An AI vendor review for small business is the short, written check you run before staff are allowed to put company data into a new AI tool. It answers six questions: whether your data trains the model, how long prompts and outputs are retained, which companies sit underneath the vendor, whether there is a real data processing agreement rather than a terms-of-service page, what happens to your data when you cancel, and whether the free plan carries the same terms as the paid one. We run this review in under an hour per tool. The reason it gets skipped at 10 to 200 people is not laziness. It is that every checklist published online runs 30 questions long and reads as all-or-nothing, so it never starts.
Five Things Worth Settling Before You Approve Any AI Tool
This is for an operations lead or owner at a company between 10 and 200 people, running lean, with no in-house counsel and no procurement team.
- Four of the six answers are deal breakers, and the rest are preferences. If you only have twenty minutes, spend it on training, retention, subprocessors, and exit. The rest can wait.
- A terms-of-service page is not an agreement. The vendor can change it on a Tuesday without telling you. A data processing agreement is signed by both sides.
- The free plan is usually where your exposure lives. Staff sign up on free tiers, and free tiers frequently allow training on your content when the paid tier does not.
- Your own data classification decides whether the vendor’s answer even matters. A tool that trains on everything is fine for public marketing copy and wrong for patient records.
- The review has to repeat. Vendors add subprocessors and rewrite terms quietly, so a one-time approval goes stale inside a year.
Why AI Vendor Review for Small Business Breaks Down at 10 to 200 People
An AI vendor review for small business breaks down because the published guidance was written for companies with a procurement function, and a 40-person firm has an operations lead doing it between two other jobs. We see the same pattern in the field almost every week. Someone in marketing finds a writing assistant, someone in finance finds a document summarizer, and by the time anyone asks about data terms there are nine AI tools in the building and three of them have already seen customer records.
The honest counterargument is that heavy review slows the business down, and that is not wrong. A 30-question questionnaire for a 20-dollar-a-month tool is disproportionate, and it teaches your team that approval is theater to be routed around. That is the real failure mode. Not an unreviewed tool, but a process so heavy that staff stop declaring tools at all.
So the position we take with clients is neither of those extremes. Run a short review that is genuinely short, make four answers non-negotiable, and let the rest be judgment. The same logic that governs how you manage third party vendor access to your systems applies here, because an AI vendor is a third-party processor wearing friendlier packaging.
Does the tool cost decide how much review it gets?
Price is a poor proxy for exposure in AI vendor review, and this is where most small teams get it backwards. A free browser extension that reads every page an employee visits carries far more exposure than a 15,000-dollar platform sitting behind a signed contract and single sign-on. We size the review by what data the tool can reach, not by what it costs.
There is a reasonable case for the opposite view. Spend thresholds are simple, they map onto approval authority that already exists, and they require no judgment from the person filling out the form. For a company with no security staff, a rule anyone can apply beats a better rule nobody applies.
Both hold in practice. The workable middle is a two-question gate: can this tool see customer data, employee data, or anything you would not publish, and can it act on systems rather than only read text. A yes to either sends the tool to the full six-question review regardless of price.
Who actually signs off on a new AI tool?
One named person signs off, and at 10 to 200 people it should be whoever already owns vendor risk, usually the operations lead or the owner. AI tools stall in approval limbo when nobody is named, because everyone assumes IT will handle it and IT was never told the tool existed.
The counterweight is that a single approver becomes a bottleneck and gets routed around during a busy month. Distributed approval, where each department head clears their own tools against a shared standard, scales better and keeps the decision close to the work.
We split it by exposure. Department heads clear read-only text tools against the written standard. Anything touching regulated data or holding write access goes to the single named approver, and that approval gets recorded with a date. The record matters more than the signature, because it is what lets you re-review later.
The 6 Costly Blind Spots in an AI Vendor Review for Small Business
The six blind spots below are the ones we find most often when we audit what a company has already approved. Each one is a question with a written answer, not a feeling about the vendor.
1. Training on your data, and whether the answer is contractual
Ask whether prompts, uploaded files, and outputs are used to train or fine-tune any model, first-party or third-party, and get the answer in the agreement rather than in a support email. The distinction that matters is between a setting you can toggle and a commitment the vendor cannot quietly reverse. A toggle can be reset by a product update or a plan change. A contractual no cannot.
Push one step further and ask whether the commitment flows down to the foundation model provider sitting underneath. Many AI products are a layer over someone else’s model, and a vendor can honestly promise not to train while passing your text to a provider whose own terms allow it.
2. Retention windows nobody asked about
Ask how long prompts, outputs, and conversation history are retained by default, and whether retention is configurable down to zero for logs. Most teams assume a chat window disappears when they close it. In practice the transcript often persists for a fixed window for abuse monitoring, and human reviewers may read flagged content.
Retention is also where the AI question stops being an AI question and becomes an incident question. Whatever the vendor holds is inside your blast radius if they are breached, which is the same arithmetic behind our data breach and incident response work. Long retention on a tool that has seen client files turns a vendor’s bad week into your notification obligation.
3. The subprocessor list you were never shown
Ask for the current subprocessor list and the notice period for additions, and treat a refusal as an answer. A vendor telling you their subprocessors are confidential for competitive reasons is not protecting a trade secret, because processor-level transparency is a standard expectation under GDPR Article 28 and most state privacy statutes now echo it.
