Wrivio
Get Wrivio
7 min readBy Wrivio Team

How to Audit an AI Vendor in 2026

Most AI vendor assessments consist of reading the privacy page and forwarding it to whoever asked. The privacy page is written by marketing and says the things privacy pages say, which is why it answers nothing you actually need to know.

Here are nine questions that produce specific answers, and what each one is really testing. Send them in writing, and treat a non-answer as an answer.

The Nine Questions

1. In which countries is inference for our account physically executed?

Tests whether they know, and whether it is contractually fixed. “We use global infrastructure” means it can change without telling you, which for a European or regulated organization is the end of the conversation rather than a detail.

2. What is the retention period for prompt and completion content, and is it configurable to zero?

Tests whether zero retention is available and whether it is default or opt-in. Zero-retention configurations are real and they are settings, which means they can be scoped narrowly, misconfigured, or reset during a migration. Ask what falls outside the zero-retention scope, because something usually does. See what zero data retention actually means.

3. Which legal entity is the data controller or processor, and under which jurisdiction’s law would a disclosure request be processed?

Tests jurisdictional exposure, which residency alone does not settle. A provider incorporated outside your region may be subject to its home jurisdiction’s process regardless of where the servers sit.

4. List every subprocessor that may access content, including model providers and observability tooling.

Tests supply-chain visibility. Many AI products are wrappers around another lab’s API, plus logging and monitoring services. Each link is a place your text can be stored. A vendor that cannot produce this list does not know their own chain.

5. Is our content used for training, evaluation, or human review, under any circumstances?

Tests the exception you were not told about. “We do not train on customer data” frequently coexists with human review of flagged content for safety purposes, which is a person reading your text.

6. What is your process and notification timeline for a security incident affecting our content?

Tests incident maturity. A vendor without a defined timeline has not thought about it, and you will discover their process during your own incident.

7. What happens to our content when we terminate?

Tests deletion. Ask for the timeline, whether it covers backups, and whether you receive confirmation.

8. Which model versions serve our requests, and how are we notified of changes?

Tests behavioral stability and your ability to keep records. Silent model swaps behind a stable label are common, and they change your output without changing your prompts. See what to do when your AI model is deprecated.

9. Can you provide your most recent independent security assessment and, for general-purpose model providers, your model documentation?

Tests whether there is anything to show. Under the EU AI Act, general-purpose AI obligations and enforcement powers took effect on 2 August 2026, so documentation should exist for serious providers.

Reading The Answers

The pattern matters more than any individual response.

Specific and contractual is what you want: a named country, a numeric retention period, a subprocessor list with entity names, a stated notification window.

Specific but unfavorable is workable. A vendor who says content is retained for thirty days and cannot be configured to zero has told you something true, and you can decide accordingly.

Vague is the finding. “We use industry-leading security practices” in response to question four is not an answer, and the absence of an answer to a question about subprocessors usually means nobody has assembled the list.

Defensive is worth noting. Vendors accustomed to enterprise procurement answer these routinely. A vendor who treats them as adversarial is telling you about their customer base.

Sending It Without Sounding Hostile

These questions are pointed, and they should be, but the framing determines whether you get a useful reply or a call from an account manager.

Before:

Just wanted to check whether our data is safe with you and whether you keep it. Also is it GDPR compliant? Thanks!

After:

We are completing a vendor assessment ahead of expanding our usage and need written answers to the following for our records.

  1. In which countries is inference for our account physically executed?
  2. What is the retention period for prompt and completion content, and can it be configured to zero? Please note anything excluded from that configuration.
  3. Which legal entity acts as processor, and under which jurisdiction’s law would a disclosure request be processed?
  4. Please provide a list of subprocessors that may access content, including model providers and monitoring services.
  5. Is our content used for training, evaluation, or human review under any circumstances?

Our procurement timeline requires responses by 14 August. We are happy to sign a mutual NDA if any answer is commercially sensitive.

The second version gets answered because it looks like a process rather than a complaint, it has a deadline, and it removes the confidentiality excuse in advance.

A Wrivio Context for procurement correspondence could say:

Rewrite this as a formal procurement enquiry. Professional register, complete sentences, no contractions. Number the questions. Keep every jurisdiction, retention term, date, and technical detail exactly as written. Do not soften direct questions into hints, and do not add pleasantries that dilute the ask.

Press Ctrl+Shift+Space, paste your blunt draft, and read the diff. Softening pointed questions is the standard failure of an unconstrained assistant, and a softened question gets a softened answer.

The Assessment That Does Not Need Doing

Worth noting for perspective: this entire exercise exists because a third party is processing your text.

For a locally executed model, most of these questions do not apply. There is no inference location, no retention period, no subprocessor chain, no training question, and no termination deletion, because no content was transmitted. What remains is much smaller: which model version, under which license, verified against which checksum.

That is not an argument for local-only. It is an argument for shrinking the surface that needs auditing. Every category of work you keep local is a category you do not have to paper, which is the cheapest compliance available. See which tasks should stay local.

Keep The Answers

Whatever you learn, record it: the questions, the answers, the date, and who provided them. A vendor’s answer in July 2026 is not their answer in July 2027, and the record is what lets you notice the change.

This also answers the question a client or auditor will eventually ask, which is not “is your vendor secure” but “what did you check and when.” There is a process in how to document your AI workflow for an auditor.

Common Questions

Is this overkill for a small business?

The nine questions take twenty minutes to send. If you handle client, patient, or financial data, the assessment is proportionate to your obligations rather than to your headcount.

What if the vendor will not answer?

That is a finding, and it should be recorded as one. A vendor unwilling to state their retention period in writing has answered the question.

Do these questions apply to a local tool?

Most do not, because nothing is transmitted. Ask instead which model and license it uses, whether downloads are checksum-verified, and whether any network request accompanies processing. Then verify by disconnecting the network.

How often should we re-run this?

Annually, and whenever a vendor announces an acquisition, a major product change, or a new subprocessor. Acquisitions in particular tend to change data-handling terms.

Download Wrivio for Windows to move confidential work into a configuration where most of these questions do not arise.