Practical AI and SaaS for Business

AI Vendor Due Diligence Checklist for Australian Business

If you've already decided your business needs a proper vendor evaluation process before adopting a new AI tool, rather than signing up on a free trial and hoping for the best, here's a practical checklist covering the full picture: not just where data goes, but retention, security certifications, breach notification, and the contract terms most businesses never think to check.

Last verified: 18 July 2026. References checked against current legislation.

Editorial Perspective

You run a physiotherapy clinic with a handful of therapists, and a new AI tool seems to turn up every week promising to save admin time. You don't have a procurement team to vet these vendors, and one bad contract could mean patient notes sitting somewhere you never agreed to. This checklist gives you the exact questions to ask any AI vendor before you sign up, so you can spot a risky vendor in minutes. No legal background needed.

This article summarises publicly available guidance from regulators and official sources. It is general educational information only and does not constitute legal or professional advice. Requirements vary by jurisdiction. Consult your regional authority or a qualified professional for advice specific to your situation.

In short: Before signing up with any AI vendor, check data retention terms, whether your data trains their models, security certifications, breach notification commitments, and data residency. This checklist is a general planning tool, confirm specific requirements with a qualified adviser for high-stakes procurement.

Why vendor due diligence matters more with AI tools

AI tools often process a broader and more sensitive slice of your business's information than a typical subscription software product (sometimes called SaaS, short for software as a service), since the whole point of the tool is usually to read, summarise, or act on your content. A vendor evaluation process that worked fine for a project management tool may not surface the questions that actually matter for something reading your emails or client communications.

Take a physiotherapy clinic owner considering an AI scribe tool to draft clinical notes after each patient session. The easy path is to sign up during the free trial and worry about the fine print later, if at all. Running through this checklist first, the owner asks where patient notes are stored and finds the vendor keeps identifiable health data on overseas servers indefinitely, with no clear deletion process once the contract ends. That single answer is enough to either push the vendor for a written retention commitment or move to an alternative before any patient data leaves the building.

What regulators say about vendor selection

cyber.gov.au guidance for small business explicitly stresses vendor data handling practices, breach notification commitments, and how securely they run their systems as part of choosing any cloud-based tool, AI included. This isn't AI-specific guidance so much as general cloud vendor guidance that applies with extra weight to AI tools given the volume and sensitivity of what they typically process.

The checklist

This is a general planning tool, not a compliance certification. Scale the depth of this check to the sensitivity of what the tool will handle, a low-stakes internal drafting tool warrants a lighter check than something touching client or financial data.

Data Handling

  • Where is data stored and processed? (See our data sovereignty questions guide for the full location-specific list)
  • Is your data used to train the vendor's models, and can you opt out?
  • What's the data retention period after you stop using the tool or cancel?
  • Does the vendor use third-party sub-processors, and are they disclosed?

Security and Certifications

  • Does the vendor hold recognised certifications appropriate to the sensitivity of your use case? (SOC 2 Type II and ISO 27001 are common benchmarks)
  • What encryption standards apply to data at rest and in transit?
  • Is there a documented incident response process, and what's the vendor's breach notification commitment?

Contract and Legal Terms

  • Does the contract include a specific breach notification timeframe, not just a vague commitment?
  • Are liability caps reasonable relative to the sensitivity of data the tool will handle?
  • Can the vendor change terms (including data handling terms) without direct notice to you?
  • Is the governing law and jurisdiction for disputes something your business can realistically act on if needed? See our AI contract clauses guide for what to look for and negotiate here specifically.

Scaling this to your business size

A 15-person business doesn't need a formal procurement committee to run this checklist, but it does need someone specifically responsible for asking these questions before a new tool goes into regular use, rather than assuming a free trial signup implies no ongoing risk. Keep a simple written record of what you checked and what the vendor confirmed, this becomes useful evidence if a client or regulator ever asks how the tool was selected.

