The AI Agent Vendor Assessment Pack

25 questions to ask any vendor deploying AI agents in your workflow. Free, no signup. Mapped to ISO/IEC 42001 themes, the SIG and CAIQ AI modules, and NIST agent guidance. Mapping indicates topic coverage, not compliance.

Want a filled example of the Evidence Pack customers receive? Open any of our six site agents on the Trust index — each has a redacted example pack.

Section A - Identity and accountability

Mapped to ISO/IEC 42001 governance and oversight themes
  1. Who is the named accountable human for this agent, and what is their role?
  2. Who owns and operates the agent, and who has authority to change its behaviour?
  3. Which model providers and frameworks does it run on, and how are versions tracked?
  4. What is its deployment status (development, pilot, production) and change history?

Section B - Scope and authority

Mapped to SIG and CAIQ AI module scope and data themes
  1. What specific use case is the agent deployed for? Treat "general purpose" as a red flag.
  2. What actions is it explicitly allowed to take?
  3. What actions is it explicitly prohibited from taking, and how are prohibitions enforced rather than just documented?
  4. What happens when it attempts an action outside its declared scope?
  5. How is out-of-scope or undeclared tool use detected and recorded?

Section C - Data access

Mapped to SIG and CAIQ AI module scope and data themes
  1. What categories of data can the agent read, and from which systems?
  2. Can it write to or change business systems? Which ones, under what controls?
  3. Does it send external communications? Under what approval rules?
  4. What activity data is retained, where, and is it content or metadata only?

Section D - Human oversight

Mapped to ISO/IEC 42001 governance and oversight themes
  1. Where is a human required in the loop, and is each approval captured as a record?
  2. What can the agent do fully autonomously, and what spending or volume caps apply?
  3. How quickly can it be paused or killed, by whom, and is that action itself logged?
  4. How are its instructions versioned, and who approves changes?

Section E - Evidence and reconstruction

Mapped to NIST agent guidance on audit trails and incident response
  1. Can the vendor produce a chronological, tamper-evident record of the agent's material actions?
  2. How is that record protected from after-the-fact editing?
  3. What evidence level backs each record: self-reported, workflow-observed, or confirmed by the target system?
  4. If an action is disputed, can the vendor reconstruct what the agent accessed, decided and did, and how long does that take?
  5. Can you, the buyer, get ongoing review access to the evidence rather than a one-off report?

Section F - Incidents and failure

Mapped to NIST agent guidance on audit trails and incident response
  1. What is the process when the agent acts outside scope, and has it ever fired? Ask to see the record.
  2. How is instruction-bearing content reaching the agent handled, and can the vendor show an injection test?
  3. What happens to the agent's work and its evidence if the engagement or the vendor's product ends?

Framework references indicate topical mapping between this evidence trail and themes in the named frameworks. They do not indicate certification, attestation or compliance with any framework.

How vendors can answer: any format works. A structured evidence trail with declared scope, action receipts and honest evidence levels answers most of these questions in one link. That is what a proof room is.