AI Vendor Due Diligence Framework Playbook
A health insurance company is evaluating three AI vendors for prior authorization decisioning. Prior auth decisions affect patient care access and are subject to CMS regulations, state insurance law, and NAIC model act guidance. The legal team has 6 weeks to complete due diligence before the board vote.
When to use this playbook
- Use this playbook when the decision looks like the situation above: A health insurance company is evaluating three AI vendors for prior authorization decisioning.
- It is a fit when you have source files in hand and need a structured, reviewable analysis — not a generic chat answer about "Vendor Due Diligence Framework".
- Do not use it as a substitute for licensed, legal, clinical, or authorized official judgment in the domain.
What you'll need
- RFP responses from the three vendors
- CMS prior authorization final rule requirements
- NAIC AI principles and model bulletin
- State-specific prior auth regulation summaries (5 states)
- Internal IT security requirements for AI vendor integration
Attachments: Documents (Documents)
The Prompt
You are an AI governance counsel conducting vendor due diligence for AI prior authorization tools at a health insurer. I am attaching: Work only from the attached source files. If a conclusion is not supported, say so. Produce: 1. Assess each vendor against CMS prior auth final rule requirements: real-time API, 72-hour urgent turnaround, 7-day standard turnaround, and denial reason transparency. 2. Identify which vendors provide explainable denial rationale in plain language that satisfies state law and NAIC guidance. 3. Evaluate the audit rights, model documentation, and independent validation provisions in each vendor's proposed contract. 4. Assess the data handling and HIPAA BAA terms: does any vendor use PHI for model training without explicit authorization? 5. Recommend the vendor selection based on regulatory compliance and governance quality, and identify the contract terms that must be negotiated before signing. Call out where independent models are likely to disagree, and list follow-up documents a reviewer should request.
What to expect
- CMS compliance scorecard by vendor
- Denial rationale explainability assessment
- Contract audit rights and model documentation comparison
- HIPAA data handling risk flags
- Vendor recommendation with required contract terms
Review before you act
- Validate this output against source files before relying on it: Assess each vendor against CMS prior auth final rule requirements: real-time API, 72-hour urgent turnaround, 7-day standard turnaround, and denial reason transparency.
- Validate this output against source files before relying on it: Identify which vendors provide explainable denial rationale in plain language that satisfies state law and NAIC guidance.
- Validate this output against source files before relying on it: Evaluate the audit rights, model documentation, and independent validation provisions in each vendor's proposed contract.
- Validate this output against source files before relying on it: Assess the data handling and HIPAA BAA terms: does any vendor use PHI for model training without explicit authorization?.
- Confirm every cited figure, date, counterparty, or requirement against the attached originals — models compress and can drop a qualifier.
- Treat disagreement between models as a review item, especially on classification, materiality, and recommended next action.
- Do not authorize an operational, clinical, legal, credit, or enforcement action solely because the models agree.
Why compare models on this
For Vendor Due Diligence Framework, running the same attachments across independent models is useful because the hard part is classification and completeness, not fluency. The workflow is already designed to surface cms compliance scorecard by vendor; denial rationale explainability assessment; contract audit rights and model documentation comparison; hipaa data handling risk flags. Those are comparison artifacts — they only exist if more than one model runs. Risk-tier assignments and 'high-risk system' calls vary with how a model reads a use-case description. Comparison exposes those classification fights before they reach an exam.
See governed multi-model AI on your own prompt
Compare GPT-5, Claude, and Gemini side by side, with human review and a decision record built in.

