All insights
Cyber & risk1 min read

AI vendor security due diligence

Questions and evidence for assessing AI suppliers across data, models, identity, contracts and exit risk.

By FORTE/CYBERx AdvisoryReviewed by FORTE/CYBERx Advisory24 July 2026

Follow the information

Ask what data enters the service, where it is processed, whether it trains provider models, how long it is retained and which subprocessors receive it. Match evidence depth to data sensitivity and business impact.

Review tenant isolation, encryption, identity, administrative access, logging and deletion.

Assess the AI-specific failure modes

Consider prompt injection, insecure output use, excessive agency, model or retrieval poisoning, unpredictable behaviour and dependency on external models. For agents, document every tool and action boundary.

Apply this to your organisation

Want this assessed against your environment?

Send us the specifics and a senior advisor will respond within one business day.

Native secure submission. Your details are never sold or shared.

Make assurance contractual

Include incident notification, material model or subprocessor changes, audit evidence, service continuity, data return and deletion, transition support and liability. Reassess high-impact suppliers on a defined cadence.

Sources and further reading

This article provides general information and decision support. It is not legal advice, audit assurance, certification advice or a guarantee of outcome.

Related reading

Start a useful conversation

Talk to a senior advisor

Tell us the decision, constraint or opportunity. A senior operator responds within one business day.

Native secure submission. No embedded HubSpot branding.