Digital Transformation & Artificial Intelligence

Due Diligence and Contract Terms When Procuring Third-Party AI Tools

Learn to run vendor due diligence on third-party AI tools and negotiate contract terms covering data use, liability, audit rights and exit, before signature rather than after.

Duration5 training days
Content4 modules · 8 sessions
On completionAccredited attendance certificate
About the programme

Course Overview

Procuring an AI tool from a vendor differs from ordinary software procurement because the risk does not end at data security; it extends to how the vendor trains models on customer data, what happens when the tool produces a harmful or incorrect output, and how dependent the organisation becomes on a system it cannot fully audit. This course equips procurement, legal and risk teams to run due diligence that goes beyond a standard security questionnaire, covering the vendor's data handling and training practices, model provenance, incident history and financial stability. It then moves into contract negotiation, working through the specific clauses an AI procurement needs that a standard software agreement often omits: data use and training restrictions, liability allocation for AI-generated harm, audit and inspection rights, service levels appropriate to probabilistic rather than deterministic systems, and an exit plan that allows the organisation to retrieve data and switch providers without disruption. Participants practise drafting and negotiating these clauses against realistic vendor pushback, and learn to recognise contract terms that quietly shift unacceptable risk back onto the customer. The course concludes with building a standard due diligence and contract checklist the organisation can reuse for future AI procurements.

Expected Learning Outcomes

01

Run a due diligence assessment covering an AI vendor's data handling, training practices and incident history.

02

Assess model provenance and the vendor's dependency on upstream foundation model providers.

03

Negotiate data use and training restriction clauses that prevent unwanted use of the organisation's data.

04

Allocate liability for AI-generated harm between vendor and customer in a way that survives negotiation.

05

Secure audit and inspection rights proportionate to the risk the AI tool introduces.

06

Define service levels appropriate to a probabilistic AI system rather than reusing deterministic software terms.

07

Build an exit clause that guarantees data retrieval and a workable transition to an alternative provider.

Who Should Attend

01

Procurement leads sourcing third-party AI tools and platforms

02

Legal counsel drafting and negotiating AI vendor contracts

03

Risk and compliance teams assessing AI supplier exposure

04

IT security teams reviewing AI vendors during onboarding

05

Vendor management teams overseeing existing AI supplier relationships

06

Finance and business owners sponsoring AI tool purchases

Course Modules

Select any module to see its sessions and points.

01

Assessing the Vendor Before Contracting

2 sessions · 8 points

Session 1Due Diligence Beyond the Security Questionnaire

  • Assess the vendor's data handling practices, including retention, storage location and sub-processor use.
  • Determine whether customer data is used to train or fine-tune the vendor's models by default.
  • Review the vendor's model provenance, including reliance on third-party foundation models.
  • Check the vendor's incident history and how past AI failures were disclosed and remediated.

Session 2Assessing Dependency and Continuity Risk

  • Evaluate the vendor's financial stability and the risk of service discontinuation or acquisition.
  • Assess how tightly the organisation's processes would depend on this specific vendor's AI tool.
  • Identify alternative providers in advance so due diligence informs negotiating leverage, not just risk scoring.
  • Document due diligence findings in a form the contract negotiation team can act on directly.
02

Data Use and Risk Allocation Clauses

2 sessions · 8 points

Session 1Data Use and Training Restrictions

  • Draft clauses that prohibit the vendor from training on customer data without explicit, separate consent.
  • Specify data residency, retention and deletion terms consistent with the organisation's own obligations.
  • Require disclosure of sub-processors and downstream model providers that will handle customer data.
  • Set breach notification timelines specific to AI-related data incidents, not only conventional data breaches.

Session 2Liability Allocation for AI-Generated Harm

  • Negotiate liability terms that address harm caused by incorrect or harmful AI-generated output.
  • Challenge blanket disclaimers that shift all responsibility for output accuracy onto the customer.
  • Align liability caps with the actual risk the AI tool introduces to the organisation's operations.
  • Require the vendor to maintain insurance appropriate to the scale of potential AI-related harm.
03

Oversight and Service Terms

2 sessions · 8 points

Session 1Audit and Inspection Rights

  • Negotiate rights to review vendor security certifications, audit reports and testing evidence periodically.
  • Secure the right to request evidence of bias, safety or fairness testing performed on the AI system.
  • Define how audit findings requiring remediation are tracked and enforced under the contract.
  • Scale audit rights to the criticality of the AI tool rather than applying one standard clause to every vendor.

Session 2Service Levels for Probabilistic Systems

  • Define availability and latency service levels appropriate to the AI tool's actual usage pattern.
  • Set quality service levels, such as accuracy thresholds, that reflect the tool's realistic performance.
  • Agree a process for the vendor to notify customers of material model updates or version changes.
  • Include remedies proportionate to service level breaches rather than symbolic penalties alone.
04

Exit Planning and Standardising the Process

2 sessions · 8 points

Session 1Building an Exit and Transition Clause

  • Require the vendor to return customer data in a usable format within a defined period after termination.
  • Specify deletion obligations the vendor must meet and evidence they must provide once data is returned.
  • Plan for a transition period during which both old and new providers may need to operate in parallel.
  • Test the exit clause's practicality against a hypothetical switch before the contract is signed.

Session 2Standardising Due Diligence Across the Organisation

  • Build a reusable due diligence checklist covering data, model, liability and continuity questions.
  • Create contract clause templates that procurement and legal can adapt rather than draft from scratch.
  • Set a review trigger so existing AI vendor contracts are reassessed as regulation and risk evolve.
  • Train procurement staff to recognise AI-specific risks that a generic software checklist would miss.

What the participant receives

4 course modules

A structured syllabus

8 training sessions

across 5 days

32 detailed points

Applied, detailed content

Accredited attendance certificate

On completing the programme

Complete your registration

We will contact you within one business day to confirm.

Ready to start?

Reserve your seat and start building the skill.

Enroll now

Share this course