IndexablePre-launch reviewLast reviewed 2026-05-21

What to check before sending customer data to an AI vendor

Before customer data goes to an AI vendor, answer the launch questions that customers will ask later: what data is sent, why it is needed, whether it trains models, how long it is retained, who can access it, and which commitments depend on it.

Workflow steps

4 practical steps

Records to keep

3 examples

Source links

4 official sources

Step-by-step process

Step 1

Describe the workflow

Name the feature, vendor product, model route, account owner, data categories, and whether the use is production, internal, or experimental.

Step 2

Check model training and retention

Attach vendor sources for data use and retention. If the answer depends on settings or agreements, keep configuration evidence with the source link.

Step 3

Review agreements and subprocessors

Confirm the DPA, product terms, subprocessor source, and any marketplace or reseller path before updating customer-facing records.

Step 4

Review your own storage

Check application logs, traces, support tickets, warehouses, vector stores, and debugging tools. These often matter as much as the AI vendor source.

Records to keep

  • An AI vendor risk assessment with data categories and source links.
  • A retention worksheet listing vendor and company-controlled copies.
  • A customer-data-not-used-for-training evidence note with scope and exclusions.

Where mistakes happen

  • Running a proof of concept with real customer data before review.
  • Checking model training but ignoring logs, files, and support copies.
  • Using a broad DPA statement to answer product-specific AI behavior.

Lightweight version

For a startup, require product owner approval and a short cited-source review before any customer data enters a new AI workflow.

More mature version

For a mature team, require intake, data classification, privacy review, security review, source monitoring, and customer commitment mapping.

Source links

These are starting sources for the examples in this guide. Review the vendor page for scope and limitations before changing customer commitments.

Related templates

Related vendor pages

Generate a review packet from this workflow.

Select your vendors, data categories, and customer commitments. AI Vendor Packet turns the workflow into evidence your team can review.