AI Vendor Due Diligence: Questions to Ask Before You Sign
Before you sign with an AI vendor, a short list of questions can save you from real trouble later. Here is what to ask about data, training, retention, and exit terms.
Signing up for an AI tool can feel as casual as starting any other subscription. Enter a card, accept the terms, and start using it. But an AI vendor is not just another app. It is a party you may be handing your data to, and the questions you fail to ask before signing are the ones that become expensive later.
You do not need a legal team to do meaningful due diligence. You need a short list of direct questions and the discipline to get real answers before you commit. Here are the ones that matter most.
Where does our data go?
Start with the most basic question. When your staff use this tool, where does the information they enter actually go, and who can see it along the way? A vendor that cannot answer clearly is telling you something important. You want to understand where data is processed and stored and whether it stays within boundaries you can account for.
Is our data used for training?
One of the most consequential questions is whether the vendor uses your data to train its models. If your inputs become part of a shared model, your confidential information could influence outputs delivered to other customers. For a regulated business, that is usually unacceptable.
Get a clear answer, in writing, on whether your data is excluded from training and how that exclusion is enforced.
Retention, deletion, and subprocessors
How long a vendor keeps your data, whether they will delete it on request, and who else touches it are all part of the picture.
- How long the vendor retains your data by default, and whether you can shorten it.
- Whether you can request deletion, and how that request is verified and honored.
- Which subprocessors, or third parties, help deliver the service and what they can access.
- How you are notified when subprocessors change.
A chain of hidden subprocessors is where a lot of data quietly ends up in places you never evaluated. Ask for the list.
Certifications and healthcare requirements
Independent certifications give you evidence that a vendor's security practices are more than marketing. Ask whether they hold a recognized attestation such as SOC 2, and request the report rather than taking the logo on their website at face value.
If you handle protected health information, add one more requirement. Confirm that the specific AI service is covered by a Business Associate Agreement, not just the vendor's other products, before any regulated data goes near it.
Exit and export terms
Finally, understand how you leave. Before you sign, know how you would export your data if you decided to switch, in what format, and what happens to your information after the contract ends. A vendor that makes leaving difficult has more leverage over you than you want them to have.
The best time to ask all of this is before you sign, when the vendor is still trying to win your business and has every reason to answer clearly. Once the contract is in place and your team depends on the tool, your leverage is gone and the same questions become far harder to force.
None of these questions require deep technical expertise, only the discipline to ask before you commit. Where does our data go, is it used for training, how is it retained and deleted, who are the subprocessors, what certifications exist, and how do we exit. A managed services partner can help you sequence this work and read the answers with a practiced eye.