The practical ask is modest. A named list, thirty days advance notice on additions, and a right to object. If the vendor cannot produce a list, you cannot tell which countries your data sits in or how many companies are one breach away from your records. The same visibility problem is why securing third party vendor access starts with an inventory rather than a control.
4. A terms-of-service page standing in for an agreement
Ask for a data processing agreement, and do not accept the answer that the terms of service already cover it. Those are different instruments. A terms-of-service page is unilateral, and the vendor amends it whenever they choose, often with notice by website posting. A data processing agreement is bilateral and binds both parties to what was agreed on the day you signed.
For regulated data the gap is wider still. If you handle protected health information, a data processing agreement is not sufficient on its own and you need a business associate agreement, which many AI vendors will not sign at all. That single answer disqualifies a tool faster than anything else on this list, and it is worth asking before the trial rather than after, alongside how SMBs cut risk before the 2026 HIPAA Security Rule overhaul.
5. Exit terms, and what leaves with you
Ask what happens to your data when you cancel, on what timetable, and whether you get an export before deletion. Two answers are worth having in writing: a deletion window measured in days rather than left open, and confirmation that deletion covers backups and derived data such as embeddings, not only the records visible in your account.
Exit terms are the least glamorous question here and the one that costs the most when it goes unasked. A tool your team has used for eighteen months holds a working archive of how your business operates, and losing access on thirty days notice is a continuity problem, which is why we fold AI tools into business continuity planning.
6. The free tier your staff already signed up on
Check the terms of the plan your people are actually using, because the free tier and the paid tier of the same product regularly carry different data terms. The paid plan may promise no training and offer a data processing agreement while the free plan of the same product allows training by default and offers no agreement at all.
This is the blind spot that quietly breaks the other five. A review can clear a vendor on enterprise terms, get recorded as approved, and mean nothing, because the version in the building is the free one somebody signed up for with a work email. Approval has to name the plan and the account, not just the product.
Matching the Answers to Your Own Data
The six answers only mean something once you have decided what data may enter an AI tool at all, and that decision is yours rather than the vendor’s. Three tiers are enough for most companies this size: content you would publish, internal content you would not, and regulated or contractual data covered by an obligation to somebody else.
A tool that trains on everything and keeps prompts for a year is a reasonable choice for the first tier and a poor one for the third. Without those tiers written down, every vendor answer becomes an abstract debate, and the debate usually resolves in favor of whoever wants the tool.
Diary the review, because vendor terms and subprocessor lists change without announcement. An annual re-read of the six answers on your top five AI tools takes an afternoon, and it pairs with the annual cycle you already run for cyber insurance requirements owners miss before renewal, since insurers have started asking what AI tools touch your data.
Frequently Asked Questions
How long should an AI vendor review take at a small company?
A first-pass AI vendor review should take under an hour per tool once you have the six questions written down. Most answers are already published in the vendor’s trust center or security page, and the ones that are not become an email to their sales contact. If a vendor takes more than two weeks to answer four plain questions about data handling, that delay is itself an answer.
Which of the six answers are actual deal breakers?
Four are: training on your data without a contractual opt-out, undisclosed subprocessors, no data processing agreement, and no defined deletion timetable on exit. Retention length and free-tier differences are usually manageable with a plan change or a rule about what staff may paste in. The four hard ones cannot be managed around from your side.
Does a small business really need a data processing agreement for an AI tool?
If the tool can see personal data about customers or employees, yes. A data processing agreement is what makes the vendor’s obligations enforceable and survives changes to their public terms. For tools that only ever touch published marketing copy, the case is much weaker and a documented decision to skip it is defensible.
What should we do about AI tools staff are already using?
Inventory first, then review the ones with real exposure, and resist starting with a ban. A ban moves usage onto personal accounts where you have no visibility at all. Our guide on AI agents and data privacy covers how that exposure builds up when nobody is counting.
How often should we re-run the review?
Once a year for your main tools, and immediately on two triggers: the vendor announces a new subprocessor, or you start putting a new class of data into a tool you already approved. The second trigger is the one teams forget, because the tool did not change but your exposure did.
Who You Are Taking This From
Our team has run vendor reviews for companies between 10 and 200 people across managed IT, healthcare, professional services, and manufacturing, and the AI wave has not changed the mechanics much. It has changed the speed. Tools now arrive by the week, they are adopted by individuals rather than departments, and the trial is free, so the old assumption that procurement sees every vendor no longer holds. What we bring is a review short enough that your team will actually run it, and the judgment to tell you which answers are worth a fight.
Mindcore is led by Matt Rosenthal, who focuses on getting security and compliance decisions to a place where they help a business move faster rather than slower. That is the standard we hold this review to. If it does not fit inside a normal working day, it is too heavy for a company your size.
Put the Six Questions to Work
You do not need a policy document or a procurement function to fix this. You need the six questions written on one page, one named approver, a note of which plan and account each approval covers, and a date to look at it again next year. Start with the AI tools already in the building rather than the next one somebody proposes, because that is where your current exposure sits. Rank them by what data they can reach, take the top five, and get written answers on training, retention, subprocessors, and exit.
Most of what you need is already published on the vendors’ own sites, and the gaps you find in an afternoon will tell you more than any sales call. Where it gets harder is the regulated end, when a tool has already seen data covered by an obligation to a client or a patient, and some of those tools have to be replaced rather than reviewed.
That is the work we do with clients every week, and it is the same discipline behind how we manage third party cyber security risks generally. If you want a second set of eyes on the AI tools already running in your business, book a free strategy call and we will go through your list with you.

