Practical guide
AI Vendor Review Checklist: What to Ask Before You Approve a Tool
The questions to answer before approving an AI vendor for business use — data handling, training, retention, security, and subprocessors — and which answers should stop the approval.
Key takeaways
- Review an AI vendor across six areas: what data it sees, whether it trains on your data, how long it retains that data, what security it publishes, which subprocessors it uses, and what happens when it is wrong.
- Two answers should stop an approval outright: the vendor trains on your data and you plan to send customer PII, or the vendor will not say how long it keeps your inputs.
- "Unclear" is a finding, not a blank. If you cannot answer a question after reading the terms, record it as unclear and ask the vendor.
- Most small businesses do not need a formal vendor assessment process — they need one page per tool, written once, reviewed annually.
- Approving a vendor is not the same as approving a use case. A vendor can be fine for drafting internal notes and unacceptable for processing customer records.
A vendor review sounds like something with a procurement department attached. For a small business it is much simpler: before you let a new AI tool touch your work, you read what the vendor says it does with your data, and you write down what you found.
The reason to write it down is not bureaucracy. It is that in a year, when someone asks whether it is acceptable to paste customer complaints into that tool, you want the answer to already exist.
This checklist covers the six areas worth reviewing, and — more usefully — which answers should stop an approval.
1. What data will this tool actually see?
Start here, because every other answer's weight depends on it.
Be concrete. Not "business data" but: customer names and email addresses, invoice amounts, employee performance notes, draft marketing copy, source code. The question is what your team will realistically paste in during a normal week, not what the ideal policy says.
Stop signal: if credentials — passwords, API keys, access tokens — are on that list, the answer is not "review the vendor more carefully." It is that no AI chat tool should be receiving them at all. Prompt safety tips covers why, and what to paste instead.
2. Does the vendor train on your data?
This is the question most people mean when they ask whether an AI tool is "safe."
There are three practical answers:
- No, contractually. The terms state that business or API inputs are not used for model training. This is common on paid business tiers.
- Opt-out available. Training is on by default; you can turn it off in settings. Fine — but someone has to actually turn it off, on every account, and confirm it. This is the default on several of the biggest consumer tiers.
- Yes, or unclear. No exclusion you can point to, or language vague enough that you cannot tell.
Do not assume the tier alone tells you which of the three applies. Consumer defaults genuinely differ between major providers — at least one requires you to switch training on — so the answer has to come from the tool you are actually approving.
Stop signal: "yes or unclear" combined with customer PII from question 1. That combination means customer information you were trusted with may end up shaping a model you do not control. Either move to a tier that contractually excludes training, or keep that data out of the tool.
3. How long is your data retained?
Retention matters even when training does not happen. Data that is stored is data that can be exposed in a breach, subpoenaed, or seen by support staff.
Look for a stated period — 30 days, 90 days, until you delete it. Then check whether you can delete it yourself, and whether deletion covers conversation history or just the visible interface.
Stop signal: you cannot find a retention period at all. Indefinite-by-omission is the most common quiet risk in AI vendor terms, and it is a reasonable reason to hold an approval until you have asked.
4. What security does the vendor publish?
You are not auditing anyone. You are checking whether they have done the basic work of publishing:
- A security page describing encryption in transit and at rest
- An independent certification or audit report (SOC 2, ISO 27001) if they serve business customers
- A documented way to report a vulnerability
A vendor with nothing published is not automatically disqualified — plenty of small, useful tools are in that position — but it should cap what you send them. Public information and internal drafts, not customer records.
5. Which subprocessors are involved?
Most AI products are built on someone else's model. A note-taking tool may send your text to a major model provider, which may in turn run on a cloud host. Each hop is another company holding your data.
Reputable vendors publish a subprocessor list. What you want to know is simply whether the chain is disclosed, because an undisclosed chain means you cannot answer a customer who asks where their data went.
6. What happens when the output is wrong?
The last question is not about the vendor at all. It is about you.
Assume the tool produces something confidently incorrect. Who catches it before it reaches a customer? If the answer is "nobody, it goes straight out," the vendor's data practices are the smaller problem. AI risk management for small businesses works through this as one of five risk dimensions, and it is usually the one that decides how tight the rest of your controls need to be.
Turning the answers into a decision
Three outcomes are enough:
Approve. Data sensitivity is low or the vendor's terms are clear and restrictive. Record the decision, the date, and who made it.
Approve with conditions. The common case. The tool is fine for specific uses and not others — approved for drafting and internal analysis, not for customer records; training setting must be disabled; no credentials ever. Write the conditions next to the approval, because an approval without conditions is remembered as unconditional.
Do not approve yet. Something in questions 2 or 3 is unresolved. This is not a rejection of the vendor; it is a note that you asked a question and have not received an answer.
Then set a review date. Annually is enough for most small businesses — AI vendors change their terms more often than that, but you will not realistically check more frequently.
Who decides, and how it gets recorded
A checklist nobody owns produces nothing. The AI tool approval process for small businesses covers the surrounding workflow: how an employee requests a tool, who reviews it, and where the answer lives so the next person can find it. If you want to know what a vendor's terms are really telling you, what AI vendor data-processing terms actually mean walks through the specific language to look for.
Where this fits
Vendor review is one section of a wider governance picture — the small business AI governance checklist shows the other sections and lets you score where you stand.
To score a specific planned use of a tool rather than the vendor behind it, the AI Risk Checklist returns a Low / Medium / High rating with tailored safeguards, free and entirely in your browser.
For a ready-made vendor review form, a tool approval checklist, and the surrounding policy documents, see the Starter Pack.
This article provides practical operational guidance for AI usage management. It is not legal advice and does not guarantee regulatory compliance. Review it with qualified professionals where appropriate before adopting it.