The Questions to Ask an AI Vendor Before You Sign Anything
Most AI procurement failures are not caused by bad tools. They are caused by nobody asking the six questions that distinguish an enterprise-grade product from a consumer product wearing a business logo. The answers exist in every serious vendor's terms; the work is asking, in writing, before signature.
This is the question set we use. Steal it.
AI vendor due diligence (n.): the structured verification, before purchase, of how an AI product handles your data, in training, retention, residency, access and audit, done against the vendor's written terms for the specific tier being bought, not the marketing page.
The six questions, and what a good answer looks like
| Question | A good answer | A red flag |
|---|---|---|
| Is our data used to train your models? | A written commitment that customer data on this tier is not used for foundation model training | Silence, ambiguity between tiers, or opt-out buried in settings |
| What is retained, and for how long? | Stated retention period with admin controls, and stricter options available on enterprise plans | No stated period, or retention framed as a support convenience |
| Where is the data processed and stored? | Named regions, contractual residency options | No answer beyond a cloud provider's name |
| Does the tool honour our existing permissions? | Grounded access inherits per-user identity; no separate copy of your data pool | A shared index or connector that flattens document permissions |
| What is logged, and can we export it? | Admin-accessible audit logs covering access and output, exportable | Logs held only by the vendor, or none |
| What happens on exit? | Deletion on termination, in writing, with timescale | Data handling on exit not addressed in the terms |
Two structural notes. First, the answers differ by tier of the same product, so ask about the tier you will actually buy. Second, ask for the terms document that contains each answer, not an assurance in a sales call. If the sentence is not in the terms, it does not exist.
The second layer: questions about the vendor, not the product
- What certifications does the vendor hold, and are they current: ISO 27001, SOC 2, and increasingly ISO/IEC 42001 for AI management systems?
- What is their subprocessor list, and will you be notified when it changes? Your data's real geography is the subprocessor list.
- What is their incident notification commitment, in hours, in writing?
- How financially durable is the vendor? An AI startup's collapse is a data event, not just a procurement inconvenience.
Running it without slowing procurement to a crawl
Proportionality matters. A marketing-copy tool touching public data needs the first two questions; a tool reading client financials needs all of them plus legal review. Grade tools by the most sensitive data class they will touch, and scale the diligence to the grade. The failure mode in most firms is not too little diligence; it is uniform diligence, which makes everything slow and important things shallow.
Keep the completed question set on file per tool. When a security-conscious client, insurer or regulator asks how the tool was assessed, the answer is a document, not a memory.
Questions people actually ask
- What is the most important AI vendor due diligence question?
- Whether your data is used for model training on the tier you are buying, answered in the vendor's written terms rather than a sales conversation. It is the question with the largest gap between tiers of the same product.
- Do enterprise tiers really differ from consumer tiers?
- Materially. Enterprise tiers of the major products carry commercial commitments on training, retention and administration that consumer tiers generally lack. The product name tells you little; the tier and its terms tell you everything.
- Should small businesses run vendor due diligence on AI tools?
- Yes, proportionately. Grade each tool by the most sensitive data it will touch and scale the questions to the grade. A one-page record per significant tool is enough to answer clients, insurers and regulators later.
- What certifications should an AI vendor hold?
- ISO 27001 or SOC 2 for information security as a baseline, with ISO/IEC 42001 emerging as the AI-management-system standard. Certification does not remove the need to check the terms for training, retention and residency on your specific tier.
- What does a subprocessor list tell you?
- Where your data actually travels. The vendor's brand is the front door; subprocessors are the building. Ask for the list and for notification when it changes.
Keep reading
- How to protect your business from AI data leakage
- The AI governance paper trail Australian firms now need
- The Operating System Era: Tech Stacking, Leadership and Governance in the New Age of Decision-Making
- Do You Need a Rebrand or a Reposition? A 7-Question Test
- How Much Does a Brand Audit Cost in Australia? (Real Numbers, Published Prices)
- Book an Audit, from $5,000