Are You Sure Your AI Vendor Is Actually Compliant? Here's What to Ask
7 min readA vendor vetting checklist for AI compliance, plus the exact audit framework we built and required 100% of our own team to pass.
Are you making sure the vendor sitting on your AI project actually knows what they're doing with your data?
Not "have they mentioned AI in a sales deck." Not "do they use ChatGPT internally." Whether they can show you, in writing, that every person touching your systems has been trained on data privacy, prompt security, and what to do when something goes wrong.
Most buyers never ask. They assume a company that sells AI services must have its own house in order. That assumption is costing people more than they realize.
The question nobody's asking in vendor selection
When you bring on an IT or automation vendor, you're not just buying a deliverable. You're handing them access to your systems, your data, and often your customers' data. If that vendor is using AI tools internally, and almost every vendor now is, the question isn't whether AI is involved. It's whether the people using it know what they're doing.
Here's what that looks like in practice. A vendor's developer pastes a snippet of your production database into an AI coding assistant to debug faster. Nothing malicious about it. But if that snippet contains customer records, you now have a compliance problem you didn't create and didn't know about, sitting with a company you're paying to protect you from exactly that kind of risk.
This isn't hypothetical. It's the same failure mode any company faces internally when building AI agents or automating workflows. The difference is that when it's your vendor, you often don't find out until it's already happened.
What to actually ask before you sign
Most RFPs ask about uptime guarantees and support SLAs. Almost none ask this: can you show me proof that everyone on this project has passed AI compliance training, not just read a policy document? If the answer is a shrug, that's your answer.
Documented program, not a policy PDF
A PDF nobody's quizzed on isn't training. It's a liability shield for them, not protection for you.
Required completion, not optional
If it's optional, assume the people who skipped it are the ones who'll make the mistake.
PHI vs. PII fluency
HIPAA Safe Harbor requires stripping specific identifier categories before data counts as de-identified. A vendor who can't name them hasn't studied this.
A defined incident reporting window
Ours is immediate, no exceptions. "We'd assess it" is a red flag. Speed is the entire point of an incident response plan.
What we did, and why we're sharing it
We required every single person at Sunflower Lab, regardless of role, to pass a mandatory AI compliance assessment. Not a policy email. Not a one-time webinar. A structured program with six modules, each built around a specific risk category, each ending in a quiz that had to be passed at 100% before anyone could keep working with AI tools day to day.
Responsible AI
Who's accountable when AI produces something wrong: the person who submitted, deployed, or acted on it. Not the tool.
Secure Prompting
What never goes into a prompt, and how to recognize prompt injection before it does damage.
Data Privacy
PHI, HIPAA Safe Harbor's 18 identifier categories, the DPDP Act, and an immediate reporting rule for exposed data.
AI Bias Awareness
Where bias originates, what automation bias looks like, and why it's especially serious in healthcare AI.
Security Risks
Supply chain attacks, hardcoded credentials in AI-generated code, and a strict one-hour reporting window.
AI Governance Standards
Approved tools registries, Business Associate Agreements, and a quarterly policy review cadence.
How the program actually ran
We didn't bring in an outside compliance firm or buy a new LMS. We built this on tools we already had, and split ownership deliberately between the team that built it and the team that enforced it.
Built the portal in Power Apps
Infrastructure we already owned. No new vendor contract required.
Video + 5-question quiz per module
Six modules, each pairing a short lesson with a real assessment.
HR owned rollout and enforcement
IT built it. HR distributed it and tracked completion in real time.
100% completion required
No partial credit. No exceptions by role or tenure.
We're not sharing this to brag. We think it should be a baseline expectation for any vendor handling your data, not a differentiator. If your current or prospective vendor can't produce something similar, down to the module structure and the completion tracking, you're trusting them on faith alone.
If you're the vendor, not just the buyer
If you're reading this from the other side, running a company that sells AI development, agentic AI automation, or IT services, the takeaway is the same. Your clients are starting to ask these questions, even if they haven't yet. Being able to answer with proof instead of a policy statement is going to matter more every quarter.
The steps aren't complicated. Map what AI tools your team actually uses. Identify the regulations that actually apply to your clients' industries, not generic ones. Build training around real scenarios instead of theory. Require full completion, not a passing grade. Use tools you already have, whether that's Power Apps or your existing intelligent process automation stack, instead of buying new software. Put a non-technical team, usually HR, in charge of enforcement.
None of this requires a large budget. It requires deciding that "we take AI seriously" means something more than a sentence on your website.
Frequently asked questions
Ask if they have documented, required training with completion tracking, not just a written policy. Ask about their reporting timeline for data incidents. Ask if their team can explain automation bias and data minimization in plain language. Vague answers usually mean vague policies.
Requirements vary by industry and jurisdiction, but any vendor touching PHI on your behalf typically needs a Business Associate Agreement under HIPAA, and any vendor processing personal data of individuals in India falls under the DPDP Act. Training isn't always legally mandated on paper, but it's how you demonstrate the safeguards those laws expect.
Ask for the pass rate and the pass threshold. A vendor requiring 100% completion with real assessment questions, not a video with no follow-up, is different from one that calls a policy read-through "training." Ask what happens if someone fails, and how long the reporting window is if something goes wrong.
Yes. We built ours using Power Apps, a tool we already owned, with HR handling distribution. No outside vendor or new software purchase was required. The framework matters more than the budget.
It gets reported immediately to security and privacy contacts, not after checking with a manager or waiting until the end of the day. The faster it's reported, the smaller the actual exposure.
Evaluating an AI or automation vendor?
Talk to our team about what real AI compliance should look like before you sign anything, or see how we approach AI development and data governance ourselves.
Talk to Our TeamYou might also like
Stay ahead in tech with Sunflower Lab’s curated blogs, sorted by technology type. From AI to Digital Products, explore cutting-edge developments in our insightful, categorized collection. Dive in and stay informed about the ever-evolving digital landscape with Sunflower Lab.






