AI Vendor Risk Assessment
How to evaluate an AI-enabled vendor before approving its use — a structured assessment that goes beyond a standard security questionnaire.
Most vendor risk processes were built before AI features were common. They ask about data security, uptime, and breach history, but rarely ask the questions that matter once a vendor's product includes AI: what the model was trained on, where inference happens, and what happens to the data after a request is processed.
Why Standard Vendor Review Isn't Enough
A vendor can pass a standard security review — encryption, access controls, breach notification terms — and still introduce AI-specific risk that questionnaire never asked about. AI adds a new set of questions layered on top of the ones legal already knows to ask.
What an AI-Specific Assessment Adds
Training Data Provenance
Whether the vendor's AI model was trained on customer data, including your organization's data, and whether that use can be opted out of.
Subprocessor Chain
Whether the vendor built its own AI capability or routes requests to a third-party AI provider, and what that provider's terms allow.
Data Retention for AI Processing
How long data submitted to an AI feature is retained, and whether it's used to improve the model beyond the immediate request.
Output Reliability Claims
What the vendor actually claims about accuracy, and what liability language exists if AI-generated output turns out to be wrong.
Control Over the Feature
Whether the AI feature can be disabled, scoped, or configured at the account level, or whether it's an all-or-nothing part of the product.
Change Notification
Whether the vendor commits to notifying customers before expanding or materially changing an AI feature's scope.
The core issue
A vendor's marketing language about AI ("smart," "intelligent," "automated") tells you almost nothing about actual risk. The assessment has to get past the language to the mechanics.
A Practical Assessment Sequence
Identify the AI component
Separate what the vendor calls "AI" from what actually functions as machine learning or generative AI touching your data.
Request AI-specific documentation
Ask directly for information on training data, subprocessors, retention, and configurability — most vendors have this ready even if it isn't on their website.
Assess against your use policy
Compare what the vendor's AI actually does against the data boundaries defined in your use policy.
Document the decision
Record the approval, conditions, or decline, along with what specifically drove that outcome, so it can be revisited if the vendor changes the feature.
Reassess on a schedule, not just at onboarding
An AI feature approved at contract signing can change significantly over the life of the relationship. Building a periodic reassessment into vendor management catches those changes before they become a surprise.
Where This Fits in the Governance Model
Vendor risk assessment is the detailed evaluation step inside the broader governance workflow — it's what a full review actually consists of when the AI in question comes from a third party rather than a tool legal built or purchased directly for AI purposes. It works alongside third-party AI risk review, which covers the broader category of embedded and vendor-introduced AI more generally.
A vendor's AI feature is only as trustworthy as the questions you asked before approving it. Most of the risk hides in details the sales conversation never covers.

