CanucktAI
Back to Blog
Data Risk August 18, 2026 9 min read

AI Vendor Risk: 12 Questions to Ask Before You Buy

Buy an AI tool and you inherit whatever it does with data. These twelve questions drag the risks into the open — the ones a slick demo would rather you skipped — before your client data ends up somewhere you can't see it.

By Vivek Chakravarthy

AI Vendor Risk: 12 Questions to Ask Before You Buy

Before you sign, ask an AI vendor how it uses your data, who its sub-processors are, where data lives and for how long, whether it'll sign a data processing agreement, what security it holds, and which model actually runs it. PIPEDA keeps you accountable for personal information even after it lands in a vendor's systems — which makes this homework yours, not theirs. Here are the twelve questions that drag out the risk a demo is built to hide.

Buying an AI tool isn't like buying a stapler. Hand a vendor your customers' names, your staff records, or a client's confidential file and you've just stretched your own privacy obligations over a company you might know almost nothing about. PIPEDA's accountability principle doesn't come along for free: the data stays your responsibility even after it leaves the building, even though the processing didn't.

Most procurement calls skip right past this. The demo lands, the price looks fair, everyone wants to move. But the questions that actually protect you rarely show up on the sales deck. Here are twelve to ask before you sign, plus what a decent answer sounds like.

1. Do you use our data to train your models?

This is the one that matters most, and the one vendors have the most practice dodging. You want a flat, written "no" covering both your inputs and your outputs — or, if it's a yes, an opt-out that's off by default rather than buried three menus deep. "We may use aggregated, de-identified data to improve our services" is a yellow flag worth leaning on: ask which de-identification method they use, and whether it can be reversed.

2. Who are your sub-processors?

Almost no AI vendor runs on its own infrastructure alone. There's a foundation-model provider underneath, a cloud host, an analytics tool, maybe a support platform — and every one of them is a sub-processor that will touch your data. Ask for the current list. Ask how you'll hear about changes. Ask whether you can object to a new one. A vendor that can't hand you that list hasn't mapped its own data flows, which tells you something.

3. Where is our data stored and processed — physically?

"The cloud" isn't an answer. You want a country, ideally a region. It bears directly on your PIPEDA cross-border transfer obligations, and if you've got Quebec customers, on Law 25's expectations for sending data outside Quebec. A vendor that offers Canadian data residency as an option is worth paying a bit more for when your data is sensitive.

4. How long do you retain our data, and what happens when we leave?

Get the retention period in writing, and ask specifically what happens to your data when you walk. Can you export everything in a format you can actually use? Is deletion confirmed — and does it reach the backups and any copies sitting with sub-processors? Indefinite retention "for service improvement" is a quiet default that works against you.

5. Will you sign a Data Processing Agreement?

A proper DPA — or, in Quebec, a written agreement that meets Law 25's transfer requirements — is the spine of the whole relationship. It should tie the vendor to purpose limitation, security obligations, breach-notification timelines, and sub-processor controls. A vendor that treats a DPA as a strange request is one that hasn't sold to privacy-conscious buyers before.

6. How and when will you notify us of a breach?

You can't meet your own PIPEDA breach obligations if your vendor sits on bad news. Ask for a defined notification window — measured in hours, not "promptly" — and ask exactly what you'll be told. You're the one who has to run the real-risk-of-significant-harm assessment, and you can't do it on rumours.

7. What security controls and certifications do you hold?

SOC 2 Type II and ISO 27001 are the usual baselines. For AI specifically, ISO 42001 — the AI management system standard — is turning into a real signal that a vendor governs its models and not just its servers. Ask for the actual report or certificate. A logo on the website isn't evidence.

8. Is our data encrypted, in transit and at rest?

This should come back as a fast, confident yes. Then push on key management: who holds the encryption keys, and could the vendor read your data if a foreign court compelled it? For sensitive workloads, that last question can decide the whole thing.

9. Who at your company can access our data, and how is that controlled?

Ask about internal access controls, logging, and whether staff can see customer data in the clear. "Only for support, only with your permission, and it's all logged" is a healthy answer. "Our engineers can see everything" is not.

