AI vendor security: what to review before connecting data and tools

A vendor is not just a licence

When an AI solution processes documents, queries your CRM or executes actions, it becomes part of your security chain. The assessment has to happen before you upload sensitive information or enable connectors.

An AI vendor is part of your risk perimeter as soon as it processes data, shapes decisions or integrates critical services.

The essential questions

  • What data does it process, for what purpose and for how long?
  • Is it used to train models or improve the service?
  • Where is it hosted and which sub-processors are involved?
  • What access controls, encryption and logging does it offer?
  • How does it communicate model, terms or incident changes?
  • How is data exported and access revoked on termination?

Assess what the connector can really do

Review scope, write access, deletion capability, access to other users’ data and service tokens. Configure least privilege and avoid generic connectors with global permissions. In agentic systems, an authorised tool must also have explicitly authorised actions.

Do not forget continuity and exit

Define alternatives in case the service raises prices, degrades quality, goes down or changes terms. Keep data and documentation in recoverable formats; dependency cannot be managed once it is already urgent.

Fold the assessment into governance

Link each vendor to a use case, a risk level, an owner and a review date. The article on AI governance explains how to keep these decisions in an operational inventory.

Conclusion: manage the vendor as an extension of the system

Assessing AI vendors has to go beyond a requirements checklist: it needs controls over data, changes, access and continuity. A proportionate process lets you innovate without losing visibility over critical dependencies.

If you need to assess AI vendors, protect data and set third-party controls proportionate to the risk, at Impulsa3 we support you with a practical, data-driven strategy.