CURRENT TREND INSIGHT
How to vet an enterprise AI vendor for strict data privacy policies Illustration

How to vet an enterprise AI vendor for strict data privacy policies

Direct Summary:

Vetting an enterprise AI vendor starts with three concrete documents, not a sales call: a current SOC 2 Type II report (or ISO 27001 certification) covering the actual service you'll use, a signed Data Processing Agreement satisfying GDPR Article 28 if any EU personal data is involved, and an explicit sub-processor list showing which other companies (cloud hosts, other AI providers) will touch your data. If a vendor can't produce these on request, that's the finding — not a detail to chase down later.

"Progress is impossible without change."

— George Bernard Shaw

Key Insights

  • SOC 2 Type II beats Type I: a Type I report only confirms controls were designed correctly at a point in time; a Type II report confirms they actually operated effectively over a period (commonly 6-12 months) — ask which type you're being shown.
  • The DPA has to name specifics, not just exist: a real Article 28-compliant DPA covers processing purpose, data categories, sub-processors, breach notification timelines, and audit rights — a one-page "we take privacy seriously" document isn't a DPA.
  • AI vendors need AI-specific questions added to standard vendor security review: traditional IT vendor checklists miss AI-unique risks like whether your prompts/outputs are used for model training, and whether the vendor has documented red-teaming or adversarial testing.

A vendor's marketing page saying "enterprise-grade security" is not evidence — it's a claim. Real vetting means asking for the specific documents that back the claim and actually reading them, not just confirming they exist. For an AI vendor specifically, standard vendor security review needs a few AI-specific additions that a generic IT vendor checklist won't catch.

What to actually request and check

1. Request the SOC 2 Type II report (or ISO 27001 certificate) and check its scope. Confirm the report covers the actual product/service you'll use — a SOC 2 report scoped to a different product line at the same company doesn't tell you much about the one you're buying.

2. Get the Data Processing Agreement and read the sub-processor list. The DPA should specify what data categories are processed, where data is stored/transferred, breach notification timelines, and — critically — a list of sub-processors (other companies, like cloud hosts, who will also touch your data).

3. Ask AI-specific questions a generic vendor questionnaire misses. Does the vendor train models on your submitted prompts/data? Do they conduct and document red-teaming or adversarial testing? What controls exist against prompt injection or cross-customer data leakage?

vendor_vetting_checklist.md
# Minimum document request list for an AI vendor security review

Standard vendor documents:
  [ ] SOC 2 Type II report (check scope + report period)
  [ ] Data Processing Agreement (check sub-processor list)
  [ ] Breach notification terms and timeline

AI-specific additions:
  [ ] Written confirmation: is submitted data used for model training?
  [ ] Data retention period for prompts/outputs
  [ ] Documented red-teaming / adversarial testing summary
  [ ] Controls against prompt injection and cross-tenant leakage
Evidence Type What It Actually Confirms
Marketing claim ("enterprise-grade security") Nothing verifiable — a claim, not evidence
SOC 2 Type II report + signed DPA + AI-specific answers Independently audited controls, contractual data-handling terms, and AI-specific risk coverage

If a vendor hesitates or can't produce a current SOC 2 Type II report and a specific, named DPA on request, treat that as the actual finding of your review — not a formality to chase down after signing a contract. The absence of these documents is itself informative.

Practical Challenge

Using the checklist above, request these documents from an AI vendor you (or your organization) currently use or are evaluating, and note which items they can and can't produce.

Concept Check

What's the key difference between a SOC 2 Type I and a SOC 2 Type II report when vetting a vendor?
Correct! Type II is the stronger evidence because it demonstrates sustained operational effectiveness, not just a design review at a single point in time.
Incorrect. Try again! The distinction is about point-in-time design review (Type I) versus effectiveness demonstrated over an audit period (Type II).

Sources & Further Reading

Previous Guide Dashboard Next Guide