AI

Are You Sure Your AI Vendor Is Actually Compliant? Here’s What to Ask

Are You Sure Your AI Vendor Is Actually Compliant? Here's What to Ask

7 min read

A vendor vetting checklist for AI compliance, plus the exact audit framework we built and required 100% of our own team to pass.

Are you making sure the vendor sitting on your AI project actually knows what they're doing with your data?

Not "have they mentioned AI in a sales deck." Not "do they use ChatGPT internally." Whether they can show you, in writing, that every person touching your systems has been trained on data privacy, prompt security, and what to do when something goes wrong.

Most buyers never ask. They assume a company that sells AI services must have its own house in order. That assumption is costing people more than they realize.

The question nobody's asking in vendor selection

When you bring on an IT or automation vendor, you're not just buying a deliverable. You're handing them access to your systems, your data, and often your customers' data. If that vendor is using AI tools internally, and almost every vendor now is, the question isn't whether AI is involved. It's whether the people using it know what they're doing.

Here's what that looks like in practice. A vendor's developer pastes a snippet of your production database into an AI coding assistant to debug faster. Nothing malicious about it. But if that snippet contains customer records, you now have a compliance problem you didn't create and didn't know about, sitting with a company you're paying to protect you from exactly that kind of risk.

This isn't hypothetical. It's the same failure mode any company faces internally when building AI agents or automating workflows. The difference is that when it's your vendor, you often don't find out until it's already happened.

What to actually ask before you sign

Most RFPs ask about uptime guarantees and support SLAs. Almost none ask this: can you show me proof that everyone on this project has passed AI compliance training, not just read a policy document? If the answer is a shrug, that's your answer.

Documented program, not a policy PDF

A PDF nobody's quizzed on isn't training. It's a liability shield for them, not protection for you.

Required completion, not optional

If it's optional, assume the people who skipped it are the ones who'll make the mistake.

PHI vs. PII fluency

HIPAA Safe Harbor requires stripping specific identifier categories before data counts as de-identified. A vendor who can't name them hasn't studied this.

A defined incident reporting window

Ours is immediate, no exceptions. "We'd assess it" is a red flag. Speed is the entire point of an incident response plan.

100%
Pass threshold, no exceptions
6
Compliance modules
30
Assessment questions
1 hr
Credential reporting window

What we did, and why we're sharing it

We required every single person at Sunflower Lab, regardless of role, to pass a mandatory AI compliance assessment. Not a policy email. Not a one-time webinar. A structured program with six modules, each built around a specific risk category, each ending in a quiz that had to be passed at 100% before anyone could keep working with AI tools day to day.

1

Responsible AI

Who's accountable when AI produces something wrong: the person who submitted, deployed, or acted on it. Not the tool.

2

Secure Prompting

What never goes into a prompt, and how to recognize prompt injection before it does damage.

3

Data Privacy

PHI, HIPAA Safe Harbor's 18 identifier categories, the DPDP Act, and an immediate reporting rule for exposed data.

4

AI Bias Awareness

Where bias originates, what automation bias looks like, and why it's especially serious in healthcare AI.

5

Security Risks

Supply chain attacks, hardcoded credentials in AI-generated code, and a strict one-hour reporting window.

6

AI Governance Standards

Approved tools registries, Business Associate Agreements, and a quarterly policy review cadence.

How the program actually ran

We didn't bring in an outside compliance firm or buy a new LMS. We built this on tools we already had, and split ownership deliberately between the team that built it and the team that enforced it.

1

Built the portal in Power Apps

Infrastructure we already owned. No new vendor contract required.

2

Video + 5-question quiz per module

Six modules, each pairing a short lesson with a real assessment.

3

HR owned rollout and enforcement

IT built it. HR distributed it and tracked completion in real time.

4

100% completion required

No partial credit. No exceptions by role or tenure.

We're not sharing this to brag. We think it should be a baseline expectation for any vendor handling your data, not a differentiator. If your current or prospective vendor can't produce something similar, down to the module structure and the completion tracking, you're trusting them on faith alone.

If you're the vendor, not just the buyer

If you're reading this from the other side, running a company that sells AI development, agentic AI automation, or IT services, the takeaway is the same. Your clients are starting to ask these questions, even if they haven't yet. Being able to answer with proof instead of a policy statement is going to matter more every quarter.

The steps aren't complicated. Map what AI tools your team actually uses. Identify the regulations that actually apply to your clients' industries, not generic ones. Build training around real scenarios instead of theory. Require full completion, not a passing grade. Use tools you already have, whether that's Power Apps or your existing intelligent process automation stack, instead of buying new software. Put a non-technical team, usually HR, in charge of enforcement.

None of this requires a large budget. It requires deciding that "we take AI seriously" means something more than a sentence on your website.

Frequently asked questions

Ask if they have documented, required training with completion tracking, not just a written policy. Ask about their reporting timeline for data incidents. Ask if their team can explain automation bias and data minimization in plain language. Vague answers usually mean vague policies.

Requirements vary by industry and jurisdiction, but any vendor touching PHI on your behalf typically needs a Business Associate Agreement under HIPAA, and any vendor processing personal data of individuals in India falls under the DPDP Act. Training isn't always legally mandated on paper, but it's how you demonstrate the safeguards those laws expect.

Ask for the pass rate and the pass threshold. A vendor requiring 100% completion with real assessment questions, not a video with no follow-up, is different from one that calls a policy read-through "training." Ask what happens if someone fails, and how long the reporting window is if something goes wrong.

Yes. We built ours using Power Apps, a tool we already owned, with HR handling distribution. No outside vendor or new software purchase was required. The framework matters more than the budget.

It gets reported immediately to security and privacy contacts, not after checking with a manager or waiting until the end of the day. The faster it's reported, the smaller the actual exposure.

Evaluating an AI or automation vendor?

Talk to our team about what real AI compliance should look like before you sign anything, or see how we approach AI development and data governance ourselves.

Talk to Our Team
Published by
Ronak Patel

Recent Posts

  • AI

Copilot Studio vs M365 Copilot: Which One Does Your Business Actually Need?

No vendor pitch here, just the plain difference, so…

4 weeks ago
  • Automation

Before You Automate: The 5-Process Audit Every Operations Director Should Run First

A process automation audit tells you which workflows are…

4 weeks ago
  • Automation

RPA Governance Without a Full IT Team: How Lean Operations Teams Keep Automations Running

Launching an automation is exciting. Keeping it running a…

4 weeks ago
  • Automation

3 Steps to Achieve Versioning and Drafts

Businesses are quickly shifting towards optimized processes. And the…

2 months ago
  • Automation

What Happens to Your RPA Program When Your ERP Upgrades? A Migration Playbook

Enterprise leaders usually celebrate when a major ERP modernization…

2 months ago
  • Automation

RPA Center of Excellence: Setup, Governance, and Scaling

Here's how to build the operating model that turns…

2 months ago