All insights

Sovereignty & Data Residency

The Sovereignty Claims Matrix: Vendor Scorecard

· 10 minute read

Stop scoring adjectives. Score evidence. This matrix fits in an evaluation Excel and survives a file inspection.

Give every bidder the same matrix. Accept only written evidence. Three evaluators mark independently. Average the numeric cells. Any zero in an eligibility row is a fail. Do not let a charming demo move a zero to a one.

This is the sheet we have used in rooms where the alternative was a 40-slide argument about the meaning of sovereign. The sheet is boring. Boring is the point.

The matrix

Row012
FacilityPublic SaaS onlyIndia region of a foreign cloudInstitution / SDC / NIC / air-gap named
KeysVendor-held, no rotationVendor HSM, you can request rotationInstitution-held or institution-controlled HSM
Model pathUndisclosed or silent fallbackNamed hosted APILocal or approved host; fallback listed
TrainingVendor trains on customer dataUnclear policyContractual ban + technical isolation
TelemetryDefault foreign APMOptional, poorly documentedNo egress; logs in your SIEM
SubprocessorsNone listedWeb page onlyContract schedule with countries
Audit exportScreenshotsCSV on requestAPI / SIEM feed the DPO controls
ExitData left in backupsExport of documents onlyWeights, indexes, logs, deletion cert
ContinuityNo planPaper planRehearsed restore without vendor SaaS
Purpose controlVendor can add workflowsChange request, informalPurpose tags enforced in runtime

How to mark

  • Eligibility rows if the RFP said sovereign or on-prem: Facility, Training, Telemetry, Model path. A zero fails the bid.
  • Quality rows: the rest. Weight them in the RFP before bids open. Do not invent weights after you have seen prices.
  • Evidence: architecture signed by the bidder's CTO, a packet capture from staging, and the DPA draft. Presentations do not score.
  • Split marks. A bidder can be a 2 on facility and a 0 on exit. Do not average that into a 1 and call it fine.

Write a one-line reason under every cell. Future officers need to see why a 1 was not a 2. Memory is not an audit trail.

How to put it in the RFP

Paste the matrix as a technical form. Require the bidder to self-score and attach evidence per row. Your evaluators then mark the same form. Gaps between self-score and evaluator score are clarification items. A self-score of 2 with no artefact is a 0.

Worked marking examples

Facility 2: named SDC hall, VLAN diagram signed by the SDC lead, no default outbound. Facility 1: India region of a named hyperscaler, primary storage committed in the order form, control plane abroad. Facility 0: public SaaS, or all of the above, or we can deploy anywhere.

Training 2: contract ban plus a tenant that cannot reach the vendor's training cluster, shown on a data-flow. Training 1: contract ban, no technical isolation. Training 0: improvement or safety rights that include customer content, or silence.

Exit 2: tested export of adapters, indexes and logs, plus a deletion-certificate template that names backups. Exit 1: export of chat transcripts only. Exit 0: we will discuss at the time.

Do not average a zero

A 2 on language quality does not rescue a 0 on telemetry if telemetry is eligibility. Average only the quality rows, and only after eligibility is clean. Committees that average everything will buy a poetic chatbot that phones home.

Score one live comparison this week

Copy the matrix into a sheet today. Add a column per bidder or per incumbent plus two alternatives. Mark independently — procurement, CISO, DPO — before you talk. Average only quality rows. Eligibility zeros fail the candidate.

Require a one-line reason under every cell. A 1 without a reason will become a 2 in the consensus meeting. Reasons keep the 1 honest.

If you have no live bid, score your current stack as if it were a bidder. Incumbents fail this exercise more often than newcomers. That is useful. It tells you what to fix before you write the next RFP, or whether you should write one at all.

  1. Self-scores without artefacts are zeros.
  2. Do not mix Make in India into this matrix.
  3. Publish weights before you see prices.
  4. Keep the sheet in the file. Memory is not a scorecard.

Objections you will hear — and what to do with them

Bidders will say a 0–2 scale is crude. Crude is a feature. Ten-point scales produce 7s that mean nothing. Three numbers force a conversation about evidence.

Evaluators will want to discuss before marking. Discussion first produces a polite average. Mark first, discuss second. The sheet will be uglier and more true.

Leadership will want a single sovereignty score for a dashboard. Give them eligibility pass/fail plus a quality total. A single number will hide a telemetry zero behind a language-quality two.

