VENDOR EVIDENCE PACK · REVIEWED AUGUST 2026
AI Vendor Security Due Diligence: A Practical 2026 Checklist
Questions and evidence to review before sending business data to an AI provider or connecting it to production systems.
Feature comparisons often happen before data, retention, subcontractor, incident and exit questions. That order can create an expensive dependency before basic protections are understood.
This guide is designed for small businesses, procurement teams and technical owners. It turns the topic into a reviewable sequence rather than asking readers to trust a provider label, a detector score or a fluent model answer.
Practical recommendation: Select vendors from evidence, not promises: document data flows, contract commitments, security controls, model-change practices, access boundaries and an exit path.
Before you start
Write down the exact task, accountable owner, approved data, affected people and the result that would be unacceptable. Use safe representative examples during the first pass. Where health, legal, employment, financial, safety or regulatory obligations may apply, involve a qualified professional and follow the rules that govern your organization.
1. Classify the intended data
List whether prompts may contain public, internal, confidential, personal, regulated or customer-controlled information. Disallow classes the service has not been approved to receive.
Document the decision made during “Classify the intended data”, the evidence consulted and the person responsible for the next action. That short record helps small businesses, procurement teams and technical owners distinguish a repeatable control from an informal habit.
2. Trace storage and reuse
Ask what is retained, where it is processed, who can access it and whether inputs or outputs are used to improve models. Capture the applicable product tier and contract.
Test “Trace storage and reuse” with a normal case and a deliberately difficult case. Record what passed, what required correction and which condition should trigger a human review for small businesses, procurement teams and technical owners.
3. Review identity and access
Check SSO, MFA, role separation, audit logs, service accounts, API-key rotation and the ability to revoke a user without losing team records.
Assign an owner and completion criterion for “Review identity and access”. If the evidence is missing or contradictory, pause the workflow instead of allowing speed or model confidence to become the approval rule.
4. Examine change and incident practices
Ask how model changes are announced, how security incidents are communicated and what evidence is available for investigation.
Keep the input, output version and reviewer note associated with “Examine change and incident practices” where policy permits. This makes later corrections traceable without retaining unnecessary sensitive data.
5. Design the exit before adoption
Test export formats, deletion, key revocation and replacement. Keep prompts, evaluations and critical knowledge in portable formats where possible.
Review this step after material changes to the model, provider, prompt, data source or connected system. A control that worked in one configuration should not be assumed to cover the next one.
Common failure modes and controls
The following table is a pre-launch challenge list. Teams should adapt it to the systems, people and permissions in their real deployment.
| Failure mode | Practical control |
|---|---|
| Marketing page treated as assurance | Request dated evidence and contract language for material commitments. |
| Consumer and enterprise tiers confused | Record the exact plan, region and data controls being evaluated. |
| Vendor access expands quietly | Review integrations, scopes and administrators on a schedule. |
| No workable exit | Run a small export and deletion drill before production use. |
What to measure
Do not optimize a single headline number. Measure useful outcomes together with correction effort, critical failures and the human work needed to make the result acceptable.
- vendors with completed data-flow recordsDefine the numerator, denominator, owner and review period for vendors with completed data-flow records; compare like-for-like workflow versions.
- critical questions backed by evidenceTrack critical questions backed by evidence beside correction effort and serious exceptions so a faster result does not hide weaker quality.
- time to revoke accessSample time to revoke access by risk level and user group; investigate material changes instead of relying on one aggregate percentage.
- time to export or migrateSet a baseline for time to export or migrate, record the intervention and review whether the change remained useful after human verification.
Final review checklist
- Data classes are approved
- Retention is documented
- Training-use terms are clear
- Access controls are tested
- Incident contacts are recorded
- An exit drill has been completed
Frequently asked questions
Is a security certification enough?
It is useful evidence but not a complete answer. Your specific data flow, plan, integrations and responsibilities still need review.
What if the vendor will not answer?
Treat missing evidence as a risk. Reduce the data and permissions, choose another tier or provider, or keep the use case out of production.
How often should reviews repeat?
Repeat after major product, model, policy, subprocesser or integration changes and on a risk-based schedule.
Primary and official sources
- NIST AI Risk Management Framework and Generative AI Profile (checked August 13, 2026)
- NIST Privacy Framework (checked August 13, 2026)
- CISA Secure by Design (checked August 13, 2026)
- FTC guidance on AI privacy and confidentiality commitments (checked August 13, 2026)
This independent guide was reviewed against the linked primary or official materials on August 13, 2026. It provides an operational framework, not legal, medical, financial or security certification. Product features, terms and policies can change, so verify time-sensitive details at the source.
Continue your comparison
Use AI Tools Galaxy to compare access models and read the detailed editorial profiles available for selected tools. Keep tests small, protect sensitive data and verify important output before acting on it.
Browse AI tools