The Questions to Ask an AI Vendor Before You Sign
A practical due diligence questionnaire for small businesses buying AI software, covering data handling, subprocessors, retention, and the answers that should end a conversation.
The short answer
Due diligence on an AI vendor comes down to six areas: data handling and training use by tier, which foundation models and subprocessors sit underneath, identity and deprovisioning support, security attestations, model behavior and auditability, and contract terms including liability caps and IP indemnity.
Small businesses are buying AI software at a pace that has completely outrun their procurement process. A department head finds a tool, expenses it, connects it to the company email account, and the first time anybody in leadership hears about it is when it shows up in a renewal notice.
The fix is not a procurement bureaucracy. It is a short, standard set of questions that a vendor either answers cleanly or does not. Here are the ones that matter most, and what the answers tell you.
Data handling
Do you use customer content to train your models, and does that differ by plan tier. The tier detail matters. A vendor can honestly say they do not train on enterprise data while training on everything from their free tier, which is where your employees started.
How long do you retain prompts and outputs, and can we shorten it contractually. Thirty days for abuse monitoring is common and reasonable. Indefinite retention with no deletion path is a problem.
Where is our data stored and processed, by country. If you have client contracts with data residency terms, you have to be able to answer this downstream.
Can we delete our data on termination and what is the timeline. Get the number in writing.
Subprocessors and the model underneath
Which foundation models power the product, and who operates them. A great many AI products are a well-designed interface on top of someone else's model. Your data may therefore flow to a company you have not evaluated. Ask for the list.
Do you maintain a public subprocessor list and will you notify us of changes. This is standard practice for mature vendors and absent from most young ones.
If the underlying model provider changes, do we get notice and an exit right. Worth asking, rarely granted, and the answer tells you how the vendor thinks about your risk.
Access and identity
Do you support single sign-on, and at what tier. Charging extra for SSO is common and it is worth pushing back on, because password-based access to a tool holding your business content is a real exposure.
Do you support SCIM or automated deprovisioning. If not, know that removing an employee's access is a manual task somebody has to remember on their last day.
What administrative visibility do we get. You want to be able to answer, later, who used what and when.
Security posture
Do you have a SOC 2 Type II report, and may we see it under NDA. A Type I says they designed controls. A Type II says the controls operated over a period. The difference is meaningful.
Have you had a security incident affecting customer data in the last 24 months, and what was the disclosure. The question is not disqualifying. The dodge is.
Do you carry cyber liability insurance and at what limits. Small vendors frequently do not, and if a breach at your vendor exposes your client data, your client is coming to you.
Contract terms
Will you sign a business associate agreement. Only relevant if you are a covered entity, and absolutely determinative if you are.
What is your liability cap. Many AI vendors cap at twelve months of fees, which for a $400 a month tool means $4,800 against a breach that could cost you far more. Know the number.
Do you have an AI-specific indemnity for intellectual property claims arising from outputs. Several large vendors now offer this. Most small ones do not.
The answers that should end a conversation
Three responses we treat as walk-away signals.
A vendor who cannot tell you which foundation model they use. That means either they do not know their own stack or they do not want you to know where your data goes.
A vendor who will not put data handling terms in the contract and points you to a web page they can change unilaterally. A terms of service page is not a commitment.
A vendor who answers the training question with "your data is secure." That is not the question, and answering a different question is itself the answer.
Get the questionnaire
The full version is a 42-question workbook, organized by category, with a scoring column, a risk rating that rolls up automatically, and notes on what a good answer looks like for each item. Send it to the vendor, get it back, and you have a documented due diligence file. Your cyber insurance underwriter will ask for exactly this at renewal.
We run this evaluation for clients when the purchase is significant. For most tools, the workbook and an hour of your time is enough.
Frequently asked questions
What questions should I ask an AI vendor about security?
Ask whether customer content trains their models and whether that differs by plan tier, how long prompts and outputs are retained, which foundation models power the product and who operates them, whether they hold a SOC 2 Type II report, what their breach notification commitment is in hours, and what their liability cap is.
What answers from an AI vendor are red flags?
Three are walk-away signals: a vendor who cannot tell you which foundation model they use, a vendor who will not put data handling terms in the contract and points to a web page they can change unilaterally, and a vendor who answers the training question with your data is secure, which answers a different question.
Does the enterprise tier of an AI tool really protect our data?
Enterprise tiers generally commit contractually that inputs are not used for training, while free and consumer tiers frequently reserve that right. The tier detail matters because a vendor can honestly say they do not train on enterprise data while training on everything from the free tier, which is where your employees started.
What is a typical AI vendor liability cap?
Many cap at twelve months of fees. For a tool costing $400 a month that is $4,800 against a breach that could cost far more. Know the number before signing, and check whether the vendor carries cyber liability insurance, because small vendors frequently do not.
Related reading
- The 90-Day AI Rollout Plan for a 50-Person Business
- Writing an AI Acceptable Use Policy Your Employees Will Actually Follow
- Copilot, ChatGPT Enterprise, or Gemini: What an Arizona SMB Should Actually Buy
- What Your Data Has to Look Like Before AI Is Worth Buying
- Measuring AI ROI Without Lying to Yourself
