Quick answer: Before a small team pays for or trusts an AI vendor, write down the exact use, data, integrations, actions, and possible harm. Then collect dated evidence about the supplier, data flow, security, contract, support, product changes, incident notice, export, deletion, and fallback. An unanswered material question is not an automatic pass.
Checked July 17, 2026. This checklist supports an internal review. It is not a security audit, certification, procurement decision, or substitute for legal, privacy, security, accessibility, or sector-specific advice.
Key takeaways
- Define the use case before comparing vendors.
- Record evidence URLs, dates, owners, and unanswered questions.
- Check the full service chain, including models, subprocessors, connectors, and plug-ins.
- Contract, incident, support, export, deletion, and fallback terms matter after the demo ends.
- Approve with conditions, accept a documented risk, ask for expert review, or stop—do not hide uncertainty inside a score.
Start with the intended use
- What task will the tool perform?
- Who will use it, and who may be affected?
- What customer, employee, confidential, or regulated data could enter it?
- What systems, files, inboxes, accounts, or actions can it access?
- What is the worst plausible failure?
- Which claims or controls must be true before use?
A vendor can look suitable for generic drafting and still be unsuitable for customer records or automated account changes. Scope the review to the real workflow.
The evidence checklist
| Area | Evidence to collect | Questions to resolve |
|---|---|---|
| Supplier and dependencies | Legal entity, product owner, model/API providers, subprocessors, connectors, service locations | Who actually handles the service and data? |
| Data flow | Inputs, outputs, logs, retention, training use, deletion, location, access, backups | Where does data go, why, for how long, and who can see it? |
| Security | Current controls, access options, vulnerability process, independent reports where appropriate, incident contacts | Is the evidence current and relevant to this product and plan? |
| Product limits | Intended use, excluded use, evaluation evidence, known failure modes, documentation version | What has not been tested or promised? |
| Contract and rights | Confidentiality, ownership, permitted use, service level, support, renewal, termination, material-change notice | Do the written terms match the sales answer? |
| Operations | Admin roles, logs, exports, monitoring, status history, incident notice, human support | Can the team investigate and respond when something goes wrong? |
| Exit and fallback | Export format, deletion confirmation, transition help, manual fallback, replacement dependencies | Can the team leave without losing essential records or operations? |
Keep an evidence register
| Question | Source | Checked | Owner | Status |
|---|---|---|---|---|
| Are prompts used for training? | Exact plan terms or provider response | Date | Name/role | Answered, unclear, or unanswered |
| How is data deleted? | Documentation and contract | Date | Name/role | Verified or follow-up |
| What happens during an outage? | SLA, support, and fallback plan | Date | Name/role | Accepted or blocked |
Save the exact page or document, not only a salesperson’s summary. If the evidence changes by account type or plan, record the plan you will actually buy. Separate a provider statement from independent assurance and from your own test result.
What to do with unanswered questions
- Ask: request a written answer or contract term.
- Limit: approve only a lower-risk use with non-sensitive data.
- Escalate: get legal, security, privacy, accessibility, or sector review.
- Accept: name the owner and record why the remaining risk is tolerable.
- Stop: do not buy or connect the tool when a required control cannot be verified.
Due diligence continues after purchase
Monitor material changes to terms, ownership, subprocessors, model behavior, pricing, privacy, security, integrations, and support. Recheck access and logs. Test the fallback. Record incidents and user complaints. A one-time questionnaire cannot cover a changing service.
Limitations
This checklist cannot verify that a vendor follows every promise or uncover every technical weakness. Evidence may be incomplete, plan-specific, confidential, or outdated. High-impact or regulated uses require qualified review. Avoid compressing different risks into one vendor score or “approved” badge.
Related guides
Use this with the plain-English assistant comparison, AI Privacy Checklist, customer-data guide, AI Tools, and AI for Small Business.

