Playbook 2 — Vendor & Procurement
Governing AI you buy — which is most of what an SMB actually uses
You’re Probably a Deployer, Not a Developer
Most SMB “AI governance” problems are really vendor-management problems. You’re not training models — you’re turning on an AI feature inside a CRM, using ChatGPT or Claude for content and support, or hiring a contractor whose tools include Copilot. Under the EU AI Act and under plain common sense, your obligations as a deployer are lighter than a developer’s, but they are not zero: you still have to know what you bought, what it does with your data, and what happens when it’s wrong.
Due Diligence Before You Sign — Checklist
- The vendor can explain, in plain language, what the AI feature does and what data it uses to do it.
- The vendor has told us whether our data is used to train their models (and we’ve decided whether that’s acceptable).
- There’s a Data Processing Agreement (DPA) in place if any personal data flows through the tool.
- The vendor states where the data is stored and processed (EU/EEA matters for GDPR).
- There’s a human override — we can turn the AI feature off, or bypass a specific decision, without losing the rest of the product.
- The vendor will tell us if the model or feature changes materially (not just “we update sometimes”).
Contract Clauses to Ask For
- Legal liability: who is responsible if the AI output causes harm or loss — you or the vendor.
- Data use limits: your data is not used to train models for other customers without explicit opt-in.
- Audit / documentation rights: you can request evidence of how the system was validated.
- Traceability: logs of inputs and outputs are retrievable if something goes wrong.
- Exit terms: you can export your data and stop using the AI feature without losing the underlying product.
- IP indemnification: the vendor covers you if generated content infringes third-party copyright (critical if you use generative tools for marketing — see Playbook 7).
Red Flags — Walk Away or Escalate
STOP AND ASK MORE QUESTIONS IF:
The vendor can’t or won’t explain how the AI makes its decisions.
There’s no Data Processing Agreement available on request.
The tool has no way to review, correct, or override an automated output.
The sales rep’s answer to “what happens to our data” is “don’t worry about it.”
It’s being used for a High-tier use case (Playbook 1) and the vendor offers no bias or fairness documentation.
5 Questions for Any AI Vendor — Quick Reference
- What decision does this make or influence, and can a human override it?
- What happens to our data, and is it used to train your models?
- Where is it processed, and is there a DPA?
- How do we know if it’s wrong, and how do we report that?
- What changes if we cancel — do we keep our data and our workflow?
One line worth adding to any vendor questionnaire: ask about GDPR explicitly, and about NIS2 or the Cyber Resilience Act where your sector or the vendor’s position makes either relevant. A single AI vendor relationship can trigger a data processing agreement, a supplier assessment, and AI Act due diligence at once — see EU AI Regulation for SMBs for which of those actually apply to you.
Next Steps
Once a vendor passes this checklist, log the tool in the AI system inventory (Playbook 6) with the risk tier from Playbook 1. If it touches hiring, credit, pricing, or personal data, also run it through Playbook 3 before go-live.