Library
The AI Vendor Risk Checklist
A procurement list you can actually use. Data handling, training-on-your-data, sub-processors, audit rights, and model-change notifications: the clauses that decide whether a vendor is safe to put on a live path.
Last reviewed
MikeFounder & developer
- AI governance
- Compliance
- Workflow
On this page
Who this is for
- Anyone buying or renewing an AI or AI-featured SaaS tool
- Operators filling the inventory who have a vendor in the row and no contract answers
- Counsel who want a working list rather than a 40-page RFP pack
How to use it
Walk the list before the tool is on a live path. A “yes” needs a clause or a screenshot, not a salesperson's nod. A “no” is a decision: accept, negotiate, or walk.
This is practice. It does not replace international transfers or a DPIA.
The checklist
Data handling
- Named legal entities: who is controller, who is processor, who is the model provider if different from the SaaS vendor.
- Categories of data they will receive, including whether special-category or children's data is in scope (and a contractual ban if it must not be).
- Retention: how long prompts, outputs, embeddings and logs are kept; a deletion / export path on exit.
- Location of inference, storage, backups, and support access.
- Encryption in transit and at rest; who holds keys.
- A data processing agreement that matches the transfer story (SCCs / IDTA / Addendum / DPF certification, whichever actually applies).
Training on your data
- The contract states whether your prompts, files or outputs may be used to train their models (foundation or product).
- Default is no, or an opt-in you control, not a buried “improve the service” line.
- If training is allowed: purpose, retention, whether other customers benefit, and how you withdraw.
- Fine-tunes on your corpus: who owns the resulting weights; what happens on termination.
Sub-processors
- Current sub-processor list, with locations, for the AI path (not only the billing path).
- Notice before a new sub-processor is added, with a right to object or exit.
- Flow-down of the same data, training, and security terms.
- No silent use of a consumer-grade model endpoint behind a business SKU.
Audit and evidence
- Right to audit, or to receive a current independent report (SOC 2 / ISO 27001 / equivalent) that covers the AI processing, not only the marketing site.
- Right to ask for the documentation you need as a deployer (limitations, intended use, oversight instructions), especially if you may sit in Annex III later.
- Incident notice: what they tell you, how fast, and whether your regulator clock is respected.
- Record of model evaluations they are willing to share (even a summary).
Model-change notifications
- They must tell you when the model, the version, or the safety layer changes in a way that could alter outputs on your path.
- You can pin a version, or you have a staging window before a change hits production.
- Changes to logging, retention, or training defaults are notice events, not changelog trivia.
Oversight and product behaviour
- You can turn off auto-send / auto-publish.
- A human confirm step is possible in the product, not only in your own wrapper. See Human Oversight by Design.
- Outputs can be traced to a model version and a prompt log your reviewers can see.
Exit
- Export of your data in a usable format.
- Deletion of your data, embeddings and fine-tunes, with a date.
- Survival of confidentiality after exit.
Scoring it
You do not need every box for a low-stakes internal summariser with no personal data. You do need the training, sub-processor, location and exit boxes for anything that sees customer or staff data. If the vendor will not answer training-on-your-data in writing, do not put live tickets in.
Questions
The vendor's DPA is “industry standard”. Enough?
Read the training clause. That is where industry standard often means they train on you. If it is silent, ask for a sentence. Silence is not “no”.
We are a processor for our client and we want to add a model.
You need your client's instruction, a sub-processor notice, and the same list above between you and the model vendor. You cannot invent a basis they do not have.
Does a DPF badge replace this list?
No. It answers one transfer gate. See transfers.
What changed
- 13 August 2026: First publication of the full checklist. Cadence: stable / evergreen (180–365 days). Next review due 13 May 2027.
Note: This is compliance consulting and training, not legal advice. We work alongside your legal counsel, translating regulation into operational reality rather than replacing them. For a structured pass, see AI compliance.
Was this helpful?
Also in the library
- Building an AI System InventoryStart with a list. Most governance programmes stall because nobody has an honest register of what is already in use, including the vendor copilots people forget to mention. The sheet below is the one we use in an audit. Copy it.
- What Counts as High-Risk Under Annex IIIAnnex III is a use-case list, not a model list. Most Lathestone clients who over-classify do it because the tool is 'AI'; most who under-classify miss internal HR and customer-decision systems. Article 6(3) exemptions exist. They are narrow, and profiling is not one of them.
- Automation vs AI: A Decision FrameworkA rule, a model, and a person are three different tools. Use a rule when the path is stable and the answer is known. Use a model when the input varies and a person will still confirm. Leave it with a person when the volume is low, the judgement is high, or the failure is expensive.