AI Responsible AI Procurement Framework Playbook
A state government CIO's office is developing a responsible AI procurement policy for all state agencies. Any AI system purchased must pass a pre-procurement assessment. The policy must address bias, privacy, security, transparency, and vendor accountability across 42 agencies and $180M in annual AI spending.
When to use this playbook
- Use this playbook when the decision looks like the situation above: A state government CIO's office is developing a responsible AI procurement policy for all state agencies.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Responsible AI Procurement Framework".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- Current state IT procurement policies
- NIST AI Risk Management Framework
- Other state AI procurement policies (3 examples)
- Agency use case inventory (42 agencies)
- State privacy law and data governance requirements
Attachments: Documents (Documents)
The Prompt
You are an AI policy specialist developing a responsible AI procurement framework for a state government. I am attaching: Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Design the pre-procurement AI risk assessment: what questions must agencies answer before purchasing any AI system? 2. Build the tiered review framework: which AI systems can agencies purchase without additional oversight (low risk), which require CIO review (medium risk), and which require a full Algorithmic Impact Assessment (high risk)? 3. Define the mandatory vendor contract requirements: what minimum transparency, bias testing, audit rights, and incident notification obligations must vendors meet? 4. Design the ongoing monitoring requirement: how do agencies report on deployed AI performance, and what triggers a post-deployment review? 5. Tell me the implementation roadmap: how to phase in requirements across 42 agencies with different technical capacity, and what the enforcement mechanism is. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- Pre-procurement AI risk assessment design
- Tiered review framework with risk thresholds
- Mandatory vendor contract requirements
- Ongoing monitoring and post-deployment review triggers
- Implementation roadmap with enforcement mechanism
Review before you act
- Validate this output against source files before relying on it: Design the pre-procurement AI risk assessment: what questions must agencies answer before purchasing any AI system?.
- Validate this output against source files before relying on it: Build the tiered review framework: which AI systems can agencies purchase without additional oversight (low risk), which require CIO review (medium risk), and which require a full Algorithmic Impact Assessment (high risk)?.
- Validate this output against source files before relying on it: Define the mandatory vendor contract requirements: what minimum transparency, bias testing, audit rights, and incident notification obligations must vendors meet?.
- Validate this output against source files before relying on it: Design the ongoing monitoring requirement: how do agencies report on deployed AI performance, and what triggers a post-deployment review?.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For Responsible AI Procurement Framework, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface pre-procurement ai risk assessment design; tiered review framework with risk thresholds; mandatory vendor contract requirements; ongoing monitoring and post-deployment review triggers. Those are comparison artifacts — they only exist if more than one model runs. Reconciliation protocols exist because models disagree. The playbook's job is to make disagreement inspectable, not to hide it behind a single blended answer.
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

