Every AI tool is a data-handling decision dressed as a purchase. The subscription is cheap, the deployment is quick, and the terms that determine what happens to your information are usually a click away and unread. Due diligence is the short, standard set of questions that turns that decision into a deliberate one.
This guide covers the questions to ask, the evidence to request, the red flags that end a procurement, and how to record the assessment. It is part of the Governance, Risk & Data pillar.
The tool is not the risk. The retention clause is the risk.
The seven questions
Ask these of every tool before it is used on company work.
| # | Question | Why it decides the answer |
|---|---|---|
| 1 | Where does the data go, and in which jurisdiction is it processed? | Determines your obligations and your exposure |
| 2 | Is input retained, and for how long? | Retention is the exposure window |
| 3 | Is input used to train models? | Training use is a disclosure and confidentiality risk |
| 4 | Who can access it on the vendor’s side? | Support and engineering access is a real path |
| 5 | Can you export and delete your data? | Determines your exit and your ability to honour deletion requests |
| 6 | What is the accuracy and verification story? | Determines how the output must be checked |
| 7 | What does the contract say about liability and breach notification? | Determines who bears the cost when something goes wrong |
Seven questions, answerable in a short call or a document review. For most small businesses, questions 2 and 3 are the ones that change the decision.
What good looks like
A tool that is comfortable for confidential work usually has these properties.
- Training disabled, either by default or by configuration on your plan, with the setting confirmed in writing.
- Defined retention, with a stated period and a deletion path.
- Access controls, so you can restrict who in your business can use it and on what data.
- Export and deletion, so you are not locked in and can honour a deletion request.
- A data processing agreement, which many vendors offer on business plans and not on consumer tiers.
The most valuable of these for most small businesses is the enterprise tier on the main assistant: it converts a policy statement about retention into a contractual one.
Red flags
Four signals should end or pause a procurement.
- Vague answers about training use. If the vendor cannot state clearly whether inputs train their models, assume they do.
- No data processing agreement available. Without one, your obligations are unaddressed.
- No retention statement. Data retained indefinitely is data exposed indefinitely.
- No export path. A tool you cannot extract from is a decision you cannot reverse.
A fifth, subtler red flag: a tool that requires the upload of your entire dataset to work. Bulk ingestion increases the exposure without improving the outcome, and it is rarely necessary for a contained use case.
The evidence to keep
Due diligence is worth little without a record. Keep four artefacts.
- The answers, in writing, ideally in the vendor’s own documentation or a signed response.
- The date of the assessment, because terms change.
- The decision, and the categories of data the tool is approved for.
- The review date, so the assessment is revisited rather than assumed to hold.
That record is what lets you answer the question a client, insurer or regulator will eventually ask: what did you assess, and when.
Re-assessing
Tool terms move. A vendor can change retention, enable training by default, or move processing to a new jurisdiction, and the change is often communicated by email rather than negotiated.
- Re-check the two questions that matter — retention and training — at least annually.
- Re-check after any material change in the vendor’s terms or ownership.
- Record the review, so the file shows a current position rather than a historical one.
- Have a fallback, so a change in terms does not force an urgent migration.
A worked assessment
A firm assesses an AI meeting-notes tool that would transcribe internal meetings and retain a searchable record.
- Processing location: the vendor processes in the US, which suits the firm’s obligations.
- Retention: transcripts retained for 30 days by default, extendable — and the firm can delete on request.
- Training use: the vendor states that business-tier input is not used for training, confirmed in the plan documentation.
- Access: vendor support can access content only with the customer’s permission, per the agreement.
- Export and deletion: a full export is available, and deletion is supported.
- Accuracy: the transcript is generally accurate but unreliable for names and figures, so the firm adds a check on any decision recorded from a meeting.
- Contract: a data processing agreement is available, and breach notification is defined.
The tool is approved for internal meetings that do not include client confidential material, with a note that any decision taken from a transcript is confirmed against the minutes. The assessment is dated, and set for review in twelve months.
Common mistakes
- Assessing features rather than data handling. The purchase decision is usually made on the wrong question.
- Accepting the vendor’s summary of its own terms. Ask for the specific clause.
- No record of the assessment. The position cannot be evidenced later.
- Assuming the consumer tier matches the business tier. Retention and training terms frequently differ.
- Never re-assessing. Terms change, and the change may not be announced.
- Bulk ingestion by default. More data in the tool means more exposure, not more value, and it is rarely necessary for a contained use case.
- Assessing once. The terms that mattered at purchase can change at the next renewal, and the change is usually communicated by email rather than negotiated.
Frequently asked questions
What should we ask an AI vendor before using their tool?
Seven things: processing location, retention, training use, vendor-side access, export and deletion, the accuracy and verification position, and liability and breach notification.
Are free AI tools safe for business use?
Generally not for confidential data. Consumer tiers frequently retain input, may use it for training, and rarely offer a data processing agreement. Business tiers with those settings disabled are a different proposition.
Do we need a data processing agreement?
Where the tool processes personal data, yes — and many vendors offer one only on business plans. Confirm the position rather than assuming it.
How often should we re-assess an AI tool?
At least annually, and after any material change in the vendor’s terms, ownership or processing location. Re-check retention and training use specifically.
What if the vendor will not answer the questions?
Treat that as an answer. Use the tool only for data you would be comfortable publishing, or choose a different tool.
Is it worth paying for the enterprise tier?
Usually yes for the main assistant. It is the cheapest way to convert a policy statement about retention and training into a contractual one, and it is often the difference between a tool being usable on real work and not.
Who should run the assessment?
Whoever owns the data rule, with finance or operations confirming the contract terms. Where there is no such owner, the person accountable for client data should run it, and the policy should name them.
Should we re-assess a tool after it changes hands?
Yes. A vendor acquisition, a terms update or a change in processing location can alter the position entirely, and the change is usually communicated by email rather than negotiated with you.
Should the assessment be repeated when we add a new use case?
Yes, where the use case involves a new data category. A tool may be approved for internal documents and not for client material, and the approval should state which categories it covers.
Next step
Run the seven questions against the tools you already use, record the answers, and confirm retention and training settings on your main assistant. See Data Security and Confidentiality in AI Tools and the AI Tool Selection Matrix, or book an AI adoption call to run the assessment with you.
Sources
- Due-diligence questions reflect standard vendor-assessment practice applied to AI tools, with retention, training use and processing jurisdiction added as the decisive criteria.
No statistic in this article is invented; where figures appear in the linked guides, they are cited there with their source and date. This article is general information, not legal advice.