vendor checklist for AI compliance
A vendor vetting checklist for AI compliance, plus the exact audit framework we built and required 100% of our own team to pass.
Are you making sure the vendor sitting on your AI project actually knows what they're doing with your data?
Not "have they mentioned AI in a sales deck." Not "do they use ChatGPT internally." Whether they can show you, in writing, that every person touching your systems has been trained on data privacy, prompt security, and what to do when something goes wrong.
Most buyers never ask. They assume a company that sells AI services must have its own house in order. That assumption is costing people more than they realize.
When you bring on an IT or automation vendor, you're not just buying a deliverable. You're handing them access to your systems, your data, and often your customers' data. If that vendor is using AI tools internally, and almost every vendor now is, the question isn't whether AI is involved. It's whether the people using it know what they're doing.
Here's what that looks like in practice. A vendor's developer pastes a snippet of your production database into an AI coding assistant to debug faster. Nothing malicious about it. But if that snippet contains customer records, you now have a compliance problem you didn't create and didn't know about, sitting with a company you're paying to protect you from exactly that kind of risk.
This isn't hypothetical. It's the same failure mode any company faces internally when building AI agents or automating workflows. The difference is that when it's your vendor, you often don't find out until it's already happened.
Most RFPs ask about uptime guarantees and support SLAs. Almost none ask this: can you show me proof that everyone on this project has passed AI compliance training, not just read a policy document? If the answer is a shrug, that's your answer.
A PDF nobody's quizzed on isn't training. It's a liability shield for them, not protection for you.
If it's optional, assume the people who skipped it are the ones who'll make the mistake.
HIPAA Safe Harbor requires stripping specific identifier categories before data counts as de-identified. A vendor who can't name them hasn't studied this.
Ours is immediate, no exceptions. "We'd assess it" is a red flag. Speed is the entire point of an incident response plan.
We required every single person at Sunflower Lab, regardless of role, to pass a mandatory AI compliance assessment. Not a policy email. Not a one-time webinar. A structured program with six modules, each built around a specific risk category, each ending in a quiz that had to be passed at 100% before anyone could keep working with AI tools day to day.
Who's accountable when AI produces something wrong: the person who submitted, deployed, or acted on it. Not the tool.
What never goes into a prompt, and how to recognize prompt injection before it does damage.
PHI, HIPAA Safe Harbor's 18 identifier categories, the DPDP Act, and an immediate reporting rule for exposed data.
Where bias originates, what automation bias looks like, and why it's especially serious in healthcare AI.
Supply chain attacks, hardcoded credentials in AI-generated code, and a strict one-hour reporting window.
Approved tools registries, Business Associate Agreements, and a quarterly policy review cadence.
We didn't bring in an outside compliance firm or buy a new LMS. We built this on tools we already had, and split ownership deliberately between the team that built it and the team that enforced it.
Infrastructure we already owned. No new vendor contract required.
Six modules, each pairing a short lesson with a real assessment.
IT built it. HR distributed it and tracked completion in real time.
No partial credit. No exceptions by role or tenure.
We're not sharing this to brag. We think it should be a baseline expectation for any vendor handling your data, not a differentiator. If your current or prospective vendor can't produce something similar, down to the module structure and the completion tracking, you're trusting them on faith alone.
If you're reading this from the other side, running a company that sells AI development, agentic AI automation, or IT services, the takeaway is the same. Your clients are starting to ask these questions, even if they haven't yet. Being able to answer with proof instead of a policy statement is going to matter more every quarter.
The steps aren't complicated. Map what AI tools your team actually uses. Identify the regulations that actually apply to your clients' industries, not generic ones. Build training around real scenarios instead of theory. Require full completion, not a passing grade. Use tools you already have, whether that's Power Apps or your existing intelligent process automation stack, instead of buying new software. Put a non-technical team, usually HR, in charge of enforcement.
None of this requires a large budget. It requires deciding that "we take AI seriously" means something more than a sentence on your website.
Ask if they have documented, required training with completion tracking, not just a written policy. Ask about their reporting timeline for data incidents. Ask if their team can explain automation bias and data minimization in plain language. Vague answers usually mean vague policies.
Requirements vary by industry and jurisdiction, but any vendor touching PHI on your behalf typically needs a Business Associate Agreement under HIPAA, and any vendor processing personal data of individuals in India falls under the DPDP Act. Training isn't always legally mandated on paper, but it's how you demonstrate the safeguards those laws expect.
Ask for the pass rate and the pass threshold. A vendor requiring 100% completion with real assessment questions, not a video with no follow-up, is different from one that calls a policy read-through "training." Ask what happens if someone fails, and how long the reporting window is if something goes wrong.
Yes. We built ours using Power Apps, a tool we already owned, with HR handling distribution. No outside vendor or new software purchase was required. The framework matters more than the budget.
It gets reported immediately to security and privacy contacts, not after checking with a manager or waiting until the end of the day. The faster it's reported, the smaller the actual exposure.
Talk to our team about what real AI compliance should look like before you sign anything, or see how we approach AI development and data governance ourselves.
Talk to Our TeamNo vendor pitch here, just the plain difference, so…
A process automation audit tells you which workflows are…
Launching an automation is exciting. Keeping it running a…
Businesses are quickly shifting towards optimized processes. And the…
Enterprise leaders usually celebrate when a major ERP modernization…
Here's how to build the operating model that turns…