Pull up your vendor security questionnaire and search it for the word “AI.” For most mid-size organizations I work with, the search comes back empty. The questionnaire was written years ago, it runs to a couple of hundred questions about encryption, backups, and penetration tests, and it was a perfectly good document for the software of its time.
Here’s the problem. The vendor answers all of those questions, you approve them, and some months later they ship an AI assistant inside the product. It’s on by default. It sends your data to a model provider you’ve never heard of. Nothing in your review covered it, because nothing in your review knew to ask. An AI vendor security questionnaire doesn’t need to be longer than the one you have. It needs two questions your current one is missing.
Why a standard review misses AI risk
Traditional vendor reviews ask where your data is stored and who can access it. AI changes three things those questions don’t catch:
- New data flows. AI features often send your content to a third-party model provider. That provider is a subprocessor, and it may not have been on the list you reviewed.
- New uses of your data. Prompts, files, and outputs might be retained, logged, or used to improve models. Whether they are is a contract question, not a marketing one.
- New ways to be attacked. An AI feature that reads documents or email can be manipulated by content inside them. Prompt injection sits at the top of the OWASP Top 10 for Large Language Model Applications for a reason: it can turn a helpful feature into a data leak.
Here’s how the assessment asks the question, and the 0 to 4 ladder I score it against:
S4. Before adopting an AI tool or AI feature, do you review how the vendor handles your data?
- No review
- Ad hoc, when someone thinks to ask
- Standard vendor security review, nothing AI-specific
- Vendor review includes AI questions (training on our data, retention, data residency)
- Formal AI risk assessment, including AI-specific threats such as prompt injection
Most teams with a working vendor process sit at level 2. The two questions below move you to level 3, and the second one, asked properly, gets you most of the way to 4.
The asset: two questions and their follow-ups
Add these to your questionnaire as a short AI addendum. Each has a headline question for the vendor and follow-ups that make the answer specific enough to act on.
Question 1: What happens to our data when your AI features use it?
- Is any of our data (inputs, files, outputs, or usage data) used to train or improve models, yours or a third party’s? Where in the contract is that stated?
- Which third-party model providers process our data, and are they listed as subprocessors?
- How long are prompts and outputs retained, and can we shorten that or turn retention off?
- In which regions is AI processing performed, and does that match the data residency commitments in our agreement?
- Are AI features on by default? Can an administrator turn them off for the whole organization, or for specific groups?
Question 2: What can your AI do on our behalf, and how do you stop it being used against us?
- What data can the AI read, and what actions can it take: read only, draft, send, create or modify records?
- Does it respect our existing user permissions, or does it have its own broader access?
- How do you defend against prompt injection from content inside our documents, email, or tickets, and do you test for it?
- Are AI actions and prompts logged, and can we get those logs?
- How will you notify us of new AI features, or changes to your AI terms, before they reach our users?
Ten follow-ups in total. That’s short enough that vendors will actually answer it, and sharp enough that vague answers stand out.
A decision rule for the answers
Collecting answers is only useful if they change decisions. I give teams a simple red, yellow, green rule:
- Red: don’t approve for confidential data. The vendor trains on customer data with no contractual opt-out, can’t name its model providers, or offers no way to turn AI features off.
- Yellow: approve with conditions. The answers are acceptable but depend on configuration, such as retention that must be shortened or features that must be disabled for some groups. Record the conditions and who checks them.
- Green: approve. No training on your data by contract, named subprocessors, admin controls, permission-aware access, and logs you can get.
A red answer doesn’t always mean “no.” It usually means “not with that data.” A vendor can be red for customer records and fine for marketing copy, and the review should say so.
Don’t forget the AI you already bought
The bigger exposure for most teams isn’t the next vendor. It’s the SaaS tools already in place that have added AI features since you reviewed them. A focused catch-up takes a few weeks:
- List your top ten SaaS vendors by the sensitivity of the data they hold.
- For each one, check the vendor’s trust center or AI documentation and answer the two questions yourself from what’s published. Many vendors now publish this.
- Send the addendum only where the published answers are missing or unclear.
- Record the results in your AI inventory. If you don’t have one yet, building an AI inventory in two weeks covers how, and this review gives you a head start on it.
When to ask
Timing matters as much as the questions. Ask them at three points: before a trial that uses real company data, before contract signature, and at every renewal. The trial is the one teams skip, and it’s where most exposure starts, because “just testing it” usually means testing it on a real customer file. Put the two questions into your trial request form so nobody can start a pilot without answering them, even roughly. A rough answer at trial time is worth more than a perfect one after the data is already in the vendor’s system.
Mistakes I see at this stage
Accepting “we don’t train on your data” from a sales call. That sentence means nothing until it’s in the contract or the data processing terms. Ask where it’s written.
Reviewing once. AI features and terms change faster than any other part of a vendor’s product. Make “vendor adds or changes AI features” a trigger for a short re-review, and ask vendors to notify you (that’s the last follow-up in question 2).
Skipping free tools. Free AI tools usually have the least favorable data terms and never go through procurement, which is exactly why they need a lightweight review. The difference between consumer and enterprise terms is covered in consumer AI vs. enterprise AI.
Making the questionnaire longer. The instinct is to add forty AI questions. Vendors will answer them with boilerplate. Two sharp questions with specific follow-ups get better answers.
Reviewing the vendor but not the access. A vendor can pass the review and still get more access than it needs through a broad OAuth grant. Pair the review with the consent controls in identity is your AI control plane.
Where does your team actually stand?
AI vendor review is one of 24 questions in the AI Readiness assessment, which covers six dimensions: data, security, infrastructure, skills, use cases, and governance. The free version is 10 questions and gives you a score in a few minutes.
Get your free AI Readiness Score →
Want to see what the full assessment covers first? Flip through a complete 38-page sample report.
Related guides
- Build Your AI Inventory in Two Weeks (Auditors Will Ask)
- Consumer AI vs. Enterprise AI: Ending the Evaluation Stall
- Identity Is Your AI Control Plane: SSO, RBAC, and Access Reviews
- The 6-Dimension AI Readiness Framework, Explained
- The AI Readiness Checklist: 24 Questions to Answer Before Spending a Dollar
Frequently asked questions
What AI questions belong in a vendor security review?
Two headline questions: what happens to our data when your AI features use it, and what can your AI do on our behalf and how do you stop it being used against us. The follow-ups cover training on your data, subprocessors, retention, admin controls, permissions, prompt injection, and logs.
Is a vendor saying it doesn't train on our data enough?
No. Ask where that commitment is written in the contract or the data processing terms. Statements made in a sales conversation aren't enforceable, and the terms for AI features change more often than any other part of a vendor's product.
What is prompt injection?
Prompt injection is when instructions hidden in content an AI reads, such as a document, email, or web page, manipulate the AI into doing something it shouldn't. It is listed first in the OWASP Top 10 for Large Language Model Applications.
Do we need to re-review vendors we already use?
Yes, at least for your most sensitive SaaS tools. Many vendors have added AI features since your last review, sometimes switched on by default. Start with your top ten vendors by data sensitivity and check their published AI documentation first.