Red flags that should stop you signing up

A handful of specific responses are worth treating as genuine warning signs rather than minor friction. A vendor that won't put data retention or breach notification commitments in writing, only in a sales conversation, is one. Terms that let the vendor change data handling practices without direct notice, buried in a clause allowing unilateral changes to the agreement, is another, since this means today's answers to your due diligence questions aren't actually binding tomorrow. A vendor that can't say clearly whether your data trains their models, hedging with general language about "improving our services," is worth pushing on directly rather than accepting as an adequate answer. None of these individually means walk away immediately, but two or more together on a tool that will handle anything sensitive is a legitimate reason to look at an alternative vendor instead.

A simple three-tier model for how deep to go

Running the full checklist on every single tool a business trials isn't realistic, so scale the depth to what the tool will actually touch. Light tier: internal-only tools with no client, patient, or financial data involved, a quick check of the vendor's general reputation and a scan of the privacy policy is usually enough. Medium tier: tools touching general business data, admin drafting, scheduling, internal documents, run the data handling and security sections of this checklist properly, in writing. Full tier: anything touching client, patient, financial, or otherwise sensitive personal information, run every section of this checklist, including the contract and legal terms section, and consider getting the vendor's answers reviewed by whoever handles legal or compliance matters for your business before signing anything. Deciding which tier a new tool falls into before you start, rather than partway through a trial, keeps the process consistent rather than ad hoc.

Methodology (Real-World, Verified)

This guide is researched against primary regulatory sources and official regulator guidance, verified as of the date shown, and written for a business with no dedicated compliance function.

Related reading: our can staff upload customer data to AI tools, our AI and the Privacy Act guide, and our free AI staff policy template.

Try our free AI Privacy Risk Scorer to score your current AI tool setup against Privacy Act requirements.

Related reading: our AI vendor contracts and Privacy Act.

Related reading: our free AI acceptable use policy template and our AI governance by region.

Try our free AI Compliance Checker to check whether your AI tools meet your compliance obligations.

For the full range of vendor assessment guidance, including contract clauses and breach response, see our AI vendor due diligence hub.

Related reading: Claude AI Review for Australian Business and Notion AI Review for Australian Small Business.

Do I need to run this full checklist for every AI tool, including free ones?

Scale the depth to the sensitivity of what the tool touches. A quick check suffices for a low-stakes free tool used for internal brainstorming, while anything touching client or financial data warrants the full checklist regardless of price.

What's the difference between this checklist and the data sovereignty questions guide?

This checklist covers the full vendor evaluation: security, contracts, retention, and location together. The data sovereignty guide is a narrower, location-only deep dive for when that specific question is your main concern.

Is SOC 2 or ISO 27001 certification mandatory for an AI vendor to be trustworthy?

Not mandatory, but their absence warrants closer scrutiny for higher-sensitivity use cases. Some smaller or newer vendors genuinely lack these certifications without necessarily being unsafe, so treat this as one signal among several, not a single pass-fail test.

What should I do if a vendor gives good answers verbally but won't put them in writing?

Treat verbal-only assurances as unconfirmed. Ask for the specific commitment in an email at minimum, or in the contract itself for anything handling sensitive data. A vendor confident in its own practices generally has no issue confirming them in writing.

How often should an existing AI vendor be re-checked against this list?

Annually is a reasonable default, or sooner if the vendor announces a major feature change, ownership change, or a public security incident. Vendor risk isn't a one-time assessment done at signup and then forgotten.

Find official guidance for your region

Requirements vary by jurisdiction. This article provides general information only. Consult your regional authority or a qualified professional for advice specific to your situation.

The information in this article is general in nature. It reflects a summary of publicly available guidance and does not constitute legal, privacy, or professional advice. Your obligations will depend on your specific situation, jurisdiction, and business circumstances. Do not rely on this article as a substitute for qualified legal or professional advice.

<a href="/calculators/ai-compliance-checker/">AI Compliance Checker</a> to check whether your AI tools meet your compliance obligations

Check Your Compliance