
How to Assess the Security of AI Vendors Before You Buy
Assessing the security of AI vendors comes down to one dealbreaker question and four due-diligence ones. The dealbreaker: does your client data train their models? If the answer is yes, or vague, or "let me check with engineering," the evaluation is over. The other four: where does the data live, who can reach it, what independently verifies the security claims, and what happens to your data when you leave. A firm that gets straight written answers to those five can adopt AI tools with a clear conscience. A firm that doesn't ask is doing due diligence by vibes.
And plenty are. The productivity gains from AI document processing and drafting are real, the demos are dazzling, and the contract gets signed before anyone reads the data processing terms. Slow down for one week. That's all this takes.
Why AI vendors get extra homework
Your practice management vendor has been through twenty years of security maturation, audits, and customer scar tissue. The AI vendor pitching you was founded eighteen months ago. That's not a reason to refuse, but it's a reason to check, because youth shows up in specific ways.
The tools are data-hungry by design; they work by reading the documents you feed them, so the data flow question can't be waved off. Processing happens in someone's cloud, sometimes across regions your clients' regulators care about. Early-stage security programs can lag far behind early-stage engineering. And startups die or get acquired, at which point "where does our client data go in the asset sale" becomes a very uncomfortable question to be asking for the first time.
The training question, in writing
This one gets its own section because it's the one that ends evaluations. Some AI products improve their models using customer inputs, which means fragments of what you upload could influence outputs shown to strangers. For a firm handling tax returns or privileged documents, that's disqualifying.
What you want is a written commitment, in the contract or terms of service, that customer data isn't used for training, ideally alongside a zero-retention processing option. Not a salesperson's reassurance on a call. Terms change, salespeople move on, and "they told us it was fine" has never once impressed a regulator.
Where the data goes and how it comes back
Ask for the map. Which regions, on whose infrastructure, retained for how long after processing. Ask who the subprocessors are, because your data's security now includes every vendor your vendor uses. And ask about the exit: can you export everything, does deletion happen on a defined timeline, will they certify it? A vendor with good answers has thought about your data's whole life. A vendor without them is improvising with your clients' files.
Proof beats promises
A SOC 2 Type II report is the standard ask: it shows an auditor watched the vendor's controls operate over months, not that a marketing page says "bank-level security." ISO 27001, regular third-party penetration testing, and a real breach notification commitment with timelines all count in the same direction.
A young vendor without certifications isn't automatically insecure. But it means you're taking their word for everything, and their word should be priced accordingly. Confine uncertified tools to low-stakes data, or wait.
The boring basics still apply
SSO support, enforced MFA, role-based permissions, audit logs showing who accessed what. Encryption at rest and in transit with grown-up standards. None of this is AI-specific, which is exactly the test: a vendor that fumbles the settled parts of security will not be handling the novel parts well. It's the same standard you'd apply to your own retention, access, and encryption practices, pointed outward.
Match the scrutiny to the stakes
An AI meeting scheduler that sees names and calendars doesn't need the full interrogation. A tool that reads client tax returns needs every question on this page answered in writing. Build one standard questionnaire, fifteen or twenty questions across the areas above, and send it to every AI vendor before any pilot touches real client data. Vendors who sell to professional firms answer these routinely. A vendor who bristles at reasonable security questions has answered the most important one.
Then re-check annually. Terms of service drift, and the training clause is where they drift first. Vendor oversight that starts strong and lapses is one of the most common compliance gaps in professional firms, and AI subscriptions multiply faster than any vendor list a firm has managed before.
Red flags that end the conversation
Vague answers about data handling. Training on customer data with no opt-out. No certifications and no timeline for any. Terms that disclaim all liability for breaches of the very data the product exists to process. No deletion path when you leave. Any one of these, on its own, is enough. You're not obligated to talk a vendor into deserving your clients' files.
Your own side of the street
Vendor scrutiny only means much if your own house is in order, because attackers don't care whether the unlocked door was yours or a supplier's. Keep the assessment habit inside your broader cybersecurity checklist, and if you'd like a second set of eyes on a vendor decision, or on the environment you'd be plugging it into, our free cybersecurity trial is built for exactly that first look.
The rest of the framework, including how vendor risk fits alongside every other kind, is in our cybersecurity guide for firms. AI tools are worth adopting. They're just not worth adopting unread.



