Free template · Vendor diligence

AI vendor due-diligence checklist

A checklist for evaluating an AI vendor before you adopt it: data handling, training opt-out, security attestations, retention, and contractual terms.

For: Whoever vets new software at your firm.

Vendor due diligence is the review you do before client data goes anywhere near a new tool. The FTC Safeguards Rule requires you to oversee your service providers, so this is not simply good practice, it is part of the same obligation your WISP describes.

For an AI tool specifically, the questions that decide the answer are narrow: does the vendor train on your inputs, can that be turned off contractually rather than in a settings menu, who are the sub-processors, how long is data retained, and what happens to it when you leave. A consumer chatbot and a business plan from the same company can differ on every one of those points.

The full checklist is below. Work through it once per tool, write down the conclusion, and set a date to review it again, because vendor terms change more often than firm policies do.

Template text · adapt every bracketed item to your firm

AI Tool Vendor Due-Diligence Checklist

Evaluate an AI vendor before your firm adopts it

Tool / vendor
[Name]
Reviewed by
[Name / Title]
Date
[Date]
Decision
[ ] Approved [ ] Rejected [ ] More info needed
Before you use this template

This is a template and a starting point only. It is not legal or compliance advice, and adopting it as-is does not make your firm compliant with anything. Every firm is different: customize every bracketed item, delete what does not apply, add what your situation requires, and have your own legal counsel review the result before you implement it. See the full disclaimer at the end of this document.

1. Data Handling and Privacy

  • The vendor's terms state whether our inputs and outputs are used to train its models, and we can opt out (or training is off by default for business/enterprise use).
  • Data is logically segregated and not shared with other customers.
  • The vendor discloses where data is stored and processed (geographic location and sub-processors).
  • A current list of sub-processors is available.
  • Data retention and deletion terms are clear, and we can request deletion of our data.

2. Security

  • Data is encrypted in transit and at rest.
  • The vendor supports multi-factor authentication (MFA) and role-based access controls.
  • The vendor holds a recognized security attestation (for example, SOC 2 Type II or ISO 27001) and will share the report or summary.
  • The vendor has a documented incident response and breach notification process.
  • Audit logging of access and activity is available.

3. Compliance and Confidentiality

  • Use of the tool can comply with IRC section 7216 if tax return information will be involved (consent obtained where required).
  • The vendor's terms are consistent with our confidentiality obligations and the FTC Safeguards Rule.
  • A Data Processing Agreement (DPA) or equivalent is available if needed.
  • The tool's use is consistent with the AICPA Code of Professional Conduct and applicable state board rules.

4. Accuracy and Controls

  • The tool's intended use, limitations, and known failure modes are documented.
  • Output can be reviewed and verified by a professional before use (no fully automated final decisions).
  • The vendor is transparent about model changes that could affect output.

5. Contractual and Operational

  • Pricing, term, and termination/offboarding (including data export and deletion) are acceptable.
  • Liability, indemnification, and warranty terms have been reviewed.
  • Vendor stability and support (uptime, SLAs, roadmap) are acceptable.
  • An internal owner is assigned and a re-review date is set (at least annually).

Notes and conclusion

[Summarize findings, residual risks, conditions of approval, and the re-review date here.]

Disclaimer. This template is provided by Charles J Barmore CPA PC for general informational and educational purposes only. It is a starting point, not legal, tax, or compliance advice, and neither downloading nor using it creates a client, advisory, or professional relationship. It is provided "as is," without warranty of any kind, express or implied, and Charles J Barmore CPA PC disclaims all liability arising from its use. Using this template does not by itself make your firm compliant with the FTC Safeguards Rule, IRS requirements, professional standards, or any other law or regulation; compliance depends on how your firm adapts, implements, and maintains it. Laws, regulations, and professional standards change and vary by jurisdiction. Review and adapt this document to your firm's facts and have your own legal counsel and advisors review it before relying on it.

Want help putting this to work?

A document is a start. If you want AI actually implemented in your firm, safely and with the controls this template describes, let's talk. The first conversation is free.