AI GOVERNANCE HUB

AI Vendor Risk Assessment

How to evaluate an AI-enabled vendor before approving its use — a structured assessment that goes beyond a standard security questionnaire.

Most vendor risk processes were built before AI features were common. They ask about data security, uptime, and breach history, but rarely ask the questions that matter once a vendor's product includes AI: what the model was trained on, where inference happens, and what happens to the data after a request is processed.

Why Standard Vendor Review Isn't Enough

A vendor can pass a standard security review — encryption, access controls, breach notification terms — and still introduce AI-specific risk that questionnaire never asked about. AI adds a new set of questions layered on top of the ones legal already knows to ask.

What an AI-Specific Assessment Adds

Training Data Provenance

Whether the vendor's AI model was trained on customer data, including your organization's data, and whether that use can be opted out of.

Subprocessor Chain

Whether the vendor built its own AI capability or routes requests to a third-party AI provider, and what that provider's terms allow.

Data Retention for AI Processing

How long data submitted to an AI feature is retained, and whether it's used to improve the model beyond the immediate request.

Output Reliability Claims

What the vendor actually claims about accuracy, and what liability language exists if AI-generated output turns out to be wrong.

Control Over the Feature

Whether the AI feature can be disabled, scoped, or configured at the account level, or whether it's an all-or-nothing part of the product.

Change Notification

Whether the vendor commits to notifying customers before expanding or materially changing an AI feature's scope.

The core issue

A vendor's marketing language about AI ("smart," "intelligent," "automated") tells you almost nothing about actual risk. The assessment has to get past the language to the mechanics.

A Practical Assessment Sequence

Identify the AI component

Separate what the vendor calls "AI" from what actually functions as machine learning or generative AI touching your data.

Request AI-specific documentation

Ask directly for information on training data, subprocessors, retention, and configurability — most vendors have this ready even if it isn't on their website.

Assess against your use policy

Compare what the vendor's AI actually does against the data boundaries defined in your use policy.

Document the decision

Record the approval, conditions, or decline, along with what specifically drove that outcome, so it can be revisited if the vendor changes the feature.

Reassess on a schedule, not just at onboarding

An AI feature approved at contract signing can change significantly over the life of the relationship. Building a periodic reassessment into vendor management catches those changes before they become a surprise.

Where This Fits in the Governance Model

Vendor risk assessment is the detailed evaluation step inside the broader governance workflow — it's what a full review actually consists of when the AI in question comes from a third party rather than a tool legal built or purchased directly for AI purposes. It works alongside third-party AI risk review, which covers the broader category of embedded and vendor-introduced AI more generally.

A vendor's AI feature is only as trustworthy as the questions you asked before approving it. Most of the risk hides in details the sales conversation never covers.