Business IT projects · Across Québec Request a quoteFrançais

AI vendor assessment

An AI vendor assessment examines, before a tool is adopted or renewed, what the vendor does with your company's data: use for training its models, hosting and processing location, subcontractors, security measures and written commitments in the contract.

Updated on

It focuses on one vendor and one specific offer, whereas the AI usage policy sets internal rules and the AI governance page presents the overall approach. The Canadian Centre for Cyber Security's baseline cyber security controls ask organizations to determine their level of comfort with how their external IT providers handle and access their sensitive information (BC.10.2). The assessment answers that question for an AI tool.

Short answer

You describe the AI tool in question, its intended use and the data that would be entered into it: your request is reviewed by the Courtier TI team, then entrusted to the IT services company that will prepare your quote. The scope of the assessment and the deliverables are set with you.

What the quote should cover

  • A description of the intended use and the data that would be entered into the tool
  • A review of the vendor's public documents: terms of use, privacy policy, data documentation
  • The vendor's answers to a written questionnaire
  • Analysis of model training, hosting location and subcontractors
  • Review of the contract clauses dealing with personal information
  • The IT elements needed for the privacy impact assessment
  • A report with open issues and recommended settings

The steps of an AI vendor assessment

  1. Scoping: tool, offer, intended use, types of data
  2. Review of the vendor's public documents
  3. Written questionnaire to the vendor and follow-up on answers
  4. Analysis of training, hosting and subcontractors
  5. Review of contract clauses with your legal advisers
  6. Report, recommended settings and management decision

Reading the vendor's public documents

The Government of Canada guide on the use of generative AI, written for federal institutions, recommends asking legal services to review a supplier's terms of use and privacy policy. These documents are the starting point, but they do not always distinguish each offer.

Two examples, read on October 9, 2026, show why the specific offer matters. OpenAI's enterprise privacy page states that data from its business offerings is not used to train its models by default, unless the customer has chosen to share it; the same page states that data from versions offered to individuals may be used for training, depending on the settings chosen by the user. Microsoft's documentation on Microsoft 365 Copilot privacy states that prompts and responses are not used to train foundation large language models, and that queries from customers outside the European Union may be processed in the US, the EU or other regions.

These examples are not a tool recommendation. Vendor documents change: the assessment records the date read and the version of each document.

Model training: what to have clarified

  • Are the data entered and the responses used to train models, and in which offer?
  • The default setting, and how to opt out
  • Data received through connectors or integrations with your software
  • Any review of conversations by vendor staff or subcontractors, and for what purposes
  • How long prompts are kept and whether they can be deleted
  • What happens to the data at the end of the contract

The federal guide also recommends understanding how a system uses input data and using the opt-out feature where possible.

Hosting location and communication outside Québec

If the tool processes personal information outside Québec, section 17 of the Act respecting the protection of personal information in the private sector requires a privacy impact assessment before the information is communicated. It takes into account, among other things, the sensitivity of the information, the purposes for which it is to be used, the protection measures, including contractual ones, and the legal framework of the State where it would be communicated. The communication must be the subject of a written agreement; the rule also applies when you entrust a body outside Québec with collecting, using, communicating or keeping such information on your behalf.

The Centre's baseline controls also recommend knowing the legal jurisdictions where providers store or use sensitive information (BC.10.3). The assessment therefore lists the announced processing regions, the data residency options offered, and the features that send data to other services, such as built-in web search.

The contract and section 18.3

When you communicate personal information to a vendor so it can perform a service contract, section 18.3 requires a written contract. It must specify the measures the vendor takes to protect confidentiality, to ensure the information is used only to carry out the contract, and to ensure it is not kept after the contract expires. The vendor must also notify your person in charge of the protection of personal information without delay of any violation or attempted violation, and allow that person to conduct any verification relating to confidentiality.

Large vendors' standard contracts are rarely negotiable for an SMB. The assessment therefore checks whether the data processing agreement offered covers these elements and flags the gaps, so management can decide with full knowledge, together with its legal advisers.

Questions to ask yourself before requesting a quote

  • Which tool and which specific offer do you want assessed?
  • Which tasks will the tool be used for, and by whom?
  • Will personal or confidential information be entered into it?
  • Will the tool be connected to your software or files?
  • Who is your person in charge of the protection of personal information?
  • Who will make the final decision to adopt the tool or not?

Pitfalls to avoid

  • Assessing the consumer version when the company will use a business offer, or the reverse
  • Relying on a marketing page rather than the terms and the data processing agreement
  • Forgetting connectors and features that send data to other services
  • Not recording the date of the documents read
  • Accepting the contract without checking the elements required by section 18.3
  • Treating the assessment as final when offers and terms change

What to specify in your request

  • The name of the tool and the offer considered
  • The intended use and the teams involved
  • The types of data that would be entered
  • Planned integrations with your software
  • Documents already received from the vendor
  • The deliverables wanted: report, questionnaire, input for the privacy impact assessment

You can then describe your project: the team will contact you to clarify your needs and provide a quote.

Frequently asked questions

Is the vendor's privacy policy enough?

It is a starting point, but it does not always answer the questions specific to your use: the offer, default settings, subcontractors, processing location. The Government of Canada guide recommends having legal services review the terms of use and privacy policy.

Does a business offer always exclude model training?

Not necessarily. Some vendors state this for their business offers, with exceptions such as voluntary data sharing. You need to read the documents for the specific offer and check the settings enabled in your account.

Is a privacy impact assessment needed to adopt an AI tool?

If the tool is an information system acquired to process personal information, section 3.3 of the Act calls for a privacy impact assessment. If the information is communicated outside Québec, section 17 requires one before the communication. The vendor assessment provides the IT input for that analysis.

What if the vendor processes data outside Québec?

The communication remains possible if the assessment required by section 17 establishes that the information would receive adequate protection, and it must be the subject of a written agreement. The assessment also lists the data residency options offered by the vendor.

Is this assessment legal advice?

No. It gathers the technical and contractual facts about the vendor. Interpreting the Act and deciding to adopt the tool are up to the company, its person in charge of the protection of personal information and its legal advisers.

AI vendor assessment

Usage policy, tool inventory and Law 25

Request a quote