What an auditor, or Sekit's evidence engine, asks for.
AI dataset record: provenance, permitted use and quality
For each dataset an AI system uses, the record of where it came from, what the company is allowed to do with it (licence, consent, restrictions), whether it contains personal data, and the quality and preparation checks run before using it (cleaning, labelling, data split).
From the Sekit evidence catalog
In practice
Acquiring data for an AI system, buying a dataset, licensing a corpus, scraping a partner feed, needs supplier-grade due diligence whether that data trains your own model or feeds a vendor tool: a purchased contact list loaded into a CRM assistant, or a scraped feed piped into a vendor summarizer, needs the same check. Before use, someone verifies where the data came from, what the licence permits, and whether no-resale or no-AI-training clauses apply. An auditor asks for the AI dataset record and matches it against the actual purchase or licence agreement. The recurring gap is data grabbed through a quick download or a free API with no acceptance check on what the source terms allow.
Common gaps
A purchased contact list gets loaded into a vendor CRM assistant with no check of whether the seller's licence allows that AI use at all.
Data acquired through a vendor contract has no clause covering AI-specific restrictions, so the supplier agreement never addresses training use.
Acceptance checks exist for regular supplier onboarding but skip any source treated as a quick download instead of a procurement.
Questions your auditor will ask
How was the data feeding this vendor tool acquired, and under what terms?
The AI dataset record names the source and the licence, consent or contract basis for each dataset acquired, whether it trains your own model or feeds a vendor tool.
Does the data source allow use for AI training?
Permitted use is checked against the acquisition terms before the dataset enters a training pipeline or a vendor tool, and any restriction is recorded.
Was this data source risk-assessed like any other supplier?
Data suppliers go through the same third-party risk assessment as other vendors, including data sources acquired specifically for AI.
Do your supplier contracts cover AI-specific data restrictions?
Contract review checks for AI training clauses alongside standard breach notification and data protection terms, catching restrictions before use.
Where regulation demands it
GDPR's processor obligations (28.1, 28.3) apply when a data supplier for AI training processes personal data on the company's behalf, not only to conventional IT vendors.
NIS2 art. 5.2 (Directory of suppliers and service providers) should list data sources acquired for AI the same way it lists any other service provider.