Vendor Due-Diligence Checklist
Pharmacy Buyer AI Guardrails, a RealActivity educational resource
Three areas decide whether a vendor can be trusted with medication-use work: data governance, model transparency, and accountability. Every unchecked box is an evidence request, not a reason to argue.
Data governance
- We know exactly where our data, including any PHI, is stored and processed.
- Retention terms are written: what is kept, for how long, and what is destroyed at exit.
- A business associate agreement (BAA) is signed where PHI is involved.
- Training and reuse rights over our data are defined, including "de-identified" reuse, with de-identification method stated.
- Access control and audit logging over our data are described and demonstrable.
Model transparency
- Validation evidence exists, with error rates by category, and we have read it, not a summary slide.
- Known limits are documented: where the tool is wrong most often and what it must not be used for.
- Human-in-the-loop points are designed in, not left to the customer to improvise.
- We know what model or provider sits underneath, and what happens when it changes.
- For certified EHR AI: the HTI-1 source attributes (31 standardized disclosures) are published and reviewed. Silence is an answer.
Accountability
- Error ownership is written: who is responsible when the tool produces a harmful or wrong output.
- Audit logs exist, we can access them, and they survive contract exit.
- An incident and error reporting path is defined, with response-time commitments.
- Exit terms cover data return, data destruction, and continuity if the vendor is acquired or fails.
- The pricing model is complete in writing, including every fee and every data right that appears after year one.
Context: FDA loosened its oversight of clinical decision support software in January 2026. The diligence burden formally shifted to buyers. This checklist is the floor, not the ceiling; your compliance, privacy, security, and legal partners may add more.