Skip to content
Amrani Academy

3. Building your AI policy and approving tools

Assessing an AI vendor

Before approving any AI tool, get written answers to a short set of questions. Vendors serious about business customers answer these routinely; a vendor who can't or won't answer them has answered a different question for you.

The core questions

  • Where does our data go? Which company processes it, in which country, and does any subprocessor see it?
  • Is our input used to train models? This is the single most important question. Many consumer tiers may use input for training unless you opt out; business and enterprise tiers typically commit contractually that customer data is not used for training. Get the commitment in writing, for the specific tier you're buying.
  • How long is data retained? Can retention be configured or disabled, and what happens to our data when we leave?
  • Where is data stored and processed? For UK firms handling personal data, UK or EU data residency simplifies your data protection position considerably. If data goes elsewhere, you need appropriate transfer safeguards in place.
  • What security assurance exists? Recognised certifications such as ISO 27001 or an SOC 2 report are a reasonable baseline signal. So is a willingness to complete your security questionnaire.
  • What admin controls do we get? Central user management, single sign-on, usage visibility, and the ability to disable features or offboard leavers matter more in practice than most feature comparisons.

Free tiers versus enterprise tiers

The same product can be a poor choice on a free personal tier and a defensible one on an enterprise agreement, because the contract, the data handling terms, and the admin controls are different even when the underlying model is identical. When staff ask why they can't just use the free version, that's the honest answer: you're not buying the model, you're buying the terms and the controls around it.

Course contents