Business and governance

Vendor questions: retention, processing and audit

Shared methods · A shared method; linked tool guides explain the exact steps.

The questions worth asking any AI vendor, and what a good answer looks like. Written as questions because the answers change and yours may differ.

Applies to
Shared methods
Last verified
Reviewed by
Timothy Fehr

Procurement questionnaires for AI vendors tend to be either a generic SaaS form that misses everything specific, or forty pages nobody answers well. A short list of the questions that actually distinguish vendors serves better.

Ask these in writing, for the plan you are buying, and keep the answers with the date attached.

Training and retention

Are our inputs used to train models? The one question where consumer and commercial offerings usually diverge sharply, and where a per-user toggle may exist that your users control rather than you. Establish which contract governs your accounts, since people frequently assume the wrong one.

How long is data retained, and under what circumstances does that change? Retention often varies with the training answer. Get both numbers together.

What happens on deletion? A good answer distinguishes removing content from an account, removing it from backups, and the fact that no provider can retroactively remove data already incorporated into model weights. A vendor that promises complete erasure has told you something useful about their candour.

Processing and location

Where does processing happen, and can we constrain it? For agentic products the answer may differ per mode, and a default can put local files on the vendor's servers without anyone choosing that.

Who are the subprocessors, and how are we told when they change? Notice periods on subprocessor changes are worth more than the current list.

Is there a zero-retention or regional option, and what does it cost in capability? Sometimes a restricted posture rules out specific models or features. Better to learn that during procurement.

Audit and evidence

What is captured in an audit trail, and what is not? The gap matters more than the coverage. Ask specifically whether every execution mode is captured, because local or on-device modes often are not.

Can we export it, and can we delete it centrally? These are separate questions with separately disappointing answers.

Is observability tooling offered as audit logging? Streaming events to a SIEM is useful and is not the same as a compliance record. A vendor who says so unprompted is being straight with you.

Contract and change

How are terms changed, and what notice do we get? Terms in this sector have changed materially and at short notice.

What are the security and incident commitments? Notification timelines, not adjectives.

What is the exit path? Export format, timescale, what survives.

What a good answer sounds like

Specific, dated, and willing to name a gap. "Local sessions are not captured in the compliance API and deletion endpoints for them are not yet available" is a better answer than a paragraph about commitment to privacy, because you can act on it.

Treat vagueness on retention or audit coverage as a finding rather than as sales language.

What goes wrong

Assuming the plan you bought is the plan your people use. Personal accounts sit under different terms, which is a provisioning problem before it is a contractual one.

Accepting a marketing page as an answer. Ask for it in writing, against your plan.

Asking only about the current subprocessor list. The change-notice mechanism outlasts the list.

Confusing observability with audit.

Filing the answers without a date. These change, and an undated answer cannot be checked for currency.

How to check it worked

Pick the three answers that most affect your risk assessment and see whether each names a specific mechanism, a number, or a timescale. Answers that survive rephrasing as "so, concretely, what happens when…" are the ones you can rely on.

Sources

  1. How long do you store my data? — Anthropic Privacy Center Tier 1 2026-08-31
  2. Updates to our Consumer Terms and Privacy Policy — Anthropic Tier 1 2026-08-31
  3. EDPB Opinion on AI models and personal data (Dec 2024) Tier 1 2026-08-31