Run a due diligence assessment covering an AI vendor's data handling, training practices and incident history.
Due Diligence and Contract Terms When Procuring Third-Party AI Tools
Learn to run vendor due diligence on third-party AI tools and negotiate contract terms covering data use, liability, audit rights and exit, before signature rather than after.
Course Overview
Procuring an AI tool from a vendor differs from ordinary software procurement because the risk does not end at data security; it extends to how the vendor trains models on customer data, what happens when the tool produces a harmful or incorrect output, and how dependent the organisation becomes on a system it cannot fully audit. This course equips procurement, legal and risk teams to run due diligence that goes beyond a standard security questionnaire, covering the vendor's data handling and training practices, model provenance, incident history and financial stability. It then moves into contract negotiation, working through the specific clauses an AI procurement needs that a standard software agreement often omits: data use and training restrictions, liability allocation for AI-generated harm, audit and inspection rights, service levels appropriate to probabilistic rather than deterministic systems, and an exit plan that allows the organisation to retrieve data and switch providers without disruption. Participants practise drafting and negotiating these clauses against realistic vendor pushback, and learn to recognise contract terms that quietly shift unacceptable risk back onto the customer. The course concludes with building a standard due diligence and contract checklist the organisation can reuse for future AI procurements.
Expected Learning Outcomes
Assess model provenance and the vendor's dependency on upstream foundation model providers.
Negotiate data use and training restriction clauses that prevent unwanted use of the organisation's data.
Allocate liability for AI-generated harm between vendor and customer in a way that survives negotiation.
Secure audit and inspection rights proportionate to the risk the AI tool introduces.
Define service levels appropriate to a probabilistic AI system rather than reusing deterministic software terms.
Build an exit clause that guarantees data retrieval and a workable transition to an alternative provider.
Who Should Attend
Procurement leads sourcing third-party AI tools and platforms
Legal counsel drafting and negotiating AI vendor contracts
Risk and compliance teams assessing AI supplier exposure
IT security teams reviewing AI vendors during onboarding
Vendor management teams overseeing existing AI supplier relationships
Finance and business owners sponsoring AI tool purchases
Course Modules
Select any module to see its sessions and points.
01Assessing the Vendor Before Contracting
2 sessions · 8 points
Session 1Due Diligence Beyond the Security Questionnaire
- Assess the vendor's data handling practices, including retention, storage location and sub-processor use.
- Determine whether customer data is used to train or fine-tune the vendor's models by default.
- Review the vendor's model provenance, including reliance on third-party foundation models.
- Check the vendor's incident history and how past AI failures were disclosed and remediated.
Session 2Assessing Dependency and Continuity Risk
- Evaluate the vendor's financial stability and the risk of service discontinuation or acquisition.
- Assess how tightly the organisation's processes would depend on this specific vendor's AI tool.
- Identify alternative providers in advance so due diligence informs negotiating leverage, not just risk scoring.
- Document due diligence findings in a form the contract negotiation team can act on directly.
02Data Use and Risk Allocation Clauses
2 sessions · 8 points
Session 1Data Use and Training Restrictions
- Draft clauses that prohibit the vendor from training on customer data without explicit, separate consent.
- Specify data residency, retention and deletion terms consistent with the organisation's own obligations.
- Require disclosure of sub-processors and downstream model providers that will handle customer data.
- Set breach notification timelines specific to AI-related data incidents, not only conventional data breaches.
Session 2Liability Allocation for AI-Generated Harm
- Negotiate liability terms that address harm caused by incorrect or harmful AI-generated output.
- Challenge blanket disclaimers that shift all responsibility for output accuracy onto the customer.
- Align liability caps with the actual risk the AI tool introduces to the organisation's operations.
- Require the vendor to maintain insurance appropriate to the scale of potential AI-related harm.
03Oversight and Service Terms
2 sessions · 8 points
Session 1Audit and Inspection Rights
- Negotiate rights to review vendor security certifications, audit reports and testing evidence periodically.
- Secure the right to request evidence of bias, safety or fairness testing performed on the AI system.
- Define how audit findings requiring remediation are tracked and enforced under the contract.
- Scale audit rights to the criticality of the AI tool rather than applying one standard clause to every vendor.
Session 2Service Levels for Probabilistic Systems
- Define availability and latency service levels appropriate to the AI tool's actual usage pattern.
- Set quality service levels, such as accuracy thresholds, that reflect the tool's realistic performance.
- Agree a process for the vendor to notify customers of material model updates or version changes.
- Include remedies proportionate to service level breaches rather than symbolic penalties alone.
04Exit Planning and Standardising the Process
2 sessions · 8 points
Session 1Building an Exit and Transition Clause
- Require the vendor to return customer data in a usable format within a defined period after termination.
- Specify deletion obligations the vendor must meet and evidence they must provide once data is returned.
- Plan for a transition period during which both old and new providers may need to operate in parallel.
- Test the exit clause's practicality against a hypothetical switch before the contract is signed.
Session 2Standardising Due Diligence Across the Organisation
- Build a reusable due diligence checklist covering data, model, liability and continuity questions.
- Create contract clause templates that procurement and legal can adapt rather than draft from scratch.
- Set a review trigger so existing AI vendor contracts are reassessed as regulation and risk evolve.
- Train procurement staff to recognise AI-specific risks that a generic software checklist would miss.
What the participant receives
4 course modules
A structured syllabus
8 training sessions
across 5 days
32 detailed points
Applied, detailed content
Accredited attendance certificate
On completing the programme
Complete your registration
We will contact you within one business day to confirm.
Ready to start?
Reserve your seat and start building the skill.
