Complete security due diligence before sharing real data, credentials or production access. First classify the use case and the consequence of failure. Then require evidence for data flows, model and subcontractor chains, identity, secure development, evaluations, incidents and exit. A questionnaire or certificate can start the review, but it does not replace architecture review or a controlled test of the proposed use case.
Depth should follow risk. A synthetic-data prototype may pass a light screen. An agent that reads personal data, executes transactions or influences consequential decisions requires detailed evidence, a technical session with the proposed delivery team and sandbox validation. Privacy, legal and security specialists should confirm applicable U.S. state, sector and contractual requirements.
The AI Provider Due Diligence Proof-8
Score each domain from zero to four: zero is unknown; one is a sales assertion; two is a policy or partial artifact; three is scope-specific evidence with an accountable owner; four is a control tested in the proposed path. Require at least 24 of 32, no zero and passage of all six gates. The score compares evidence; it does not accept risk for the buyer.
- Use-case boundary — users, decisions, data, environments, allowed actions, oversight and failure impact.
- Data and model use — purpose, retention, training, location, deletion, backups and derivatives.
- Identity and secrets — least privilege, named accounts, segregation, rotation, approval, logs and emergency access.
- Model and component chain — models, APIs, open source, connectors, versions, regions, subprocessors and substitution.
- Development and change — repositories, review, tests, dependencies, environments, releases and model or prompt changes.
- Evaluation and misuse — test sets, failures, prompt injection, leakage, abuse, human review and regression.
- Operations and incidents — telemetry, alerts, severity, notification, containment, recovery and continuity.
- Evidence and exit — reports, certification scope, exceptions, export, transfer and access revocation.
Six mandatory gates
- The provider cannot produce a relevant data-flow map and inventory of models, components and subprocessors.
- Buyer data, prompts, feedback or outputs may train shared products without separate, explicit authorization.
- Production access relies on shared accounts, broad privileges or activity without attributable logs.
- No process exists to notify the buyer of material incidents or model, region or subcontractor changes.
- The provider cannot demonstrate reproducible evaluation for the use case and its critical failure modes.
- Essential controls exist only as generic claims, without evidence scoped to the proposed service.
Build a compact evidence room
Request seven packets: architecture and data flow; model and subprocessor inventory; development and change practices; access matrix plus sample logs; evaluation report and failure register; incident and continuity plan; and export and exit package. Each artifact should state scope, date, owner, exceptions and validity. Confidential evidence can be reviewed under access controls; its absence should not be replaced by a sales promise.
NIST SP 800-161r1 treats cybersecurity supply-chain risk as a lifecycle activity. For AI, trace the firm plus the models, APIs, libraries, licensed data and cloud services supporting the solution. NIST SP 800-218A extends this view with secure-development practices for AI models and is relevant to technology acquirers.
Use questionnaires for routing, not assurance
The Cloud Security Alliance AI Controls Matrix and AI-CAIQ help structure questions and responsibility. Use them to identify gaps and decide where to investigate. Verify whether certifications cover the relevant legal entity, product, region and period. A report covering a provider's corporate environment may not include its AI pipeline or a critical subprocessor.
Run an evidence session with the delivery team
- Trace a normal user request through models, tools, data stores and logs.
- Inject a permission change, a prompt-injection attempt and primary-model unavailability.
- Ask the team to demonstrate detection, blocking, fallback, communication and recovery.
- Record decision owners, produced evidence and gaps that belong in the SOW or a paid validation.
The session should not expose secrets or attack production. It verifies whether claimed controls exist on the actual path and whether the team can explain boundaries. Commission independent assessment and risk-proportionate technical testing for higher-impact systems.
Turn gaps into contracting gates
- Before discovery: synthetic or minimized data and segregated access only.
- Before real data: approved use, retention, region, subprocessors and deletion terms.
- Before integration: named identities, least privilege, logs and change process tested.
- Before production: agreed evaluation, incident response, SLOs, rollback and residual-risk approval.
- Before acceptance: documentation, transfer, export and revocation verified.
NIST's AI RMF and Generative AI Profile organize governance, mapping, measurement and management, but the hiring decision still needs control evidence for the specific service. Do not treat an enterprise-wide policy as automatic proof of implementation.
Connect diligence, governance, testing and contract
Use https://makinai.co/insights/en/how-to-choose-ai-governance-consulting-firm for accountability, https://makinai.co/insights/en/how-to-choose-ai-evaluation-testing-company for independent validation and https://makinai.co/insights/en/what-to-include-ai-services-contract-sow to convert evidence into obligations. Explore https://makinai.co/services/en/ai-strategy-transformation-consulting.
When to involve MAKINAI
MAKINAI can risk-tier the use case, structure the scorecard, facilitate the evidence session and convert gaps into RFP, SOW or paid-pilot requirements. Qualified specialists should validate legal, privacy and security conclusions that require formal audit or certification.