Learn
Plain-English definitions of the terms that quietly decide technology deals - what they mean, why they cost you, and how to get ahead of them before you sign.
59 terms
Acceptance criteria are the specific, testable conditions a deliverable must meet for the buyer to consider it complete and approved.
Agentic AI refers to systems that take multi-step actions toward a goal with limited human oversight, rather than answering a single prompt.
AI vendor evaluation is the process of assessing an AI/LLM provider's contractual, technical, and regulatory risk before adopting their model or platform.
Annual contract value is the recurring revenue a contract represents per year, used to compare deals of different lengths on a like-for-like basis.
An architecture decision map lays out the key technical choices in a deal, the options for each, and their cost, timeline, and lock-in trade-offs.
An auto-renewal, or evergreen, clause renews a contract automatically for another term unless you cancel within a fixed notice window.
Data portability is the ability to export your data from a vendor's system in a usable, non-proprietary format so you can move it elsewhere.
A DPA is a contract that governs how a vendor processes personal data on your behalf, defining purpose, security, sub-processing, and breach obligations.
Data residency is the requirement that data is stored and processed in a specific geographic location, often for legal or regulatory reasons.
Demoware is functionality a vendor shows in a demo that is not actually committed in the contract or proposal.
Indemnification is a contractual promise by one party to cover the other's losses from specified claims, such as IP infringement or a data breach.
ISO/IEC 42001 is the international management-system standard for artificial intelligence, giving organisations a certifiable framework for governing AI responsibly.
A master service agreement is the overarching contract setting the legal terms between a buyer and vendor, under which individual statements of work are executed.
Model deprecation is when an AI vendor retires or changes a model you depend on, forcing you to re-test and re-engineer.
An MFN clause guarantees you pricing or terms no worse than the vendor gives comparable customers.
Per-seat pricing charges a fixed fee for each named user or licence, regardless of how much each one is used.
Prompt injection is an attack that hides malicious instructions in content an AI system reads, hijacking its behaviour.
A proof of concept is a limited, time-boxed trial to validate that a vendor's solution works for the buyer's specific use case before committing.
A reference check is contacting a vendor's existing customers to verify claims about delivery, support, and hidden costs before you sign.
A renewal uplift is the percentage a vendor raises your price at each renewal.
RAG is an architecture that grounds an AI model's answers in your own retrieved documents, improving accuracy over the model's built-in knowledge.
An RFI is an early-stage procurement document that gathers high-level information from potential vendors to shape requirements and a shortlist before a formal RFP.
An RFP is a document a buyer issues to solicit structured proposals from vendors against a defined set of requirements.
An RFQ is a procurement document that asks vendors for firm pricing on a clearly defined set of goods or services, used when requirements are already fixed.
A right-to-audit clause lets you, or a third party, inspect a vendor's controls, records, or security posture during the contract.
Scope creep is the uncontrolled expansion of a project's requirements after the contract is signed, usually surfacing as change orders.
A scope package is a buyer-authored definition of exactly what a project must deliver, with testable acceptance criteria and explicit exclusions.
A security questionnaire, such as the SIG, is a standardised set of questions used to assess a vendor's security, privacy, and compliance controls during due diligence.
Service credits are pre-agreed refunds a vendor owes when it misses a service level agreement, usually as a percentage of fees.
A service level agreement is a contractual commitment to a measurable level of service, such as uptime, with a defined remedy when it's missed.
Shelfware is software a company has licensed and paid for but does not actually use.
SOC 2 is an independent audit report attesting that a vendor's controls for security, availability, and confidentiality meet defined criteria.
Sole-source procurement is buying from a single vendor without competitive bidding, usually justified by a unique capability.
A statement of work is the contractual document defining exactly what a vendor will deliver, including scope, deliverables, timeline, and acceptance criteria.
A subprocessor is a third party your vendor uses to process your data - cloud hosting, analytics, or an AI model provider, for example.
Switching cost is the total expense - financial, technical, and operational - of moving from one vendor or platform to another.
Termination for convenience is a contractual right to end an agreement without cause, on notice.
Token-based pricing charges for AI usage by the token - roughly, pieces of text - that a model processes.
Total cost of ownership is the full lifetime cost of a system - licensing, implementation, integration, change orders, and renewal uplifts - not just the quoted price.
Training-data indemnity is a vendor's promise to cover you if its model's training data triggers a copyright or intellectual-property claim.
Usage-based pricing charges for what you actually consume - API calls, storage, compute, or tokens - rather than a flat licence.
User acceptance testing is the final stage where the buyer verifies the delivered system meets the agreed acceptance criteria before sign-off and payment.
Vendor asymmetry is the structural information advantage a vendor's pre-sales team has over a buyer who evaluates that category for the first time.
A vendor interrogation kit is a structured set of questions a buyer asks a vendor to expose risk, hidden cost, and uncommitted claims before signing.
Vendor lock-in is the cost and difficulty of switching away from a supplier once you depend on their proprietary formats, integrations, or data.
Vendor risk management is the practice of identifying, assessing, and mitigating the risks a third-party vendor introduces to an organisation.
A vendor scorecard is a weighted-criteria framework for comparing vendors on evidence - capability, risk, cost, and references - rather than demo impressions.
From definition to deal
Benchside turns every term above into the questions, exclusions, and lock-in math for your specific vendor - your first project is free.