AI Vendor Evaluation Scorecard.
Stop evaluating vendors by demo quality. Rate your two shortlisted vendors across 9 due-diligence dimensions and see which one wins, and where each carries hidden risk.
Listen to this briefing
Vetting AI Vendors Beyond the Demo
Vendor A
–
out of 100
Vendor B
–
out of 100
This is a self-assessment built from the ratings you enter, not independent testing or verification of either vendor. It is not procurement, contractual, or legal advice, and the recommended steps above are a starting point for your own due diligence, not a substitute for it. Your ratings stay in your browser and are not sent to Terence Kok or reviewed by anyone.
The criteria that separate a good vendor choice from a costly mistake.
Integration, TCO & Speed
- Integration Fit is the hidden multiplier on every other cost. A technically capable product that requires 12 months of integration work to deploy is not a low-cost option.
- TCO is often understated in vendor proposals. As a directional pattern, not a measured statistic, licensing commonly runs 40–60% of all-in cost. The rest is implementation labour, training, maintenance, and governance overhead.
- Time to Deploy matters because value not yet realised is value lost. A 6-month deployment difference has compounding ROI consequences.
Governance, Portability & Risk
- Data Governance scores below 3 are a legal and reputational risk. PDPA, GDPR, and sector-specific regulations make vendor data practices a board-level concern.
- Portability scores below 3 mean you are signing a long-term contract even if the paper says 12 months. Data lock-in, API dependencies, and proprietary formats all compound over time.
Support & Proof of Value
- Support Quality is where most vendor relationships fail post-signature. The account executive who closed the deal is rarely the person handling your production incidents at 2am.
- Proof of Value at score 1–2 means you are being asked to be a reference customer, not joining one. Ask for 3 references from organisations similar to yours before scoring above 3.
Tool-Ecosystem Security & Pricing Risk
- Tool-Ecosystem Security covers how the vendor secures the MCP servers, plugins, and third-party connectors its agents call. Unauthenticated MCP implementations produced real, documented vulnerabilities in 2026: ask specifically how tool connections are authenticated and scoped.
- Pricing Model Risk separates predictable pricing from token or credit-based models where the same usage pattern can produce wildly different invoices month to month. Ask for a worst-case cost scenario at your expected volume.

Vendor demos are designed to hide exactly the things this scorecard forces into the open, total cost of ownership, portability, what support looks like once the sales rep is gone. Rate two vendors side by side across seven dimensions and you'll usually find the gap isn't where you expected. I added the risk flags after seeing too many contracts signed on a strong demo and a weak governance answer nobody pushed back on. Use it before the meeting where you're expected to have a recommendation.
