Why a vendor-security review belongs in the buying workflow
Many AI tools ask for broad access before the owner has checked what data will be uploaded, how long it is retained, whether outputs are reviewed, which users can invite others, or what happens when the subscription is cancelled. This checklist gives non-technical owners a practical approval card before the team connects another app.
Vendor-security review card
| Field | What to capture | Owner review rule |
|---|---|---|
| Vendor and use case | Tool name, website, plan, owner, team requesting it, problem it solves, and whether it is a trial, pilot, or permanent tool. | Approve only a specific use case; do not approve vague “AI productivity” access. |
| Data access | Customer data, employee data, files, email, calendar, CRM, payments, invoices, website chat, call recordings, API keys, browser data, or uploads needed. | Choose the minimum access needed. If sensitive data is required, pause for owner/legal/security review. |
| Vendor claims and proof | Privacy policy, security page, data-retention terms, training/use-of-data claims, deletion/export process, support contact, and contract/SLA links. | Use vendor source links only. Do not let AI invent certifications, compliance status, retention rules, or deletion rights. |
| Account controls | Admin owner, user invite rules, MFA/SSO availability, shared-login risk, permissions, audit logs, and connected apps/OAuth scopes. | Require named admin ownership and a removal process before inviting the team. |
| Customer-facing impact | Will the tool draft replies, publish pages, update CRM, change prices, recommend services, or message customers? | Customer-facing output needs human review, source checks, and a rollback/complaint path. |
| Exit plan | Export needs, cancellation date, replacement workflow, deletion request path, final bill check, and who removes seats/API keys. | No approval without an exit owner and shutoff checklist. |
Copy/paste vendor questions
Before we approve this AI vendor, please confirm: what data is stored, whether customer/business data is used for model training, how long data is retained, how deletion/export requests work, what admin controls are available, and which support contact handles security or privacy questions.
Internal pilot approval: [Tool] is approved only for [use case] using [allowed data]. Do not upload [blocked data]. Customer-facing outputs require human review by [owner]. Pilot review date: [date]. Exit owner: [person].
Access review note: Connected systems: [CRM/email/calendar/files/API]. Permissions granted: [scopes]. Minimum-access alternative considered: [yes/no]. Owner approval proof: [link/screenshot]. Next access review: [date].
AI review prompt
Act as a cautious small-business AI vendor-security reviewer. Use only the verified facts below. Do not invent vendor security claims, certifications, compliance status, data-retention terms, deletion rights, pricing, support promises, approval history, or legal advice. Return: 1) missing vendor/security facts, 2) data-access risks, 3) customer-facing output risks, 4) account-control questions, 5) exit-plan gaps, and 6) a STOP AUTOMATION decision if this vendor is not ready for approval.
Verified facts:
- Tool/vendor URL:
- Requested use case:
- Team/user requesting access:
- Data needed:
- Connected systems/OAuth scopes:
- Vendor privacy/security source links:
- Admin owner:
- Customer-facing impact:
- Pilot/review date:
- Exit owner and export/deletion path:Fast QA before approving the tool
- Confirm the vendor source links yourself; do not rely on an AI summary of security or privacy terms.
- Approve the narrowest data access needed for one pilot workflow.
- Block uploads of customer data, financial records, medical/legal details, passwords, API keys, or employee records until qualified review says otherwise.
- Set a review date, exit owner, and cancellation/export path before team rollout.
Related free assets: AI Tool Onboarding Checklist, AI Tool Data Boundary Worksheet, and AI Vendor Exit Checklist.
Disclosure: Horizon Flow is Andrew Burton's digital product catalog. This worksheet is useful without purchase; product links are labeled and UTM-tagged.