Skip to content
arcloops
Let's talk →

Guide · Global

AI vendor due diligence checklist — before you sign

Due diligence for AI vendors goes beyond standard SaaS questionnaires. This checklist covers security, data handling, model operations, subprocessors, references, and exit—so procurement and risk teams evaluate what auditors will ask about later.

Arcloops Advisory

AI adoption practice · 26 August 2026 · 5 min read

  • Guide

When to run AI vendor due diligence

Run diligence before master agreement sign—not after production data flows. Triggers: material spend; regulated or personal data; write-back to systems of record; customer-facing outputs; multi-year lock-in; vendor uses subprocessors or foundation models you do not contract with directly.

Lightweight diligence may suffice for low-tier internal draft tools with no production data. Escalate checklist depth with risk tier—/resources/guides/enterprise-ai-checklist governance section.

Consulting partners need diligence too: access to samples, systems, and facilities; subcontractor use; insurance; primary office claims versus delivery reality.

Arcloops advises buyers via /ai-consulting/ai-procurement-advisory and accepts reciprocal diligence from enterprise clients.

Request breach notification history for the past twenty-four months—vendors without incidents may still lack mature detection; ask how they would notify you, not only whether they promise to.

Include tabletop exercise in diligence for Tier 3: simulate vendor breach and walk your incident response—gaps appear before real events.

Verify cyber insurance covers AI-specific incidents your counsel defines—not all policies include model or data poisoning scenarios without riders.

Ask for customer reference calls in the same industry tier—fintech references do not predict NGO or healthcare-adjacent behaviour.

Store diligence artefacts with contract ID and review date—renewals should not restart from blank questionnaires unless vendor materially changes.

Escalate diligence gaps that cannot close in thirty days to risk committee with explicit accept-or-defer decision—open gaps should not auto-default to approve.

Compare vendor security questionnaire answers to live config in proof—misconfigured retention is common when sales engineering sets up demos.

Company and financial stability

Legal entity name and jurisdiction; ownership structure (PE, subsidiary, startup runway); years operating in stated category; financial statements or credit references if policy requires; professional indemnity and cyber insurance certificates; bankruptcy or material litigation disclosure; key person dependency for small vendors.

For early-stage AI vendors, assess continuity plan if acquired or shut down—export and migration clauses matter more.

Verify marketing claims: "global HQ" addresses, certification badges, and client logos—reference checks validate substance.

Security and compliance

SOC 2 Type II or equivalent (scope and date); ISO 27001 if claimed; penetration test summary and remediation status; SSO/SAML support; encryption at rest and in transit; access control model; vulnerability disclosure programme; incident response process and notification SLAs; employee background checks if required by your policy; secure SDLC for vendor-built models and integrations.

Map certifications to your jurisdiction—EU AI Act readiness—/resources/guides/eu-ai-act-enterprise-readiness—GDPR—/resources/guides/ai-data-privacy-gdpr-ai—sector rules as applicable.

Request evidence, not checkbox answers. Sample redacted audit report beats a marketing trust page.

Data handling and subprocessors

Data residency options and default regions; training use of customer data (opt-in/out); retention and deletion timelines; subprocessors list including foundation model providers; cross-border transfer mechanisms; DPA availability and negotiation history; right to audit or receive third-party audit summaries; logging of prompts/outputs and who can access logs.

Clarify whether vendor staff review prompts for quality improvement. Regulated clients often prohibit or restrict such review.

Proof environments must not silently use production data. Diligence should confirm environment separation.

Model operations and product risk

Model sources (own, partner, open-weight); update and rollback process; versioning communicated to customers; accuracy/limitation documentation; bias and safety testing summary for customer-facing features; human oversight features in product; API rate limits and downtime history; support for customer-owned evaluation sets.

Ask for incident examples: model update caused quality regression—how was it handled?

For consulting vendors: who builds, who operates after handover, and whether they resell licences with undisclosed incentive.

References and proof validation

Reference calls with integration leads—not only executive sponsors. Questions: Did go-live match demo? Logging and override as sold? Hidden costs? Support quality after hypercare? Would they buy again for same use case?

Validate proof claims from RFP stage against production references. Discrepancies go back to vendor before sign.

For AI consultancies: ask for redacted sample deliverables and examples of stop recommendations—not only success stories.

Arcloops provides references when NDAs allow and expects buyers to verify delivery claims against /how-we-engage.

Tier 3 vendors should receive on-site or video walkthrough of logging and admin consoles—not questionnaire answers alone. Screenshots can be staged; live navigation reveals retention and access gaps.

Ongoing vendor monitoring after sign

Due diligence is not a one-time PDF archive. Subscribe to vendor status pages; track subprocessors list changes; re-run lightweight DD when the vendor ships a new foundation model default or changes data retention terms.

Quarterly, sample logs with security: who accessed prompt history, whether retention matches contract, whether deleted data requests were honoured in SLA.

For consulting partners, confirm insurance renewal annually and whether delivery team matches proposal key personnel—bait-and-switch teams are a common enterprise complaint.

Maintain a vendor risk register ranked by data tier and blast radius. Tier 3 vendors get executive review when incidents occur; Tier 1 may only need ticket tracking.

Arcloops expects reciprocal monitoring from clients and provides updated subprocessors and security summaries when material changes occur.

Document a four-hour exit drill before sign for Tier 3 vendors: export sample dataset, rotate API keys, and confirm deletion certificate timeline—vendors that stall in drill should not receive production data.

Diligence for foundation model subprocessors

Most AI vendors rely on foundation model providers you may not contract with directly. Diligence must chain: your vendor's DPA, their subprocessor list, and the model provider's terms affecting training use, retention, and abuse monitoring.

Ask whether prompts are used for model improvement by default and how to opt out in production. Ask geographic routing—which region handles inference when your users work in Dubai, Dhaka, or London.

For open-weight models hosted by the vendor, ask patch cadence and security response when CVEs publish. Custom fine-tunes need data deletion guarantees if you terminate—weights may retain memorised samples.

Counsel should review the full chain, not only your direct vendor MSA. Arcloops documents subprocessors we use in client engagements and notifies clients when the chain changes materially.

Maintain a subprocessor diff log—what changed, when, and whether your DPA required notification. Missing notification is a contract breach independent of product quality.

FAQ

It helps but does not cover model ops, subprocessors, or prompt logging. Use this checklist in addition to standard SaaS DD.

Yes. Verify primary office, team composition, subcontractor use, insurance, and sample deliverables—not only platform partnerships.

Emphasize export, escrow if policy allows, financial runway, subprocessors, and shorter contract terms with revisit gates.

Annually for Tier 2–3 vendors; after model changes, subprocessors changes, or incidents.

Document fails; require remediation with dates; do not bypass for executive sponsorship without risk acceptance on record.

Complete vendor DD with evidence

Arcloops helps enterprise buyers structure AI due diligence and responds transparently to client DD requests—with honest scope and delivery claims.