A vendor claims their fraud detection model is "99% accurate" based on internal testing. Your company plans to deploy it to score $2B in annual transactions. What should the security team require BEFORE signing the contract?
A. A SOC 2 Type II report covering the vendor's development environment
B. Independent red team testing of the model against adversarial inputs
C. A performance guarantee with financial penalties for accuracy below 99%
D. Source code escrow in case the vendor goes out of business