AI Risk & Governance
Vendor VettingPart 3 of 4

Five Questions to Ask Before Adopting Any AI Tool

You do not need a procurement department or a six figure budget to vet an AI vendor responsibly. You need five questions and the discipline to ask them first.

6 min read

There is a moment that happens just before most AI tools get adopted inside a small business or nonprofit. Someone finds something useful, tries it, likes it, and starts using it for real work. The vetting step, if it happens at all, happens after the tool is already woven into someone's daily routine, which is exactly backward.

You do not need a legal team or an enterprise procurement process to fix this. You need five questions, asked before anyone signs up, and the discipline to walk away from a vendor that cannot answer them clearly.

"Fifteen minutes of vetting beats months of wondering what happened to a sensitive file later."

What follows are five questions that belong in every AI tool decision, written for the leader who is not a procurement specialist or a data privacy attorney. You can ask all five in a single conversation with a vendor's sales team, and a vendor that cannot answer them clearly has already told you what you need to know.

1
Ask this about training
Does this tool train its models on our data by default?

Many free and lower cost tiers use submitted conversations to train future models unless a user actively opts out, and some do not offer an opt out at all on the free plan.

A strong answer states the default clearly and explains how to change it. A weak answer is vague, or the vendor cannot produce a written policy at all. If a vendor cannot give you a clear answer, treat that silence as your answer.

Why this matters
Free tiers are the most common entry point for AI tools at small businesses and nonprofits, and they are also where training defaults are weakest and least disclosed.
2
Ask this about storage
Where is our data stored, and for how long?

You do not need an engineering deep dive. You need to know whether data is deleted on a defined schedule, retained indefinitely, or stored in a way that creates compliance questions for your sector.

A strong answer names a specific retention period. A weak answer is that data is kept as long as needed, with no further detail.

Why this matters
Retention practices vary widely across AI vendors, and few publish a specific deletion timeline unless a customer asks for one directly.
3
Ask this about deletion
Can we delete our data on request, and will the vendor confirm it?

This matters most for any tool touching donor records, client case files, or anything covered by a privacy commitment your organization has made publicly.

A strong answer describes a specific deletion process and a way to confirm it happened. A weak answer is that deletion is not supported, or nobody at the vendor seems to know.

Why this matters
If your organization cannot honor a donor's or client's deletion request because a vendor cannot fulfill one, that gap becomes your liability, not theirs.
4
Ask this about validation
Does the vendor have any independent third party validation?

SOC 2, ISO 27001, or a similar certification is not required for every tool you adopt, but it is a meaningful signal for anything touching sensitive data.

A strong answer points to a current certification or a clear explanation of compensating controls. A weak answer treats the question as irrelevant.

Why this matters
93% of IT leaders report ongoing concern about the data security risks tied to AI tools, yet most small organizations have no formal process for checking vendor certifications before adoption, according to a 2025 SaaS Management Index report.
5
Ask this about tier
What changes between the free tier and the paid tier?

This is the question most organizations skip, and it is often the one that matters most. Free tiers frequently come with weaker data protections, in part because your data and your usage are part of how the vendor offsets the cost of giving the tool away.

A strong answer lays out the specific protections gained at the paid tier. A weak answer treats the tiers as functionally identical.

Why this matters
More than a third of employees use free versions of AI tools even when their employer has approved a paid plan, often without realizing the free tier carries materially weaker data protections, according to a 2025 BlackFog survey.

What a Defensible Answer Sounds Like

"We use the free version" is not an answer to any of these five questions. Neither is "it seemed fine." A defensible answer is specific. It names the tier, the retention period, the deletion process, and the certification, or it names the gap honestly and says what your organization is doing about it in the meantime.

The test to apply: If a board member or a major donor asked why your organization chose this AI tool, could you walk through what you checked and what you found? If the honest answer is that nobody checked, the conversation is not finished.

The ask for this week: Before your team adopts another AI tool, run these five questions, even informally. Fifteen minutes is the cheapest insurance policy available to your organization.

Ready for a clearer picture of where you actually stand?

A 90-day or 30-day Security Business Review translates your organization's risk into clear, prioritized decisions leadership can act on. No enterprise complexity. No vendor lock-in. Just defensible outcomes.

Start a Conversation
Vendor RiskAI GovernanceData PrivacyNonprofit TechnologySmall Business