Enterprise sales & vendor reviews
How do you assess the privacy and security risk of an AI vendor?
Reviewed by the Privacy Horizon team · Last reviewed
Quick answer
Assess an AI vendor the way you would any high-risk processor, plus AI-specific questions. Map what data the tool touches and how sensitive it is; confirm whether your inputs and outputs train the vendor's models; check where data is hosted and who sub-processes it; review security evidence such as SOC 2 and ISO 27001; and verify what the contract guarantees. For AI handling personal or health information, run an AI Privacy Impact Assessment before you sign.
On this page
- What should an AI vendor risk assessment actually cover?
- How do you tell if an AI vendor trains on your data?
- What security evidence should you ask an AI vendor for?
- When does an AI vendor review need a formal AI Privacy Impact Assessment?
- What contract terms protect you when using an AI vendor?
- Frequently asked questions
What should an AI vendor risk assessment actually cover?
An AI vendor assessment is a standard third-party risk review extended with questions unique to machine learning: what data the model sees, whether your data trains it, how outputs are generated, and who is accountable when the model is wrong. Treat any AI tool that touches personal, health, or confidential information as a high-risk processor and scope the review accordingly.
Work through these dimensions in order so you can stop early if a deal-breaker surfaces:
- Data scope and sensitivity: what categories of data the tool ingests (personal information, PHI, financial, IP), and whether that data is necessary for the use case or scope creep you can trim.
- Data use and training: whether your prompts, inputs, and outputs are used to train, fine-tune, or improve the vendor's models, and whether you can opt out by default.
- Hosting and data residency: where data is processed and stored, which cloud regions and which sub-processors and model providers are involved, and whether data leaves Canada.
- Security posture: independent evidence such as a SOC 2 Type II report, ISO 27001 certification, recent penetration tests, encryption in transit and at rest, and access controls.
- AI-specific risks: model accuracy and bias, hallucination and the consequences of a wrong output, human oversight, explainability, and retention of prompts and generated content.
- Contracts and accountability: a data processing agreement, breach notification commitments, audit rights, deletion on termination, and clear liability for AI-driven harm.
How do you tell if an AI vendor trains on your data?
Read the terms, then confirm in writing, because the default behaviour differs sharply between consumer and enterprise products. Many free or consumer AI tools reserve the right to use your inputs to improve their models, while paid enterprise and API tiers from the same provider often exclude customer data from training by default. The tier you actually use determines the answer, not the brand on the box.
Ask the vendor directly: are my prompts, uploaded files, and the model's outputs used to train or fine-tune any model? Is training opt-out the default or something I must request? How long are prompts and outputs retained, and are they reviewed by humans for quality or abuse monitoring? Get the answers in the contract or DPA rather than a sales email, since marketing claims and binding terms frequently diverge.
This matters most when staff might paste personal information, patient details, source code, or unreleased strategy into a tool. If those inputs feed a shared model, you have effectively disclosed that information to a third party, and potentially exposed it to other customers through model outputs.
What security evidence should you ask an AI vendor for?
Ask for independent, current evidence rather than self-attestation, and read it rather than just collecting it. A logo on a trust page is not proof; the underlying report and its scope are what matter. Request the following and check that each genuinely covers the product you are buying:
- A SOC 2 Type II report (read the scope, the period covered, and any exceptions the auditor noted) or an ISO 27001 certificate with its Statement of Applicability.
- Recent third-party penetration test summaries and how findings were remediated.
- A current sub-processor list, including which foundation-model providers and cloud regions are used.
- Encryption details for data in transit and at rest, plus tenant isolation in multi-tenant environments.
- Access controls, including SSO, role-based access, and audit logging you can review.
- Breach history and incident response commitments, including notification timelines.
When does an AI vendor review need a formal AI Privacy Impact Assessment?
Run a formal AI Privacy Impact Assessment (AI-PIA) whenever the tool processes personal or health information, makes or materially informs decisions about individuals, or introduces new automated profiling. A questionnaire tells you what a vendor claims; a structured assessment tells you whether using that vendor with your data is actually defensible.
