AI HOSPITALITY ALLIANCE · WORKGROUP 8 · VENDOR QUESTIONS
AI vendor due diligence
A practical short-form question set. Record the answers as part of the AI Vendor Due Diligence Record.
4.1.1 Vendor red flags
Tier 2 and Tier 3 procurement should be paused, slowed or escalated where the vendor:
- cannot identify the AI, model or provider chain behind the service (the level of disclosure may be subject to IP, privacy and contract terms);
- cannot clearly explain how organisational data is used, retained or deleted;
- cannot provide adequate information about material changes, incidents or relevant assurance; or
- cannot provide appropriate means of human intervention, suspension or exit.
4.1.2 Vendor questionnaire
A practical short-form question set that operationalises the governance areas above is provided at Appendix C. Record the answers as part of the AI Vendor Due Diligence Record.
Appendix C: Vendor due diligence questionnaire
Informative companion to the vendor governance areas in Pillar 4. A property-usable question set; record the answers as part of the AI Vendor Due Diligence Record.
ASK THE VENDOR | WHAT TO ESTABLISH |
|---|---|
What AI or models power this system, and how are they updated? | Model and provider chain, material changes and how changes are communicated. |
What data do you collect and what is it used for? | Data categories, purpose, inputs, outputs, telemetry and secondary uses. |
Do you use our data to train or improve your models? | Whether organisational data trains or improves models, and whether it is isolated from other customers. |
Are your recommendations informed by other customers’ data? | Whether pricing or other recommendations draw on non-public data from other customers, including competitors, and how it is segregated. |
Where is our data stored and processed, and does it cross borders? | Locations, jurisdictions, subprocessors and transfer safeguards. |
How long do you retain our data, and can it be deleted? | Retention for inputs, outputs, logs and backups; deletion process and evidence. |
Who can access our data? | Vendor personnel, subprocessors, support arrangements and access controls. |
What can the AI do without human approval? | Action boundaries, permissions, human review, override and suspension capability. |
How will we know if something changes or goes wrong? | Material-change and incident notification, relevant records and escalation. |
What happens when the relationship ends? | Data return or deletion, records, continuity and exit assistance. |