What an auditor, or Sekit's evidence engine, asks for.
Vendor due diligence and monitoring
How the company assesses a supplier's security before hiring and monitors it during the relationship, including the process when it ends.
From the Sekit evidence catalog
In practice
For a company buying an AI vendor's API or chatbot, this control means running the same due diligence on that vendor as any critical supplier, then adding AI-specific questions: does the vendor train on your prompts, who are its sub-processors, and how does it notify you when it deprecates a model version. An auditor pulls the AI supplier terms and assurances record and checks it against the vendor's actual data processing agreement, not a sales page. The typical gap is a team signing up for a new AI tool on a company card, skipping the vendor security review that every other supplier goes through.
Common gaps
A department buys an AI subscription with a company card and skips the vendor security review required for every other supplier.
The onboarding assessment checks general security posture but never asks whether the AI vendor trains on the company's prompts or documents.
Ongoing supplier monitoring covers infrastructure providers but stops at the AI vendor, so a model deprecation arrives with no warning.
Questions your auditor will ask
How do you vet an AI vendor before signing up?
The same supplier due diligence process applies, plus questions on prompt training use, sub-processors and incident notification, recorded in the AI supplier terms file.
Does the AI vendor use our data to train its models?
The AI supplier terms and assurances record states the vendor's training-use policy, taken from its actual data processing agreement rather than marketing copy.
What happens if the AI vendor changes or retires a model version?
The record captures the vendor's version-change notice period and any certification it publishes, checked at onboarding and on the review cycle.
How often is the AI vendor's security posture reviewed after onboarding?
Vendor due diligence and monitoring sets a defined review cycle and tracks breach or incident signals for the AI vendor like any critical supplier.
Where regulation demands it
GDPR Articles 28.1 and 28.3 require choosing a processor with sufficient guarantees and binding it by contract, which applies directly to an AI vendor processing company data.