All insights
EN · AI Strategy & Transformation

How to conduct security due diligence before hiring an AI services company

Evaluate data use, access, models, subcontractors, development, testing, incidents and exit before granting real information or system access.

An evidence room separates enterprise data and credentials from a modular AI supplier chain through a security gate.
AI Provider Due Diligence Proof-8 releases data and access only after eight evidence domains pass review. · Generated with OpenAI

Complete security due diligence before sharing real data, credentials or production access. First classify the use case and the consequence of failure. Then require evidence for data flows, model and subcontractor chains, identity, secure development, evaluations, incidents and exit. A questionnaire or certificate can start the review, but it does not replace architecture review or a controlled test of the proposed use case.

Depth should follow risk. A synthetic-data prototype may pass a light screen. An agent that reads personal data, executes transactions or influences consequential decisions requires detailed evidence, a technical session with the proposed delivery team and sandbox validation. Privacy, legal and security specialists should confirm applicable U.S. state, sector and contractual requirements.

The AI Provider Due Diligence Proof-8

Score each domain from zero to four: zero is unknown; one is a sales assertion; two is a policy or partial artifact; three is scope-specific evidence with an accountable owner; four is a control tested in the proposed path. Require at least 24 of 32, no zero and passage of all six gates. The score compares evidence; it does not accept risk for the buyer.

  • Use-case boundary — users, decisions, data, environments, allowed actions, oversight and failure impact.
  • Data and model use — purpose, retention, training, location, deletion, backups and derivatives.
  • Identity and secrets — least privilege, named accounts, segregation, rotation, approval, logs and emergency access.
  • Model and component chain — models, APIs, open source, connectors, versions, regions, subprocessors and substitution.
  • Development and change — repositories, review, tests, dependencies, environments, releases and model or prompt changes.
  • Evaluation and misuse — test sets, failures, prompt injection, leakage, abuse, human review and regression.
  • Operations and incidents — telemetry, alerts, severity, notification, containment, recovery and continuity.
  • Evidence and exit — reports, certification scope, exceptions, export, transfer and access revocation.

Six mandatory gates

  • The provider cannot produce a relevant data-flow map and inventory of models, components and subprocessors.
  • Buyer data, prompts, feedback or outputs may train shared products without separate, explicit authorization.
  • Production access relies on shared accounts, broad privileges or activity without attributable logs.
  • No process exists to notify the buyer of material incidents or model, region or subcontractor changes.
  • The provider cannot demonstrate reproducible evaluation for the use case and its critical failure modes.
  • Essential controls exist only as generic claims, without evidence scoped to the proposed service.

Build a compact evidence room

Request seven packets: architecture and data flow; model and subprocessor inventory; development and change practices; access matrix plus sample logs; evaluation report and failure register; incident and continuity plan; and export and exit package. Each artifact should state scope, date, owner, exceptions and validity. Confidential evidence can be reviewed under access controls; its absence should not be replaced by a sales promise.

NIST SP 800-161r1 treats cybersecurity supply-chain risk as a lifecycle activity. For AI, trace the firm plus the models, APIs, libraries, licensed data and cloud services supporting the solution. NIST SP 800-218A extends this view with secure-development practices for AI models and is relevant to technology acquirers.

Use questionnaires for routing, not assurance

The Cloud Security Alliance AI Controls Matrix and AI-CAIQ help structure questions and responsibility. Use them to identify gaps and decide where to investigate. Verify whether certifications cover the relevant legal entity, product, region and period. A report covering a provider's corporate environment may not include its AI pipeline or a critical subprocessor.

Run an evidence session with the delivery team

  • Trace a normal user request through models, tools, data stores and logs.
  • Inject a permission change, a prompt-injection attempt and primary-model unavailability.
  • Ask the team to demonstrate detection, blocking, fallback, communication and recovery.
  • Record decision owners, produced evidence and gaps that belong in the SOW or a paid validation.

The session should not expose secrets or attack production. It verifies whether claimed controls exist on the actual path and whether the team can explain boundaries. Commission independent assessment and risk-proportionate technical testing for higher-impact systems.

Turn gaps into contracting gates

  • Before discovery: synthetic or minimized data and segregated access only.
  • Before real data: approved use, retention, region, subprocessors and deletion terms.
  • Before integration: named identities, least privilege, logs and change process tested.
  • Before production: agreed evaluation, incident response, SLOs, rollback and residual-risk approval.
  • Before acceptance: documentation, transfer, export and revocation verified.

NIST's AI RMF and Generative AI Profile organize governance, mapping, measurement and management, but the hiring decision still needs control evidence for the specific service. Do not treat an enterprise-wide policy as automatic proof of implementation.

Connect diligence, governance, testing and contract

Use https://makinai.co/insights/en/how-to-choose-ai-governance-consulting-firm for accountability, https://makinai.co/insights/en/how-to-choose-ai-evaluation-testing-company for independent validation and https://makinai.co/insights/en/what-to-include-ai-services-contract-sow to convert evidence into obligations. Explore https://makinai.co/services/en/ai-strategy-transformation-consulting.

When to involve MAKINAI

MAKINAI can risk-tier the use case, structure the scorecard, facilitate the evidence session and convert gaps into RFP, SOW or paid-pilot requirements. Qualified specialists should validate legal, privacy and security conclusions that require formal audit or certification.

Sources and references

  1. NIST SP 800-161r1 — Cybersecurity Supply Chain Risk Management · NIST

    Guides organizations in identifying, assessing and mitigating cybersecurity supply-chain risks across the lifecycle.

    2026-09-01
  2. NIST — AI Risk Management Framework · NIST

    Organizes AI risk management around governance, mapping, measurement and management of trustworthiness characteristics.

    2026-09-01
  3. NIST AI 600-1 — Generative AI Profile · NIST

    Applies the AI RMF to generative-AI risks including provenance, privacy, information security, evaluation and incidents.

    2026-09-01
  4. NIST SP 800-218A — Secure Software Development for AI Models · NIST

    Adds secure-development practices for AI models and is intended for producers, acquirers and users.

    2026-09-01
  5. Cloud Security Alliance — AI Controls Matrix · Cloud Security Alliance

    Provides AI controls and a vendor-assessment questionnaire with evidence expectations and role-based responsibilities.

    2026-09-01
Making connections

Continue exploring

AI Strategy & Transformation

How to define AI provider governance and performance management before hiring

Read insight
AI Strategy & Transformation

How to evaluate an AI consulting ROI business case before hiring

Read insight
AI Strategy & Transformation

Boutique AI firm, global consultancy, or systems integrator: how to choose

Read insight
Related capability

AI strategy & transformation

An AI transformation consultancy should answer four questions before recommending technology: where business value exists, which capabilities and data are required, how risk will be controlled, and who will operate the change. MAKINAI connects those answers in an executable plan with priorities, owners, metrics and scale decisions.

Explore this capability