AI Governance

AI Vendor Risk Management: What to Ask Before You Let an AI Tool Touch Your Business Data

Infinity Network Support TeamJune 29, 20268 min read
Back to Blog

Every AI vendor you onboard is a new data processor with access to your most sensitive information. Here is the due diligence framework that protects your business before you sign.

The AI vendor landscape has exploded. There are now thousands of AI-powered tools targeting business users — AI writing assistants, AI customer service platforms, AI analytics tools, AI-powered CRMs, AI code generators. Each one is a new third party with access to your data, your customers' data, and potentially your regulated data.

Most SMBs evaluate AI tools based on features and price. Very few conduct meaningful vendor risk assessment before onboarding. This is how sensitive data ends up in the hands of vendors with inadequate security controls, no data processing agreements, and terms of service that permit training on your business content.

The AI Vendor Due Diligence Checklist

Data Handling and Training

  • Does the vendor use customer data to train their AI models? (Get this in writing)
  • Can you opt out of model training? Is opt-out the default or must you request it?
  • How long is your data retained? Can you request deletion?
  • Where is your data stored? (Data residency matters for GDPR and some US regulations)
  • Is your data isolated from other customers' data, or is it pooled?

Security Controls

  • Does the vendor have a current SOC 2 Type II report? (Request it)
  • Is data encrypted in transit and at rest? What encryption standards?
  • What is the vendor's vulnerability disclosure and patch management policy?
  • Does the vendor conduct regular penetration testing? By whom?
  • What is their incident response and breach notification process?

Contractual Protections

  • Will the vendor sign a Data Processing Agreement (DPA)?
  • Does the DPA include sub-processor disclosure and approval rights?
  • What are the vendor's liability limits in the event of a data breach?
  • Does the contract include a right to audit or request security attestations?
  • What are the data return and deletion obligations at contract termination?

Regulatory Compliance

  • If you handle PHI: will the vendor sign a HIPAA Business Associate Agreement (BAA)?
  • If you handle EU personal data: does the vendor offer Standard Contractual Clauses (SCCs)?
  • If you are subject to PCI DSS: is the vendor PCI DSS compliant or scoped out of your cardholder data environment?
  • If you are pursuing SOC 2 or ISO 27001: does the vendor's security posture support your compliance obligations?

Red Flags That Should Stop an AI Vendor Evaluation

  • No SOC 2 report and no timeline for obtaining one
  • Terms of service that grant broad rights to use customer data for model improvement with no opt-out
  • Refusal to sign a DPA or BAA when your data requires one
  • No clear answer on data residency or sub-processor list
  • Security questionnaire responses that are vague or reference outdated assessments
  • No dedicated security contact or security documentation portal

Building an AI Vendor Registry

As you onboard AI tools, maintain a vendor registry that tracks: the tool name and vendor, the data it accesses, the DPA status, the last security review date, and the business owner responsible for the relationship. This registry becomes essential when you need to respond to a data subject request, a regulatory inquiry, or a security incident involving a third party.

Infinity Network Support helps South Florida businesses build third-party AI risk management programs — from vendor questionnaire development and DPA review through ongoing monitoring and registry management. Contact us if you are onboarding AI tools and want to ensure your due diligence is defensible.
Share X LinkedIn Facebook
INS

Infinity Network Support Team

Managed IT & Cybersecurity Specialists

Serving small and mid-sized businesses in Miami & South Florida with managed IT support, cybersecurity, and compliance services.

Free Download

The AI Governance Playbook

How to adopt AI safely in 2026 — free guide for South Florida businesses.

Download Free (PDF)

Related Articles

AI Governance

AI Governance for SMBs: Build a Framework Before You Need One

8 min readRead
AI Governance

Building an AI Acceptable Use Policy for Your Business: A Template and Step-by-Step Guide

8 min readRead
Cybersecurity

5 Cybersecurity Threats Every SMB Should Know in 2026

6 min readRead

Have Questions? We're Here to Help.

Our team of South Florida IT specialists is ready to answer your questions and help protect your business.