Before an AI vendor touches client data, ask better questions.
AI features are now embedded inside research, accounting, tax, practice-management and productivity tools. A practical vendor review helps a firm understand what happens to its data before approving the tool for real work.
10 questions to document before approval
Define whether the intended use could include client-identifying data, tax information, payroll data, financial statements, workpapers, emails or internal confidential information.
Document the vendor’s current contractual and product terms rather than relying on assumptions about the consumer version of the tool.
Understand prompts, uploaded files, generated output, logs and backups separately where possible.
Review employee access, subprocessors, support access and administrative controls.
Capture the evidence the vendor provides, such as security documentation, audit reports or certifications, without treating marketing language as verification.
Look for account-level controls, role management, SSO/MFA options, logging and ways to disable risky functionality.
Embedded AI can change quickly. Decide what type of material change should trigger a new review.
Even a strong vendor does not replace the firm’s own review standard before output enters client work or professional conclusions.
Know how the vendor communicates incidents, what evidence the firm should preserve and who internally owns escalation.
A vendor review is only useful if approval, ownership, conditions and review date are recorded.
AI Governance Control Pack — $49 one time
Built to help organizations maintain practical governance artifacts around AI use, vendor review, accountability and recurring controls.
Get the AI Governance Control Pack