ACCESS RED TEAM — AI VENDOR REVIEW QUESTIONS Catalog: 2026-09-12.1 https://accessredteam.com/vendor-review/ Use these questions with procurement, security, operations and integration owners. These are proposed review questions, not a vendor ranking or independent verification. Keep confidential documents in your approved systems. 1. Which configured workflow and release does the evidence cover? Why it matters: A product demonstration may not match the planned configuration, site or connector. Artifact to request: Scope statement and configuration version Suggested reviewer: Release owner Capabilities: general Supporting guide: Health-system acceptance planning — https://accessredteam.com/health-systems/#acceptance 2. Who can review and correct an uncertain outcome? Why it matters: A responsible reviewer needs usable evidence, access, time and authority. Artifact to request: Oversight and escalation process Suggested reviewer: Operations Capabilities: general Supporting guide: Usable human oversight — https://accessredteam.com/research/human-oversight/#review 3. What evidence matches the current release rather than an earlier demo? Why it matters: Controls can change after a pilot. Acceptance needs versioned results for the live configuration. Artifact to request: Versioned test results and scope exclusions Suggested reviewer: Security + release owner Capabilities: general Supporting guide: Health-system acceptance planning — https://accessredteam.com/health-systems/#acceptance 4. Do legitimate patient or proxy requests still succeed after the proposed controls? Why it matters: A control that blocks everyone is not a successful patient-access design. Artifact to request: Paired allowed and denied request evidence Suggested reviewer: Patient access + security Capabilities: general Supporting guide: Patient and proxy authority — https://accessredteam.com/research/patient-proxy-authority/#checklist 5. What confirms the requested appointment milestone? Why it matters: Conversation success and the final record can describe different milestones. Artifact to request: Authoritative record and confirmation mapping Suggested reviewer: Integration Capabilities: scheduling, appointment_changes Supporting guide: Success is not completion — https://accessredteam.com/research/success-is-not-completion/#milestones 6. What happens after a timeout, retry or conflicting confirmation? Why it matters: An uncertain response can create a second effect or a contradictory patient message. Artifact to request: Uncertain-outcome test, duplicate-effect check and reconciliation owner Suggested reviewer: Integration + operations Capabilities: scheduling, appointment_changes Supporting guide: Success is not completion — https://accessredteam.com/research/success-is-not-completion/#milestones 7. What rule establishes permission for a requested change? Why it matters: Caller identification and permission for an action are separate decisions. Artifact to request: Permission rule and paired allowed/denied review evidence Suggested reviewer: Security Capabilities: appointment_changes Supporting guide: Patient and proxy authority — https://accessredteam.com/research/patient-proxy-authority/#checklist 8. When is authority checked if permission changes after the conversation starts? Why it matters: An earlier check may no longer describe a later cancellation or reschedule. Artifact to request: Timing of authorization checks and treatment of expiry or revocation Suggested reviewer: Security + integration Capabilities: appointment_changes, scheduling Supporting guide: Patient and proxy authority — https://accessredteam.com/research/patient-proxy-authority/#checklist 9. Who accepts unfinished work? Why it matters: A promise does not establish an accepted staff task. Artifact to request: Receiving team, acceptance record and closure process Suggested reviewer: Patient access Capabilities: callbacks, referrals Supporting guide: Staff handoff ownership — https://accessredteam.com/research/handoff-ownership/#states 10. What due window and escalation apply if no one calls back? Why it matters: Without a time expectation and escalation route, staff have nothing to follow. Artifact to request: Due window, after-hours path and escalation owner Suggested reviewer: Operations Capabilities: callbacks Supporting guide: Staff handoff ownership — https://accessredteam.com/research/handoff-ownership/#states 11. What recorded reason closes a referral or routed request? Why it matters: A terminal status does not explain whether the agreed outcome happened. Artifact to request: Closure reason taxonomy and sample closed items Suggested reviewer: Patient access + quality Capabilities: referrals Supporting guide: Staff handoff ownership — https://accessredteam.com/research/handoff-ownership/#states 12. Which record shows that the receiving team accepted the routed request? Why it matters: Sent-to-queue is not the same as accepted-by-owner. Artifact to request: Work-item acceptance event or equivalent operational record Suggested reviewer: Operations + integration Capabilities: referrals, callbacks Supporting guide: Staff handoff ownership — https://accessredteam.com/research/handoff-ownership/#states Create an interactive questionnaire: https://accessredteam.com/vendor-review/