Technology governance

Nine Questions to Send Any AI Vendor Before You Sign

What should I actually ask an AI vendor before I let it near client information?

Most vendor security questionnaires are long, generic, and produce answers nobody reads. These nine questions are shorter and harder, because each one has an answer that would change whether you sign. They cover the breach-notification clock, where your client data physically goes, whether it trains a model, what you can export, whether the vendor's records satisfy your recordkeeping rule, and who carries the loss. Each question is paired with what a usable answer looks like.

Most vendor security questionnaires are long, generic, and produce answers nobody reads. They are built to be completed rather than to be informative, and a capable vendor can fill one in without telling you anything you did not already assume.

The nine questions below are shorter and harder than a standard questionnaire. Each one has an answer that would change whether you sign, or change what you write into the contract before you do. Send them in writing, keep the reply, and file it where your next examiner or your next successor can find it.

The breach-notification clock

1. Will you notify us within 72 hours of becoming aware of a breach? Please point to the clause and tell us which document it is in.

The 72 hours is not arbitrary. If you are SEC-registered, your incident response program has to be reasonably designed to get service providers to notify you within that window, because your own notice to affected clients is due as soon as practicable, and in any event no later than 30 days after you become aware. A useful answer names a clause and a document. An answer that describes a commitment to security without naming either is not an answer, and this is the one question where the response tells you something no matter what it says. A vendor who can point to the clause in a day has thought about your obligation.

2. Are those calendar hours or business hours, and can our contract override the period?

Both of those qualifiers, business hours and contractual override, [appear in real vendor agreements](/blog/what-your-ai-vendor-promises-if-they-lose-your-data/), and both change what the 72-hour number means. Business hours can stretch a 72-hour commitment across a weekend and beyond, and a clause that defers to your master services agreement means the governing number is in your paperwork rather than on their website. Ask which one you have. Then check that your paperwork says what you think it does.

If your firm is state-registered rather than SEC-registered, the 72-hour figure has no hook in the federal rule that covers you, because the FTC Safeguards Rule requires the contract but sets no deadline. The clause is still worth asking for. The reason is your contract rather than a regulator's clock.

Where your client data goes

3. Where is our client data physically processed, including by any subcontractor?

The answer for the vendor's own systems is usually easy. The answer for their subcontractors is the one that matters, because that is where processing quietly moves to a jurisdiction or a provider nobody evaluated. A good answer is specific about regions and says who else is in the chain.

4. Please name every subprocessor and every model provider that touches our data.

A list, by name, with the ability to be notified when it changes. Model providers are the part firms most often miss: the vendor may be a thin layer over someone else's model, and the terms that matter may be that other company's terms. If the vendor cannot tell you which model provider sees your data, they cannot tell you whose privacy commitments you are actually relying on.

5. Is our data used to train any model, yours or a third party's, in any form including de-identified?

Ask about all three: their own models, any third party's, and de-identified data. "We do not train on customer data" sometimes means the vendor does not, while the model provider underneath might. De-identification is worth naming explicitly because it is the common exception, and because removing obvious identifiers does not by itself make client information appropriate for a system your firm has not approved.

What you can get back from the vendor

6. What is your retention period, and what happens to our data when we terminate?

Two dates: how long they hold it during the relationship, and how long after it ends. Get the deletion commitment in writing along with whatever confirmation you will receive. This is also the question whose answer tends to change when you ask it a second time, in the contract rather than in email.

7. Can we export our complete audit trail without requesting your permission?

Not a report they run for you. An export you can take yourself, on your schedule, without a support ticket. If the answer requires the vendor's cooperation, then your ability to reconstruct what happened depends on a company that may be the subject of the question you are trying to answer.

8. Do your records satisfy Advisers Act Rule 204-2, or do your terms disclaim that?

Advisers Act Rule 204-2 is your recordkeeping obligation, not the vendor's. Many vendor agreements disclaim any recordkeeping role, which is fine as long as you know it and keep the records yourself. Worth knowing: since the Regulation S-P amendments, Rule 204-2(a)(25)(v) requires SEC-registered advisers to retain the written documentation of any contract or agreement entered into pursuant to Regulation S-P's service-provider provision. So the clause you negotiate in answer to question one is a record in its own right, and the vendor's reply is worth keeping with the contract that 204-2(a)(10) already requires you to hold.

Who carries the loss

9. What is your liability cap, and do you indemnify us?

Liability caps are often set at some multiple of fees paid, which for an inexpensive tool can be a small number against a large loss. That may still be an acceptable trade. The point is to know the number before an incident rather than to discover it during one, and to decide deliberately whether the exposure sits with them, with you, or with your insurer.

How to use them

Send all nine questions at once, in writing, and give the vendor a date for the reply. The pattern of the response is as informative as its content: which questions get a clause reference, which get marketing copy, and which get a promise to follow up.

Then file the answers with the contract. The value of this list is not the afternoon you spend on it. It is that two years from now, when someone asks what you knew about this vendor and when, [there is a document that answers](/blog/a-policy-without-a-record/).

Advisor Insights provides general professional information, not individualized investment, legal, cybersecurity, or compliance advice. Which rules apply to your firm depends on your registrations, your systems, and your contracts, and should be confirmed with counsel. Regulatory descriptions are U.S. federal and current as of August 2026.

Primary sources

ValaisOS is building a more enduring operating foundation for private-wealth professionals.

Request early access