Skip to main content
    AI & Automation

    AI Vendor Due Diligence: The 12 Questions Every SMB Should Ask in 2026

    Most AI incidents at small and mid-sized companies start with a vendor, not a model. Here is the due diligence set we run before any AI tool touches regulated data.

    James Tuttle·Founder & Principal Consultant
    2 min readAI vendor due diligence, AI risk assessment, NIST AI RMF

    Last updated:

    Almost every AI risk review we run at a small or mid-sized company ends in the same place: the model is fine, the vendor is the problem. Data is being retained longer than the contract implies, sub-processors are undisclosed, or an "enterprise" plan quietly trains on customer prompts.

    Below is the diligence set we run inside Meridian Governance™ before an AI tool is approved for regulated or customer data. It maps to NIST AI RMF (GOVERN and MAP) and to the vendor-management expectations in SOC 2 and HIPAA.

    Data handling

    1. Is our input data used to train or fine-tune any model, on any plan? Get it in writing, not in a marketing FAQ.
    2. What is the retention period for prompts, outputs, and logs, and can it be set to zero?
    3. Which regions do inference and storage happen in?
    4. Who are the model sub-processors, and are we notified before they change?

    Security posture

    1. Do you hold a current SOC 2 Type II or ISO 27001 certificate — and does the scope actually cover the AI product?
    2. Is SSO plus MFA available on our tier, or gated behind an enterprise upsell?
    3. How are API keys and service credentials scoped and rotated?
    4. Will you sign a BAA (healthcare) or DPA with the required transfer mechanism?

    Model behaviour and accountability

    1. What evaluation results can you share for accuracy, bias, and refusal behaviour on tasks like ours?
    2. How are model version changes communicated, and can we pin a version?
    3. What human-review controls exist for consequential outputs?
    4. What is the incident notification window for a security or model-integrity event?

    Turning answers into a control

    Answers age quickly. Treat the questionnaire as a recurring control rather than a one-time purchase gate:

    • Record each answer against the vendor record, with a review date.
    • Score the vendor and attach the score to the system it supports, so an audit can trace tool to risk to owner.
    • Re-run diligence when the vendor ships a major model change or when your use case widens.

    Companies using the Meridian Suite get this as a tracked workflow: each AI system carries its vendor evidence, its owner, and its contribution to the Senticit Intelligence Score, so gaps surface before a customer security review does.

    Share

    This article is part of our comprehensive AI & Automation guide.

    Read the complete guide →