AI Vendor Checklist: 7 Questions Every SMB Must Ask

Why Due Diligence Matters

A July 2025 Bitsight advisory notes that assessing a vendor’s AI governance posture is now a top criterion in third‑party risk management. Bitsight

The Magnificent Seven Questions

  1. What data trains your model—and who owns it?

  2. Can you show current SOC 2 or ISO 27001 certificates?

  3. How often do you retrain, and who audits drift?

  4. Is there a kill switch or rollback plan?

  5. Do we keep IP rights on outputs?

  6. What’s your price after year one?

  7. Will you sign our AI‑use addendum?

2‑Page Scorecard Template

DimensionWeightPass Threshold
Security & Privacy30 %All certs current
Transparency20 %Written audit log
TCO Predictability20 %≤ 5 % price escalator
Support SLAs15 %< 2 hr P1 response
Cultural Fit15 %Named success manager

Red‑Flag Signals

  • “Black‑box” answers on training data.

  • Non‑standard pricing escalators.

  • No human contact for critical support.

Executive Cheat‑Sheet

  • Governance questions belong in the first call, not the contract addendum.

  • Continuous monitoring beats annual questionnaires.

  • Legal IP clauses should mirror your data‑privacy policy.

Related Posts

AI Strategy for SMBs: Build a Winning AI Roadmap in 5 Steps

AI Ethics & Governance for SMBs: A 5‑Step Playbook

AI Training for SMBs: Building a Culture of Adoption

Index
Scroll to Top