Direct answer
Evaluate an AI vendor's data use and training terms, retention and deletion, identity and access, encryption, tenant separation, logs, subprocessors, hosting, incident duties, AI-specific testing, independent assurance, legal commitments, availability, export, and termination. Verify evidence and configuration for the exact product and plan you will deploy.
Start with context
Define the use before reviewing the vendor
- Business purpose and intended users
- Information categories and minimum necessary fields
- Whether the system only reads, drafts, recommends, or takes actions
- Connected systems and permission level
- Customer, employee, financial, legal, or safety impact
- Required availability, recovery, and support
- Applicable contracts, regulations, and internal policies
Core review
Ask for specific controls and evidence
| Area | Question | Evidence |
|---|---|---|
| Data use | Are inputs, outputs, metadata, or feedback used for training? | Contract and product-specific data terms |
| Retention | How long is data stored and how is deletion verified? | Configuration, retention schedule, deletion process |
| Identity | Can access use SSO, MFA, roles, and least privilege? | Administrative documentation and test account |
| Security | How are data and secrets protected? | Architecture, encryption, key, and secure-development evidence |
| Logs | Can administrators trace access, prompts, actions, and exports? | Sample audit events and retention |
| Supply chain | Which subprocessors, models, and hosting regions participate? | Current subprocessor and data-flow list |
| Incident | When and how will the customer be notified? | Contract language and response process |
| Exit | Can data, configuration, and logs be exported and deleted? | Demonstrated export and termination procedure |
AI-specific risk
Traditional security assurance is necessary but incomplete
- Prompt injection and malicious retrieved content
- Sensitive information disclosure in outputs or logs
- Excessive agency and tool permissions
- Insecure output passed into another system
- Model, data, plugin, and dependency supply-chain risk
- Poisoned or untrusted source material
- Unbounded consumption, unexpected cost, or denial of service
- Model or product changes that alter tested behavior
Evidence hierarchy
Move from claims to configuration and contracts
Published claim
Useful for discovery, but not enough for approval.
Technical documentation
Confirms intended architecture and available controls.
Independent assurance
Review scope, period, exceptions, and whether the exact service is covered.
Customer test
Verify identity, logs, deletion, export, limits, and relevant security behavior.
Contract
Make material data, incident, subprocessor, support, and termination duties enforceable.
Decision
Approve the use case, not the vendor in the abstract
The same vendor may be acceptable for public content drafting and unacceptable for a workflow involving restricted records or autonomous actions. Record approved data, users, integrations, actions, configuration, review date, and prohibited uses.
The value point
After this page, you should be able to decide:
Whether the vendor and selected service tier can support the intended data, actions, risk, and exit requirements.Your working output should be an evidence-based security review, contract questions, AI-specific threat list, and approve, limit, or reject decision.
Questions business leaders ask
Frequently asked questions
Is a SOC 2 report enough to approve an AI vendor?+
No. It can be useful assurance, but review its scope, period, exceptions, and exact services. AI data use, model behavior, prompt injection, actions, retention, and product-specific controls still require review.
What is the most important AI vendor question?+
Start with what happens to inputs, outputs, metadata, and feedback in the exact account and service tier, then confirm the answer contractually and through configuration.
Should a small business perform vendor security review?+
Yes, proportionate to risk. A focused review can still cover data, access, retention, incidents, assurance, subprocessors, and exit.
How often should an AI vendor be reviewed?+
Review before use, at contract renewal, after material product or model changes, after incidents, and when the use case, data, integrations, or action permissions expand.
Research anchors
Primary and authoritative sources
- CISA: Secure by Design↗
- NIST Generative AI Profile↗
- OWASP Top 10 for Large Language Model Applications↗
- FTC: Privacy and confidentiality commitments for AI companies↗
Examples and planning ranges are clearly labeled. Source terms, provider behavior, and regulations can change; verify current requirements for your organization and jurisdiction.
Prepared and reviewed by the Future Made Useful systems editorial team. Material guidance reviewed July 17, 2026.