About this tool
Generate the questions to ask an AI vendor about data handling, training, subprocessors, security and exit.
The AI Vendor Due Diligence Checklist generates the specific questions to ask an AI vendor before signing — covering data handling and retention, training on your data, subprocessors and model provenance, security certifications (SOC 2 Type II, ISO/IEC 27001, ISO/IEC 42001), GDPR processor terms and exit rights. Questions are tailored to your vendor type and data sensitivity, and split into must-ask and recommended. It is built for procurement leads, security reviewers and founders evaluating model APIs, AI-enabled SaaS or custom AI development partners.
Open AI Vendor Due Diligence Checklist on AltFTool — it loads instantly in your browser.
Provide your input — an image, text, or data.
Let the tool analyze or generate the result.
Review, refine, and reuse the output wherever you need it.
Covers training-on-your-data, human review of prompts, model deprecation and prompt-injection isolation — the questions ordinary vendor checklists miss.
Every question is tagged must-ask or recommended, so a 30-minute vendor call covers what matters first.
Export the whole checklist with checkboxes for your procurement doc or ticket.
Ask two things: whether your prompts, outputs or files are used to train or improve models by default, and whether the opt-out is written into the contract rather than buried in a dashboard setting. Also ask whether human reviewers ever see your data (for example in abuse review) and under what controls — many vendors that don't train on data still allow human review.
SOC 2 Type II and ISO/IEC 27001 are the baseline security attestations most enterprise buyers require, and you should ask to see the actual report under NDA rather than the badge. For AI-specific governance, ISO/IEC 42001 (published in 2023) certifies an AI management system, and alignment with the NIST AI Risk Management Framework is a good signal where certification is absent.
A subprocessor is any third party the vendor uses to process your data — for AI products that usually includes the underlying model provider and the cloud host, which many buyers overlook. Ask for the full list with locations, and for advance notification of changes with a contractual right to object; under GDPR Article 28 a processor may only engage subprocessors with the controller's authorisation.
If the vendor processes personal data on your behalf, GDPR Article 28 requires a data processing agreement covering instructions, confidentiality, security, subprocessors, and deletion or return of data at contract end. For EU data you also need a lawful transfer mechanism such as standard contractual clauses or an adequacy decision. This checklist flags both as must-ask when EU personal data is involved — final review belongs with your legal counsel.