Key takeaways
- Most small businesses vet a new AI tool by trying it, not by asking the vendor anything — this checklist gives you 20 specific questions to ask before you buy, grouped into five categories.
- The single most important category is data use: whether your data trains the vendor's models, and whether you can turn that off.
- 49% of SMBs cite data security and compliance among their top barriers to AI adoption — a vetting process turns that hesitation into a specific, answerable set of questions instead of a vague worry.
- A vendor that can't or won't answer these questions clearly is itself an answer — treat vagueness as a red flag, not a reason to ask again more politely.
- Keep the answers on file. When a customer, auditor, or insurer asks how you vet AI vendors, "we have a checklist and the answers" is a much better position than "we checked it out and it seemed fine."
Buying software used to mean checking a feature list and a price. Buying an AI tool means checking that too — plus what happens to every piece of data your team feeds into it, who else can see it, and what recourse you have if something goes wrong. Most small businesses skip this step entirely, not out of carelessness, but because nobody handed them the list of questions to ask.
Here it is: 20 questions across five categories, ready to paste into an email or a vendor call.
Why this matters more with AI tools than with typical software
Traditional software mostly stores your data. AI tools often process it — feeding it through a model, sometimes using it to improve that model for other customers, sometimes routing it through subprocessors you've never heard of. Upwork's 2026 State of AI in SMBs research found that data privacy and security top the list of AI adoption barriers for small and medium businesses, at 49%. That hesitation is reasonable — and it's fixable with a specific list of questions rather than a general sense of unease.
| Finding | Source |
|---|---|
| Data privacy and security top the list of AI adoption barriers for SMBs, at 49% | Upwork, 2026 State of AI in SMBs |
The 20-question checklist
How to actually use this in a vendor conversation
You don't need to ask all 20 questions of every vendor for every tool. Match the depth of the check to the sensitivity of what the tool will touch:
| Tool will touch... | Minimum questions to ask |
|---|---|
| No customer data — internal drafting only | 1–4 (data use and training) |
| General customer data (names, non-sensitive contact info) | 1–8 (data use, access, and storage) |
| Regulated data — health, financial, legal | All 20 — and get answers in writing, not a verbal assurance |
Send the questions in writing and keep the vendor's written answers on file. A verbal "yeah, we don't train on your data" from a sales call isn't something you can point to later — an email or a signed data-processing agreement is. This also matters if your business is subject to specific vendor-oversight requirements, like the ones covered in our guide on GLBA and AI in financial and insurance offices or our HIPAA guide for healthcare-specific BAA requirements.
Red flags worth walking away from
- Vague or evasive answers to the data-training question. This is the single most important question on the list — a vendor that can't give a straight answer here is telling you something.
- No written data processing agreement available on request. A legitimate business-tier AI vendor should have one ready, not something they need to "check with legal" about for weeks.
- Refusal to name subprocessors or third-party infrastructure. You can't assess a risk you're not allowed to see.
- No clear incident-notification commitment. If a vendor can't tell you how fast they'll notify you of a breach, assume it will be slower than you'd want.
- Pressure to skip the security conversation and "just try it." A trial period is fine; skipping the questions before real data goes in is not.
Once a vendor clears this checklist, add it to a written approved-tools list so the vetting doesn't have to happen again from scratch every time someone on your team wants to use it. See our guide to building an approved AI tools list.
Who should own vendor vetting
Vetting works best when it isn't reinvented by whoever happens to be excited about a new tool that week. Assign this checklist to one person or role — an office manager, an IT lead, or an owner in a small enough business — rather than leaving it as an ad hoc step whoever's excited about a new tool happens to skip. The same person should keep a simple log: vendor name, date vetted, answers on file, and renewal date for re-checking. That log is also exactly what you'll want on hand if a customer, insurer, or regulator ever asks how your business evaluates AI tools before adopting them — a specific, documented process reads very differently in that conversation than a shrug and "we've been fine so far."
A simple way to score the answers
Twenty questions can feel like a lot to weigh all at once, especially for someone doing this for the first time. A rough scoring approach makes the decision faster without pretending to be a formal security audit:
| Pattern of answers | What it suggests |
|---|---|
| Clear, specific answers to all 20, in writing | Reasonable candidate for an approved-tools list, even for sensitive data |
| Clear answers to data-use and access questions, vague on compliance/security | Fine for internal or low-sensitivity tasks; hold off on regulated data until gaps close |
| Vague or evasive on data-use and training (questions 1–4) | Treat as a hard no for any real customer or patient data, regardless of other answers |
| Refuses to put anything in writing | Walk away — verbal reassurance isn't a substitute for a documented agreement |
Revisiting vendors you already use
This checklist isn't only for new purchases. Most small businesses already have at least a few AI tools in use that were never formally vetted — someone signed up during a free trial, it stuck, and nobody circled back. Running the existing tools through this same checklist retroactively, starting with whichever ones touch the most sensitive data, closes that gap without requiring you to rip out and replace anything that turns out to check out fine.
What the checklist doesn't replace
This checklist covers the vendor's side of the relationship — what they do with your data, how they secure it, and what happens if something goes wrong. It doesn't cover your side: which employees are allowed to use the tool, what data they're allowed to put into it, and how AI-generated output gets reviewed before it reaches a customer. Those internal rules still matter even after a vendor passes every question here — see our AI acceptable use policy guide for that half of the picture.
Common mistakes
- Only checking price and features. A cheaper tool that trains on your customer data isn't actually the better deal once the risk is priced in.
- Accepting verbal answers as sufficient. Get the answers in writing — a sales call promise doesn't hold up if the vendor's practices turn out to differ later.
- Vetting once and never again. Vendors change their terms, ownership, and subprocessors — build a renewal date into your log, not a one-time check.
- Applying the full 20 questions to every low-stakes tool. Match the depth of the check to what the tool will actually touch, so the process doesn't become a reason to avoid using it at all.
◆ Small Business AI Kickstart
Get AI ready today.
Before it's too late.
yforest AI Labs comes to your company, trains your team, and ships your first tools.
FAQ
Do we need to ask a vendor all 20 questions for every tool?
No. Match the depth to sensitivity — a handful of questions for a tool touching no customer data, all 20 with written answers for a tool that will touch regulated data.
What's the single most important question on the list?
Whether your data is used to train the vendor's models by default, and whether that can be turned off. It affects every other answer about where your data actually ends up.
Should vendor answers be in writing?
Yes. A verbal assurance on a sales call isn't something you can point back to later — get answers by email or in a signed data processing agreement.
What's a red flag during vendor vetting?
Vague or evasive answers about data training, no written data processing agreement available, or refusal to name subprocessors. Any of these is a reason to keep looking.
Who should own vendor security vetting at a small business?
One named person or role — an owner, office manager, or IT lead — who also keeps a simple log of which vendors were checked, when, and when to re-check.
Sources
This guide is general information, not legal advice. Have a qualified attorney review any policy before you adopt it.