Incumbents will say it is unfair to score a live system like a bid. Live systems are the ones that can leak now. Score them. If they fail, you have a remediation plan, not an insult.

Someone will add extra rows until the matrix is a novel. Ten rows is enough. More rows are how evaluators stop reading. If a concern does not fit, put it in the RFP as its own clause, not as row 24.

How this shows up in the file

A matrix nobody marks independently is a consensus fiction. Three people, marks first, talk second, reasons under every cell. Ugly sheets are true sheets. True sheets survive file inspection.

Do not average a zero on an eligibility row. That zero is the whole point of having eligibility. Language quality cannot rescue telemetry. If leadership wants one dashboard number, give them pass/fail plus a quality total. One mashed number will hide the fail.

Score the incumbent. The first time you do this you will be embarrassed in a closed room. That embarrassment is cheaper than a PAC. Keep the sheet. Update it when the stack changes.

What the next noting must contain

“The Sovereignty Claims Matrix: Vendor Scorecard” belongs in a file, not only in a search result. A P2 Procurement should be able to point at one artefact that proves “sovereign AI vendor comparison”: a packet capture, a processing schedule, a scored evaluation row, a dated notice, or a refusal rule. If the only evidence is a slide, you have a heading.

Stop scoring adjectives. Score evidence. This matrix fits in an evaluation Excel and survives a file inspection. DPDP 2023 does not define sovereign AI and does not write a blanket localisation rule for every model hop. CERT-In’s 28 April 2022 directions still set specified incident clocks and 180-day log retention in India for in-scope events. The November 2025 AI governance text is guidance, not a statute. A Proprietary Article Certificate, when it is lawful, lives in GFR Rule 166 — not Rule 161.

Write three dated sentences under C1 Sovereignty & Data Residency: what was decided, which designation owns it after the next posting order, and when it will be re-checked. Unsigned sentences are souvenirs. Dated sentences are controls.

  • Name the designation that owns “sovereign AI vendor comparison”, plus a deputy.
  • Attach one artefact a stranger can open next year.
  • Name the instrument you are actually using — Act, direction, GFR clause, GeM term, or guideline paragraph.
  • Leave unsourced percentages, GMV slides and house forecasts out of the noting.
  • Revisit when the model, the SI, the notice, the region or the posting changes.

A rehearsal you can run before go-live

Before anyone announces that “The Sovereignty Claims Matrix: Vendor Scorecard” is live, run one rehearsal on a pack you brought. Do not use live citizen rows, Aadhaar-linked tables, or a production write tool. A P2 Procurement should minute what broke when “sovereign AI vendor comparison” met a messy PDF, a transferred officer, or a refused hop.

IndiaAI compute access, NICSI application-software empanelment and a GeM catalogue entry are three different legal persons and three different clocks. Mixing them on one slide is how a file applies to the wrong portal. Open the live notice. Screenshot the date.

  1. Write the one-sentence definition of sovereign AI vendor comparison a secretary can repeat.
  2. Disable undeclared outbound paths on staging and run the demo script.
  3. Export the log you claimed you keep. If the export is empty, the claim is false.
  4. Name the owner and deputy on the same line as the revisit date.
  5. Write training and improvement rights as refused unless counsel says otherwise.
How to score “The Sovereignty Claims Matrix: Vendor Scorecard” without inventing a number.
ClaimArtefactFail if
We handle sovereign AI vendor comparisonDated export or clause extractA heading with no attachment
Compliant / sovereign / secureNamed instrument + PDF dateAn adjective
Pilot succeededHeld-out task, baseline, kill sentenceA newspaper line

If the rehearsal produces no artefact, cancel the announcement. A public URL without a stop rule is not a pilot. It is an unowned processing activity with a press note.

Questions this usually raises

Should this replace financial scoring?
No. Use it as eligibility or as a high-weight quality block. A cheap bid that fails the matrix should not reach L1 comparison.
How many evaluators?
At least three: procurement, CISO, DPO. Average after each has marked independently. A consensus meeting that starts from a blank sheet will produce a polite fiction.
Why only three scores instead of a ten-point scale?
Because 7s mean nothing. 0, 1 and 2 force a conversation about evidence. Crude is a feature. If a concern needs more nuance, write a clause. Do not add row 24.
Should we score the incumbent with the same matrix?
Yes. Live systems can leak now. If the incumbent fails, you have a remediation list rather than a speech for the PAC. Run it on yourself before you run it on bidders.

Sources