AI vendor and model due diligence: the questions that matter
A practical due-diligence checklist covering data use, retention, tenancy, subprocessors, evaluation, incident terms and exit.
Data use and retention
Establish whether inputs and outputs are used to train or improve models, whether that setting is contractual or configurable, how long content is retained, and whether human reviewers can access it.
Ask the vendor to point to the specific contract clause and the specific tenant setting. Where the two disagree, the contract is what protects you.
Tenancy, hosting and sovereignty
Confirm processing and storage regions, whether they can change without notice, and how tenant isolation is implemented. For Australian organisations with sovereignty commitments, get the regional guarantee in writing rather than in a support article.
List subprocessors, including the underlying model provider, and confirm notification obligations before a new subprocessor is engaged.
Security posture
Request current certifications and the scope statement, penetration test summaries, vulnerability management commitments, SSO and SCIM support, granular role controls, and admin audit logging exportable to your own systems.
Check that the audit log records AI-relevant events, not just logins. Without that, you cannot investigate an AI incident on their platform.
Want this assessed against your environment?
Send us the specifics and a senior advisor will respond within one business day.
Model management and change
Ask how model versions are managed, whether you can pin a version, what notice you receive before deprecation, and what evaluation the vendor performs before pushing a change.
Silent behavioural change is the most under-assessed AI vendor risk. Notice periods are a control.
Incidents, liability and exit
Confirm notification timeframes, the definition of a reportable incident, support for your own regulatory notification obligations, liability position and indemnities, and whether AI output is covered.
Plan the exit before you sign: data and configuration export formats, deletion certification, transition assistance and the practical cost of moving. Lock-in is highest where the vendor holds your prompts, evaluations and workflow logic.
Sources and further reading
- ISO/IEC 42001 AI management systems
- ISO/IEC 27001 information security management systems
- OAIC guidance on privacy and the Privacy Act
This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.
Related reading
Securing enterprise AI adoption: a practical AI security control set
The AI security controls that matter first — identity, data boundaries, model access, logging, human oversight and supplier assurance.
Read articleAI risk assessment: how to assess an AI system before it ships
A repeatable AI risk assessment covering purpose, data, model behaviour, integration, human oversight, failure modes and evidence.
Read articleISO 42001 vs ISO 27001: how the two management systems interlock
What each standard covers, where they overlap, and how to run one integrated management system instead of two parallel programmes.
Read article