Artificial intelligence is becoming part of everyday business operations, but choosing an AI vendor requires more than comparing features and pricing. Once an AI system processes company or customer information, businesses need to understand exactly how that data is handled.
AI Due Diligence is the process of evaluating an AI system, model, or vendor before allowing it to process business information. It should cover data handling, privacy, security, compliance, model behavior, deployment, retention, and third-party access.
Why AI Due Diligence Matters
Traditional software due diligence usually focuses on functionality, security, uptime, integrations, and vendor reliability. AI introduces additional questions because AI systems can process prompts, documents, conversations, source code, customer records, and other unstructured information.
An AI vendor may also rely on third-party foundation models, cloud providers, analytics platforms, and other subprocessors. This creates additional points where sensitive information can be accessed, transferred, stored, or retained.
A business may therefore approve an AI application without realizing that its data is being processed by several organizations.
AI Due Diligence helps identify these risks before deployment rather than after an incident, audit finding, or compliance problem.
1. Define the AI Use Case
The first step is understanding why the organization wants to use the AI system.
An AI tool used to summarize public information has a very different risk profile from an AI application processing financial records or confidential customer documents.
Businesses should identify what the system will do, what information it needs, who will use it, and what decisions or workflows depend on its output.
The sensitivity of the intended use case should determine how detailed the vendor assessment needs to be.
2. Understand the AI Model
Businesses should identify which model powers the product.
Is it a proprietary model, an open-source model, or a third-party foundation model?
If the vendor relies on another AI provider, the organization’s due diligence should extend beyond the primary vendor. The underlying model provider may have its own data-processing practices, retention policies, and contractual terms.
Understanding the technology stack makes it easier to identify where additional data exposure could occur.
3. Map the Complete Data Flow
Data flow is one of the most important areas of AI Due Diligence.
Businesses should understand what happens when a user submits a prompt or uploads a document.
Does the information go directly to a third-party model? Is it processed by the vendor first? Are uploaded documents cached? Are prompts and responses stored in logs? Can subprocessors access the information?
A simple data-flow map can reveal risks that are not obvious from a product’s marketing material.
The goal is to understand where information goes from the moment it enters the AI system until it is deleted.
4. Check How Sensitive Data Is Protected
AI applications can process personally identifiable information, financial data, healthcare records, intellectual property, employee information, and confidential business documents.
Businesses should determine whether sensitive information can be minimized, redacted, masked, or anonymized before it reaches the AI system.
This can reduce exposure because the AI model receives less sensitive information in the first place.
For organizations operating in regulated industries, privacy protection should be considered part of the architecture rather than an afterthought.
5. Ask Whether Data Is Used for Training
One of the most important questions in AI Due Diligence is whether customer data is used to train or improve AI models.
Businesses should never assume that their information is automatically excluded from training.
The vendor should clearly explain whether prompts, documents, conversations, outputs, or other customer information can be used for model training or fine-tuning.
This should be confirmed in writing through appropriate contractual terms rather than relying only on statements made during a sales discussion.
6. Evaluate Security Controls
Generic claims such as “enterprise-grade security” are not enough.
Businesses should ask specific questions about encryption, authentication, access controls, identity management, logging, vulnerability management, and independent security assessments.
Relevant documentation may include security reports, certifications, and other evidence demonstrating how the vendor protects customer information.
The assessment should focus specifically on the AI workflow being adopted rather than treating security as a general checkbox.
7. Review Compliance Requirements
AI vendor assessment should reflect the organization’s actual regulatory obligations.
Depending on the industry and location, this could involve GDPR, HIPAA, financial-sector requirements, contractual obligations, data-processing agreements, or data residency requirements.
Businesses should determine whether the vendor can support these requirements through appropriate technical controls, documentation, and contractual protections.
A vendor describing itself as “compliant” does not automatically mean that its solution satisfies the organization’s specific obligations.
8. Check Deployment and Data Residency
Where AI processing occurs can significantly affect risk.