An AI-PIA extends the traditional PIA method. According to the federal Office of the Privacy Commissioner, a PIA is a risk management process that helps institutions ensure they meet legislative requirements and identify the impacts their programs and activities will have on individuals' privacy, analysed against core privacy principles such as limiting collection, retention, accuracy, safeguards, and limiting use and disclosure. An AI-PIA layers on the questions a model raises: what the system was trained on, how decisions are explained, where bias or inaccuracy could harm someone, and what human review sits between the model and the affected person.
Most private-sector businesses are not legally bound by the government PIA mandates that bind federal and provincial public bodies, but the same methodology is best practice and is increasingly demanded by enterprise, healthcare, and government buyers, and by regimes such as PHIPA and Quebec's Law 25. Doing the assessment before you deploy is far cheaper than unwinding a tool already wired into your workflow.
What contract terms protect you when using an AI vendor?
The contract is where verbal assurances become enforceable, so push the AI-specific protections into the data processing agreement and master terms before signing. The strongest technical posture is undermined by a contract that lets the vendor change the rules later or disclaims all responsibility for the model's output.
- A data processing agreement that names the purposes data may be used for and explicitly prohibits training on your data unless you opt in.
- Sub-processor transparency, with notice and the right to object before new sub-processors or model providers are added.
- Data residency and cross-border commitments aligned to your obligations under Canadian privacy law.
- Breach notification within a defined, short timeframe, with cooperation on investigation and regulator or individual notice.
- Deletion and return of data on termination, including any copies held for model improvement.
- Audit or assurance rights, and clear allocation of liability for harm caused by inaccurate or biased outputs.
Frequently asked questions
No. A SOC 2 report tells you the vendor operates sound controls over a defined system during a defined period, but it says nothing about whether your data trains their model, how outputs are generated, or whether the AI introduces bias or inaccuracy. Use the report as security evidence, then layer AI-specific and privacy questions on top.
You need a fresh look whenever a new feature materially changes what data the tool touches or how it makes decisions. A new AI capability bolted onto an existing tool can quietly expand data use or introduce automated decision-making, so treat significant feature launches as a trigger to reassess rather than assuming your original review still holds.
The core third-party risk steps are the same, but AI adds questions a traditional review misses: whether your inputs train the model, how outputs are generated and explained, the risk of hallucination or bias, and accountability when the model is wrong. You are assessing not just how the vendor protects data, but how the model behaves.
Not with personal, health, or confidential data. Until you have confirmed the tool's data-use and security posture, restrict staff to non-sensitive inputs and set an interim AI usage policy. Pasting regulated or proprietary information into an unvetted tool can amount to an unauthorized disclosure that is difficult to reverse.
Keep exploring
All Enterprise sales & vendor reviewsHow do we prepare for a customer security questionnaire?
Customer security questionnaires (SIG, CAIQ, and custom) gate enterprise deals. Prepare with a control framework, ready evidence, a reusable answer library, and an owner.
ReadPrivacy & security assessmentsPIA vs TRA: which assessment do you need (or do you need both)?
PIA vs TRA: a PIA assesses privacy risk to individuals; a TRA assesses security threats to systems. Learn which assessment you need, or whether you need both.
ReadSOC 2 & ISO 27001What is SOC 2, and does my business need it?
SOC 2 is an independent report on how a service organization protects customer data. Learn what it covers, who requires it, and whether your business needs one.
ReadSOC 2 & ISO 27001SOC 2 vs ISO 27001 — which should we pursue first?
SOC 2 is a North American attestation report; ISO 27001 is an international certification. Compare them and decide which to pursue first — or whether you need both.
ReadEnterprise sales & vendor reviewsHow does a startup pass an enterprise vendor security review?
How does a startup pass an enterprise vendor security review? Map the buyer's requirements, close real gaps, gather evidence, and lead with a SOC 2 or ISO 27001 report.
ReadEnterprise sales & vendor reviewsHow do you prepare for a hospital or healthcare vendor security and privacy review?
How to prepare for a hospital or healthcare vendor security and privacy review: data mapping, PHIPA safeguards, evidence, PIA support, and the documents reviewers expect.
Read