Free AI Workshops
AIHA Academy — 8 free live AI workshops for hospitalityFrom AI basics to building your own agents and appsLive online · One hour each · Recordings included
Register free
Back to Standards page

AI HOSPITALITY ALLIANCE · WORKGROUP 8 · VENDOR QUESTIONS

AI vendor due diligence

A practical short-form question set. Record the answers as part of the AI Vendor Due Diligence Record.

4.1.1 Vendor red flags

Tier 2 and Tier 3 procurement should be paused, slowed or escalated where the vendor:

  • cannot identify the AI, model or provider chain behind the service (the level of disclosure may be subject to IP, privacy and contract terms);
  • cannot clearly explain how organisational data is used, retained or deleted;
  • cannot provide adequate information about material changes, incidents or relevant assurance; or
  • cannot provide appropriate means of human intervention, suspension or exit.

4.1.2 Vendor questionnaire

A practical short-form question set that operationalises the governance areas above is provided at Appendix C. Record the answers as part of the AI Vendor Due Diligence Record.

Appendix C: Vendor due diligence questionnaire

Informative companion to the vendor governance areas in Pillar 4. A property-usable question set; record the answers as part of the AI Vendor Due Diligence Record.

ASK THE VENDOR

WHAT TO ESTABLISH

What AI or models power this system, and how are they updated?

Model and provider chain, material changes and how changes are communicated.

What data do you collect and what is it used for?

Data categories, purpose, inputs, outputs, telemetry and secondary uses.

Do you use our data to train or improve your models?

Whether organisational data trains or improves models, and whether it is isolated from other customers.

Are your recommendations informed by other customers’ data?

Whether pricing or other recommendations draw on non-public data from other customers, including competitors, and how it is segregated.

Where is our data stored and processed, and does it cross borders?

Locations, jurisdictions, subprocessors and transfer safeguards.

How long do you retain our data, and can it be deleted?

Retention for inputs, outputs, logs and backups; deletion process and evidence.

Who can access our data?

Vendor personnel, subprocessors, support arrangements and access controls.

What can the AI do without human approval?

Action boundaries, permissions, human review, override and suspension capability.

How will we know if something changes or goes wrong?

Material-change and incident notification, relevant records and escalation.

What happens when the relationship ends?

Data return or deletion, records, continuity and exit assistance.