Every AI vendor is a potential doorway into your business — into your data, your customers’ data, and your operations. Strong vendor due diligence ensures that the AI tools you adopt meet your standards for security, privacy, and responsible use, and that risks are understood before contracts are signed rather than discovered after something goes wrong.
- Define a Tiered Review Process:
- Categorize by Risk: Group vendors into tiers based on data sensitivity, business criticality, and the actions their AI takes, so high-risk vendors receive deeper scrutiny.
- Right-Size the Effort: Apply lighter reviews to low-risk vendors and reserve thorough due diligence for those handling sensitive data, regulated information, or high-impact decisions.
- Assess Security Posture:
- Request Documentation: Review SOC 2 reports, ISO certifications, penetration test summaries, and incident history to understand the vendor’s security maturity and track record.
- Use Security Questionnaires: Ask vendors about access controls, encryption practices, monitoring capabilities, and incident response, and verify their answers against available evidence.
- Clarify Data Handling:
- Training Data Use: Confirm whether your prompts, uploads, and outputs may be used to train the vendor’s models, and ensure any default settings reflect your requirements.
- Retention and Location: Understand how long data is retained, where it is stored, and which subprocessors may have access, including those in different jurisdictions.
- Examine the AI Supply Chain:
- Map Subprocessors: Identify the underlying model providers, hosting platforms, and other AI services your vendor relies on, since their risks become your risks.
- Assess Concentration: Be aware of cases where many of your vendors depend on the same upstream provider, which can create unexpected single points of failure.
- Negotiate Strong Contract Terms:
- Security and Data Provisions: Include explicit terms on encryption, access control, monitoring, and data use restrictions, plus breach notification timelines that meet your regulatory obligations.
- Right to Audit: Retain the right to review or verify vendor controls, particularly for high-risk relationships, and define clear procedures for exercising that right.
- Monitor Vendors Continuously:
- Track Changes: Subscribe to vendor announcements and security advisories so you are aware of changes in features, defaults, terms, or ownership that may affect risk.
- Reassess Annually: Conduct formal vendor reviews at least once a year, requesting updated documentation and confirming continued alignment with your standards.
Email noelga@vastmanagementcorp.com
Phone +1-516-449-7411