# Bring these seven items to the supplier review

DataXLR8 · Practical project checklist · 2026-09-25

Original recommendations, not an official regulator template or a certification.

Use with the full guide: https://dataxlr8.ai/blog/bank-ai-vendor-due-diligence

- [ ] One defined job, named users and explicit limits on system actions.
  - Owner:
  - Evidence:
  - Open question:

- [ ] An information-flow diagram covering storage, logs and support access.
  - Owner:
  - Evidence:
  - Open question:

- [ ] The bank’s assessment of applicable requirements and arrangement materiality.
  - Owner:
  - Evidence:
  - Open question:

- [ ] Representative test cases, agreed acceptance rules and recorded failures.
  - Owner:
  - Evidence:
  - Open question:

- [ ] A demonstrated review process with clear responsibility for uncertain cases.
  - Owner:
  - Evidence:
  - Open question:

- [ ] Evidence from interruption, change, rollback and export exercises.
  - Owner:
  - Evidence:
  - Open question:

- [ ] A short decision brief with open issues, owners and approval conditions.
  - Owner:
  - Evidence:
  - Open question:

## Primary sources

- APRA: CPS 230 Operational Risk Management
  https://www.apra.gov.au/standards/cps-230
- APRA: CPS 234 Information Security
  https://www.apra.gov.au/standards/cps-234
- ASIC: REP 798: Beware the gap — governance arrangements in the face of AI innovation
  https://download.asic.gov.au/media/mtllqjo0/rep-798-published-29-october-2024.pdf
- APRA: CPG 234 Information Security
  https://www.apra.gov.au/practice-guides/cpg-234

Discuss implementation: https://dataxlr8.ai/contact?intent=business