10. What model powers this, and where does it come from?

Model provenance is the newest question and the one people skip. Is the underlying model built in-house, licensed from a major provider, or an open-weights model the vendor hosts itself? Each carries different data-flow and reliability implications. You're entitled to know whose model is reading your data — and a vendor who gets cagey here is answering the question anyway.

11. Can we get an audit trail of what the AI did?

If the tool makes or shapes decisions about people — screening resumes, flagging transactions, ranking support tickets — you may have to explain those decisions down the road. Ask whether it logs inputs, outputs, and the basis for its outputs in a form you can actually pull later.

12. What happens if you're acquired or shut down?

Vendors get bought. Vendors go under. Ask what happens to your data either way, whether you get any warning, and how you get your data out. It's the awkward question to raise and the painful one to have skipped.

What do good and bad answers look like?

The words a vendor reaches for are a signal all on their own. A quick way to sort what you hear:

TopicGreen flagRed flag
Training on your dataWritten "no," opt-out off by default"We may use aggregated data to improve services"
Sub-processorsCurrent list, notice on changeCannot produce a list
Data residencyCanadian option offered"It's in the cloud"
DPASigns readily, has a templateTreats it as an unusual request
Breach noticeDefined window in hours"We'll let you know promptly"
Model provenanceNames the model and providerVague or evasive

Keeping a running vendor inventory turns these answers into a record you can go back to, and pairing it with an AI governance process means every new tool runs the same twelve questions instead of quietly slipping in unassessed.

Turning answers into a decision

You won't get a perfect answer to all twelve, and you're not looking for a flawless vendor — just an informed choice, made with your eyes open and written down. Hang onto the responses. They become part of your due-diligence record, and your defence if a regulator ever asks why you trusted this tool with personal information.

The vendors worth buying from tend to answer fast and precisely, because they've been asked all of this before. The ones who stall, deflect, or promise to "circle back" are telling you something too.

*This article is general information, not legal advice; consult a qualified professional about your specific situation.*

At Canuckt we build privacy-first AI tooling for Canadian businesses, and our sister product Valdra turns vendor assessments like this one into a repeatable process instead of a one-time scramble. Either way, ask the twelve questions — the ten minutes it costs is cheaper than the alternative.

Frequently asked questions

What is AI vendor risk?+

AI vendor risk is the exposure you take on when a third-party AI tool handles your personal information. PIPEDA keeps you accountable for that data even after it leaves your systems, so the vendor's practices around data use, security, residency, and retention all become risks you have to assess and document yourself.

Should an AI vendor sign a data processing agreement?+

Yes. A data processing agreement (DPA) is the contract that binds the vendor to purpose limitation, security, breach notification, and sub-processor controls. If a vendor treats a DPA as an odd request, odds are they haven't sold to privacy-conscious Canadian buyers before.

Do AI vendors use your data to train their models?+

Some do. Ask for a clear written answer covering both your inputs and your outputs. If training happens, insist the opt-out be off by default, and lean on vague phrases like "aggregated, de-identified data to improve services" until you understand what they actually mean.

Why does data residency matter for AI tools?+

Where a vendor physically stores and processes data shapes your PIPEDA cross-border transfer obligations and, for Quebec customers, Law 25's expectations for transfers outside Quebec. A vendor that offers Canadian data residency lowers that exposure when the information is sensitive.

What is model provenance?+

Model provenance is where the AI model actually comes from — built in-house, licensed from a major provider, or an open-weights model the vendor hosts. Each carries different data-flow and reliability implications, and you're entitled to know whose model is reading your data.

AI vendor riskthird-party riskdata processing agreementsub-processorsdata residencymodel provenancePIPEDAvendor due diligence

AI governance and privacy compliance, simplified.

Valdra helps Canadian companies govern AI and meet PIPEDA and Law 25 — hosted in Canada.

Explore Valdra

Our own compliance

We run our own compliance programme inside Valdra — the product we sell. Our SOC 2, ISO 27001 and ISO 42001 programmes are actively in progress; we do not claim certifications we do not yet hold.

Valdra compliance badge — click to verify
  • PIPEDA
  • Law 25 (Quebec)
  • CASL
  • Data hosted in Canada 🇨🇦
  • AI governance
View our Trust Centre

Self-declared, not audited by a third party. Click the badge to verify it is genuine and see what it covers.

AI Vendor Risk: Questions to Ask Before You Buy | Canuckt AI