Businesses should determine whether the system operates in a public cloud, private cloud, dedicated environment, or on-premises infrastructure.
They should also understand where data is stored and processed and whether information crosses international borders.
For regulated organizations, data residency requirements may determine which deployment models are acceptable.
Private or on-premises deployment can provide greater control over sensitive AI processing when organizational requirements demand it.
9. Investigate Subprocessors
AI vendors often depend on multiple third parties.
These may include cloud infrastructure providers, foundation model providers, analytics platforms, monitoring services, and other technology vendors.
Businesses should request an up-to-date subprocessor list and determine what information each provider can access.
They should also understand how they will be notified when a vendor adds or changes subprocessors.
Evaluating only the primary AI vendor can leave significant gaps in the assessment.
10. Review Data Retention and Deletion
Businesses should know how long prompts, uploaded files, outputs, logs, and other information remain available.
Important questions include whether information can be deleted on request, how backups are handled, and whether deletion extends to relevant subprocessors.
Retention policies should be clearly documented.
An organization should not discover months after deployment that sensitive prompts or uploaded documents remain stored in systems it did not know existed.
11. Look for AI Vendor Red Flags
Several warning signs should trigger additional investigation.
A vendor that cannot clearly explain its data flow presents a significant concern. Vague statements about model training should also be investigated.
Other red flags include unclear retention periods, unexplained third-party access, missing subprocessor information, limited deletion capabilities, and a lack of options for anonymizing or redacting sensitive information.
Generic security claims without supporting documentation are another warning sign.
Transparency is an important indicator of vendor maturity.
12. Use a Practical AI Due Diligence Checklist
Before approving an AI vendor, businesses should ask:
- What information does the AI system process?
- Where is that information processed?
- Does data cross international borders?
- Is customer information retained?
- How long is information retained?
- Is customer data used to train models?
- Who can access the information?
- Which subprocessors are involved?
- Can sensitive information be anonymized or redacted?
- Where is the AI system deployed?
- Can information be deleted on request?
- What happens to prompts, files, outputs, and logs?
- How are customers notified about architectural or subprocessor changes?
Documenting the answers creates a useful record for security, privacy, legal, procurement, and compliance teams.
How Questa AI Can Reduce Data Exposure
Due diligence is important, but organizations can also reduce risk by limiting the sensitive information that reaches an external AI system.
Questa AI takes a privacy-first approach by providing technologies designed to anonymize sensitive information before it reaches AI systems. Its Blackbox and Developer API offerings can sit between organizational data and AI workflows, helping protect sensitive fields before external model processing.
This approach can complement vendor due diligence.
Instead of relying entirely on an AI vendor’s downstream protections, organizations can reduce the amount of sensitive information exposed in the first place.
For businesses handling confidential or regulated information, this can provide an additional layer of control.
AI Due Diligence Should Be Ongoing
AI Due Diligence should not end when a vendor contract is signed.
AI vendors can change their models, infrastructure, subprocessors, retention policies, and product capabilities.
The organization’s own use of the AI system can also expand. A tool initially used for simple document summarization might later become connected to customer databases or business-critical workflows.
Businesses should therefore reassess AI vendors periodically and whenever significant changes occur.
AI Due Diligence works best as a continuous process involving security, IT, privacy, legal, procurement, compliance, and the business team responsible for the AI application.
Conclusion
AI adoption can create significant business value, but organizations need to understand what happens to their information before trusting an AI system with sensitive data.
Effective AI Due Diligence should examine the complete AI ecosystem, including the use case, model, data flows, training practices, security controls, compliance requirements, deployment location, subprocessors, retention, and deletion.
The most important question is simple:
What happens to our data when we use this AI system?
Businesses that answer that question before deployment are better positioned to adopt AI while maintaining control over privacy, security, and compliance.
With a privacy-first approach, Questa AI can complement this process by helping organizations reduce sensitive data exposure before information reaches AI systems.