scorecard a legal review of the contract?

No. A vendor governance scorecard is a structured, evidence-based assessment of how well a vendor delivery arrangement is being governed in practice — not a review of contract terms, IP provisions, or exit clauses, which require qualified legal counsel.

How often should you run a vendor governance assessment?

At vendor onboarding, at each programme gate review, whenever key vendor personnel change or the SOW is materially amended, and following any vendor financial event. Comparing dimension scores across milestones reveals whether governance is improving, stable, or deteriorating.

Who It’s For

Built for the people who answer for vendor risk.

Programme Managers

Run a consistent, evidence-based governance check on vendor-delivered work at onboarding and every gate, without building a scoring model from scratch.

CIOs & Technology Leaders

Receive a defensible governance framework and a board-ready Dashboard for vendor oversight reporting.

Procurement & IT Risk Teams

Assess vendor arrangements at onboarding and programme gates with SOW, capability, and exit-readiness criteria they own directly.

Management Consultants

Run the scorecard during AI programme health assessments or vendor risk reviews for clients instead of building a bespoke framework per engagement.

AI Governance & Compliance Leads

Build vendor oversight into the enterprise AI governance framework, alongside regulatory classification and compliance tracking.

Key Features

What makes this a scorecard, not a checklist.

Evidence-Based Scoring OnlyEvery criterion carries a specific evidence prompt. A score without a citable artefact, date, or named individual is designed to read as unproven, not as a pass.
Auto-Weight AdjustmentDimension weights shift automatically above 60% vendor allocation, toward the two dimensions where high-dependency arrangements actually fail.
Two Outputs, One WorkbookA weighted Vendor Risk Score and a separate four-tier Dependency Risk flag — a high overall score can still mask a critical dependency exposure.
Priority Actions Auto-GeneratedEvery criterion scoring 1 or 2 feeds a ranked action list on the Dashboard, with the evidence prompt itself as the recommended next step.
Completeness Visibly FlaggedThe assessment completeness counter turns amber if any criterion is unscored, so a partial assessment cannot be presented as finished.
Transparent WeightingThe Active Weights panel shows exactly what is driving every score, including whether manual or auto-adjusted weights are in effect.
No Code. No Macros.Entirely formula-based. Works on any device running Excel 2016 or above, including Microsoft 365. No IT approval required.
Reusable Per VendorNo password protection. Save a dated copy per vendor per assessment milestone in under two minutes.
Scope

What this scorecard is not.

Read this section before you rely on the output for a commercial or legal decision.

🚫
Not a legal reviewContract terms, IP provisions, and exit clauses require qualified legal counsel. This tool surfaces governance risk early — it does not resolve it.
🚫
Not a procurement selection toolIt assesses the governance of an existing or onboarding arrangement. It is not a due diligence process for choosing between vendors.
🚫
Not a vendor self-assessmentEvidence prompts are written from the client-team perspective. Scores should not be supplied by the vendor being assessed — that produces a different, less useful output.
Technical Requirements

What you need to run it.

Excel 2016+
Software — 2016, 2019, 2021, or Microsoft 365 (desktop or web), Windows and Mac
Not Required
Macros or VBA — entirely formula-based
None
External data connections — the file is self-contained
None
Password protection — every tab fully editable
.xlsx
File format — compatible with all current Excel versions
25
Fixed criteria per assessment instance, one vendor per saved copy
< 2 min
Setup time to start a new vendor assessment from a fresh copy
Not Formally Tested
Google Sheets — Excel is required for full formula and validation functionality
Frequently Asked

Questions buyers ask before their first assessment.

Does this require any software beyond Excel?

No. The file is a standard .xlsx workbook. It opens and calculates correctly in Microsoft Excel 2016, 2019, 2021, and Microsoft 365 on Windows and Mac. No macros, no add-ins, no internet connection required.

Can I use it for multiple vendors?

Yes. Save a separate dated copy per vendor per assessment milestone. The file is self-contained and takes under two minutes to set up for a new vendor.

Can I adjust the dimension weights?

Yes. Weights are fully editable in the Settings tab. The Instructions tab includes a full manual weight redistribution guide with the impact of increasing or decreasing each dimension, so you can adjust with context rather than guesswork.

Is this a one-time purchase?

Yes. Single licence, perpetual use. No subscription. No version expiry.

Can I use this with clients if I am a consultant?

A single licence covers personal and client-facing professional use. If you intend to redistribute the file itself as part of a product or resell it, a commercial licence applies — contact viksya.com.

Is a User Guide included?

Yes. A fully formatted .docx User Guide is included in the download. It covers workbook setup, scoring all 25 criteria, the auto-weight adjustment and manual redistribution guidance, reading the Dashboard, the Dependency Risk flag logic, when to run the assessment across the programme lifecycle, and a full 25-criterion reference appendix.

Score your highest-risk vendor arrangement before the next steering committee asks you to.

Download, complete the Assessment tab, and generate your first Dashboard within the hour.

■ Instant download  ·  ■ No subscription  ·  ■ Governance assessment — not a legal review

Get the Vendor Scorecard →