AI Vendor Due Diligence: The 12 Questions Every SMB Should Ask in 2026
Most AI incidents at small and mid-sized companies start with a vendor, not a model. Here is the due diligence set we run before any AI tool touches regulated data.
Last updated:
Almost every AI risk review we run at a small or mid-sized company ends in the same place: the model is fine, the vendor is the problem. Data is being retained longer than the contract implies, sub-processors are undisclosed, or an "enterprise" plan quietly trains on customer prompts.
Below is the diligence set we run inside Meridian Governance™ before an AI tool is approved for regulated or customer data. It maps to NIST AI RMF (GOVERN and MAP) and to the vendor-management expectations in SOC 2 and HIPAA.
Data handling
- Is our input data used to train or fine-tune any model, on any plan? Get it in writing, not in a marketing FAQ.
- What is the retention period for prompts, outputs, and logs, and can it be set to zero?
- Which regions do inference and storage happen in?
- Who are the model sub-processors, and are we notified before they change?
Security posture
- Do you hold a current SOC 2 Type II or ISO 27001 certificate — and does the scope actually cover the AI product?
- Is SSO plus MFA available on our tier, or gated behind an enterprise upsell?
- How are API keys and service credentials scoped and rotated?
- Will you sign a BAA (healthcare) or DPA with the required transfer mechanism?
Model behaviour and accountability
- What evaluation results can you share for accuracy, bias, and refusal behaviour on tasks like ours?
- How are model version changes communicated, and can we pin a version?
- What human-review controls exist for consequential outputs?
- What is the incident notification window for a security or model-integrity event?
Turning answers into a control
Answers age quickly. Treat the questionnaire as a recurring control rather than a one-time purchase gate:
- Record each answer against the vendor record, with a review date.
- Score the vendor and attach the score to the system it supports, so an audit can trace tool to risk to owner.
- Re-run diligence when the vendor ships a major model change or when your use case widens.
Companies using the Meridian Suite get this as a tracked workflow: each AI system carries its vendor evidence, its owner, and its contribution to the Senticit Intelligence Score, so gaps surface before a customer security review does.
This article is part of our comprehensive AI & Automation guide.
Read the complete guide →