29 criteria across six areas. Work through what you know, flag what you do not. Get a clear picture of where the risk sits before you approve a tool.
Black Chili's AI Governance and Guardrails Design includes structured supplier review criteria and DPA assessment as part of a full governance build.
Most organisations have not reviewed the terms of the AI tools their staff use. Not really. They have clicked through a sign-up flow, picked a paid plan, and assumed that was enough.
It is not.
AI suppliers vary significantly in how they handle your data – where they process it, whether they use it to train models, what their security posture actually looks like, and whether they will give you a Data Processing Agreement when you ask. The gap between what staff assume and what the terms actually say is where most AI-related data risk sits.
This free checklist works through 29 criteria across six areas – data residency, data use, security, contractual protections, model transparency, and commercial risk. It takes around ten minutes per supplier. It tells you where the gaps are and how significant they are.
No email required. Results are yours to save or print.
When organisations think about AI risk, they typically think about outputs – hallucinations, bias, employees saying things they should not. The data risk sits further upstream, in the supplier relationship, and it is largely invisible until something goes wrong.
The questions that matter are straightforward. Does your supplier use submitted data to train its models? Where is that data processed? Is there a Data Processing Agreement in place? What happens to your data if you cancel? Most organisations cannot answer these questions for the tools their staff use every day.
Enterprise customers are starting to ask. Regulators are starting to look. The ICO has made clear that using AI tools to process personal data without a DPA in place is a breach of UK GDPR – not a grey area. Procurement teams at large organisations are beginning to include AI governance questions in supplier due diligence. The external pressure is building.
Getting ahead of it is straightforward. This checklist is the starting point.
Our AI Supplier Checklist tooling identifies common gaps in AI adoption, in the following categories.
Where is your data processed and stored? Is it within the UK or EEA, and is that clearly documented by the supplier?
Does the supplier use submitted data to train models? How long is data retained, and can it be deleted on request?
Does the supplier hold ISO 27001 or SOC 2 certification? Is MFA enforced? Is audit logging available?
Is a Data Processing Agreement available? Are the terms of service clear and fair? What jurisdiction applies?
Does the supplier disclose how its models are trained and where they may be unreliable? Are output accuracy risks acknowledged?
Is the supplier financially stable? Can you exit cleanly? Are SLAs documented and pricing transparent?
Work through the checklist for one supplier at a time. For each criterion, mark it Met, Partial, or Not Met. At the end you get an overall risk rating – Low, Medium, or High – a breakdown by section, and a list of the gaps that need attention.
The checklist is designed to be used by IT leads, security and compliance teams, procurement functions, or anyone responsible for reviewing tools before staff adopt them. It does not require technical knowledge of AI systems – it assesses the supplier relationship, not the underlying model.
Complete reviews can be saved as a PDF to keep on file or share with a governance lead.
The checklist gives you a picture of where the gaps are. Acting on them – reviewing terms in detail, negotiating DPAs, building a repeatable supplier approval process – is a different piece of work.
Black Chili’s AI Governance and Guardrails Design service includes a full structured supplier review as part of a broader governance build. If you want a conversation about what that looks like for your organisation, get in touch. It costs nothing and takes thirty minutes.
We can help improve your AI Security.