HD Field Guide 07
AI supplier security questions
Questions that turn an AI demonstration into a reviewable security, privacy, resilience and accountability decision.
A polished AI capability does not explain how data is retained, how access is controlled or what happens when a model, plugin or supplier changes. Ask for evidence that matches the intended use.
Data and model boundaries
Ask how prompts, files, embeddings, outputs, feedback and support data are separated between customers. Confirm retention periods, deletion behaviour and subprocessors.
Understand which model and hosting components are used, how they can change and whether customers are notified before material changes.
Identity, integration and operations
Review single sign-on, MFA, administrative roles, service accounts, audit logs, API security and connector permissions. Confirm how access is revoked and how privileged support is controlled.
Ask how the service detects abuse, prompt injection, data exfiltration, unsafe output and compromised dependencies.
Evidence, resilience and exit
Request independent assurance relevant to the service rather than accepting generic badges. Review incident response, backup, recovery objectives, vulnerability handling and customer communication.
Plan how data, configurations and logs can be exported or deleted if the service is replaced.
Before you close the guide
- Use case and data flow documented
- Training, retention and subprocessors confirmed
- Identity, logs, connectors and incident handling reviewed
- Exit, export and verified deletion defined
Continue with primary guidance
This guide provides general educational information. Adapt it to your organisation’s policies, contracts, legal obligations and incident process. For an active incident, use trusted professional and official support channels.