AI Vendor Risk Management: What to Ask Before You Let an AI Tool Touch Your Business Data
Every AI vendor you onboard is a new data processor with access to your most sensitive information. Here is the due diligence framework that protects your business before you sign.
The AI vendor landscape has exploded. There are now thousands of AI-powered tools targeting business users — AI writing assistants, AI customer service platforms, AI analytics tools, AI-powered CRMs, AI code generators. Each one is a new third party with access to your data, your customers' data, and potentially your regulated data.
Most SMBs evaluate AI tools based on features and price. Very few conduct meaningful vendor risk assessment before onboarding. This is how sensitive data ends up in the hands of vendors with inadequate security controls, no data processing agreements, and terms of service that permit training on your business content.
The AI Vendor Due Diligence Checklist
Data Handling and Training
- Does the vendor use customer data to train their AI models? (Get this in writing)
- Can you opt out of model training? Is opt-out the default or must you request it?
- How long is your data retained? Can you request deletion?
- Where is your data stored? (Data residency matters for GDPR and some US regulations)
- Is your data isolated from other customers' data, or is it pooled?
Security Controls
- Does the vendor have a current SOC 2 Type II report? (Request it)
- Is data encrypted in transit and at rest? What encryption standards?
- What is the vendor's vulnerability disclosure and patch management policy?
- Does the vendor conduct regular penetration testing? By whom?
- What is their incident response and breach notification process?
Contractual Protections
- Will the vendor sign a Data Processing Agreement (DPA)?
- Does the DPA include sub-processor disclosure and approval rights?
- What are the vendor's liability limits in the event of a data breach?
- Does the contract include a right to audit or request security attestations?
- What are the data return and deletion obligations at contract termination?
Regulatory Compliance
- If you handle PHI: will the vendor sign a HIPAA Business Associate Agreement (BAA)?
- If you handle EU personal data: does the vendor offer Standard Contractual Clauses (SCCs)?
- If you are subject to PCI DSS: is the vendor PCI DSS compliant or scoped out of your cardholder data environment?
- If you are pursuing SOC 2 or ISO 27001: does the vendor's security posture support your compliance obligations?
Red Flags That Should Stop an AI Vendor Evaluation
- No SOC 2 report and no timeline for obtaining one
- Terms of service that grant broad rights to use customer data for model improvement with no opt-out
- Refusal to sign a DPA or BAA when your data requires one
- No clear answer on data residency or sub-processor list
- Security questionnaire responses that are vague or reference outdated assessments
- No dedicated security contact or security documentation portal
Building an AI Vendor Registry
As you onboard AI tools, maintain a vendor registry that tracks: the tool name and vendor, the data it accesses, the DPA status, the last security review date, and the business owner responsible for the relationship. This registry becomes essential when you need to respond to a data subject request, a regulatory inquiry, or a security incident involving a third party.
Infinity Network Support Team
Managed IT & Cybersecurity Specialists
Serving small and mid-sized businesses in Miami & South Florida with managed IT support, cybersecurity, and compliance services.
The AI Governance Playbook
How to adopt AI safely in 2026 — free guide for South Florida businesses.
Have Questions? We're Here to Help.
Our team of South Florida IT specialists is ready to answer your questions and help protect your business.