A quiet reading corner in a modern office at blue hour, an armchair and floor lamp by tall glazing

Choosing a supplier

The questions to ask an AI supplier before you sign anything

Ask who holds the accounts, who owns what gets built, where your data goes and who else touches it, what happens on the day you leave, and who fixes it when something it depends on changes. A supplier worth having answers each of those in a sentence, and the ones who cannot are telling you something useful.

Last checked 20 September 2026

Five questions, a sentence each #

You do not need to understand the technology to buy this well. You need to know where you would stand if the relationship ended badly, and that is decided by five things.

  • Whose name is on the accounts?

    A good answer: yours, with us invited in as a user we can remove. A poor one tells you they intend to be the gatekeeper, whether or not they have thought about it that way.

  • Who owns what you build for us?

    A good answer: you do, in writing, and here is the clause. A poor one tells you nobody has raised it before, which means the default applies and the default is not you.

  • Where does our data go?

    A good answer: a named list of who processes it and where. A poor one tells you they cannot say, so neither can you tell anyone who asks.

  • What happens on the day we leave?

    A good answer: you keep the accounts, you get an export, here is what stops working. A poor one tells you the exit has never been designed, which is how lock in happens quietly.

  • Who fixes it when it breaks?

    A good answer: a named arrangement with a cost attached. A poor one tells you the proposal is incomplete, because things it depends on will change.

Ownership is three separate things #

People ask about ownership as one question and get a reassuring answer about one third of it. Split it up.

  • The accounts. Every subscription, every connected service, every login. If these were bought in the supplier's name, then leaving means rebuilding rather than removing a user.
  • The thing that was built. Whatever was made specifically for you. Under UK law the default for commissioned work is not what most people assume, which is why this one has its own page in who owns what gets built.
  • The data. Your records, your correspondence, and anything the system accumulated while it ran. Ownership of data is less clean a concept than people expect, so the practical question is whether you can get a complete copy out in a usable form, whenever you want, without asking permission.

The data questions, in the order that matters #

UK GDPR requires a written contract whenever a supplier processes personal data on your behalf, and the ICO publishes the list of terms it has to contain. You do not have to memorise that list. You do need to know whether one exists for your arrangement, which is covered in what a data processing agreement is for.

  1. Who else touches it?

    Almost every supplier uses others underneath them. Ask for the list, and ask whether you are told when it changes.

  2. Does any of it leave the UK?

    Sending personal data abroad is its own subject with its own rules. The ICO’s material on international transfers covers when a transfer is restricted, when a country has adequacy, and the contractual routes that exist otherwise. The answer you want from a supplier is a specific one, not a reassurance.

  3. Is any of our content used to improve a model?

    That is a second thing happening to your data, not a footnote to the first, and it deserves a direct answer.

  4. What happens to it when we stop?

    Deletion or return at the end of the contract is one of the terms the ICO says a processor contract has to cover, and it is the one businesses discover they needed after they have left.

Security, without pretending to be an auditor #

A business cannot meaningfully audit a supplier's security, and should not pretend to. What it can do is ask for the things that are checkable.

Cyber Essentials is the most useful of those. Certification is a baseline signal rather than a guarantee, and plenty of competent one person suppliers do not hold it. Absence of it is a reason to ask more, not a reason to walk away.

What Cyber Essentials actually certifies

The NCSC describes it as the minimum standard of cyber security recommended by government, built on five technical controls, delivered through IASME as its official partner. The higher level, Cyber Essentials Plus, adds independent technical testing that those controls work in practice rather than on paper.

The questions about what happens later #

Most disappointment with this kind of work is not about the build. It is about month nine, when something the automation depends on changes and nobody agreed whose job that is. Ask directly what the arrangement is for keeping it working, and what it costs. A proposal with a build price and no running arrangement is an incomplete proposal, which is the point made in full in how much AI automation costs.

Ask, too, what the supplier expects to change underneath the work. Anyone who has built this kind of thing for more than a year has watched a product alter its behaviour without warning, and can say so plainly.

One question that sorts people quickly #

Ask what they would tell you not to automate.

A supplier who has looked at your business has an answer, and it is usually specific: the job that only happens four times a year, the process nobody can describe the same way twice, the decision that turns out to be judgement wearing a checklist.

A supplier with no answer is selling capability rather than solving anything. The patterns are set out in when not to automate something, and the test that separates the two is in which jobs are worth automating.

What to do with the answers #

Write them down and send them back in an email that starts with "just so I have understood". That single habit converts a conversation into a record, gives the supplier a chance to correct anything you misheard, and makes the terms visible to whoever reads it next.

If you want to see what these answers look like written out by a business rather than promised on a call, ours are on our privacy notice, which names the processors we use, what each one does and how long we keep things. What happens on a first conversation with us, before anything is agreed, is set out in what a free audit involves.

Questions people ask

What is the single most important question to ask?
Whose name is on the accounts. If the supplier holds the logins to the software your business runs on, everything else you agree is subject to their goodwill, because the practical ability to remove you is theirs. Accounts in your name, with the supplier invited in, costs nothing to arrange at the start and is close to impossible to unwind later.
Is it fair to ask a small supplier all of this?
Yes, and a good one will be glad you did. None of these questions needs a document or a legal team to answer. They need a sentence each, and a supplier who cannot give a sentence has either not thought about it or would rather you did not.
What if the answers are fine but nobody will write them down?
Then treat the answers as not given. Verbal assurance about ownership, data and exit has no value at the point it matters, which is when the relationship has gone wrong or the person you spoke to has left.
Does the supplier need to be Cyber Essentials certified?
Not necessarily, and the absence of it is not a disqualification for a very small supplier. It is a useful baseline signal, because it shows five specific technical controls have been assessed rather than asserted. What matters more for most businesses is whether the supplier can say clearly where your data sits and who else can reach it.

Where these numbers come from

  1. ICO, Contracts and liabilities between controllers and processors , read 20 September 2026 . Sets out the minimum terms a controller to processor contract must contain, including deletion or return of data at the end.
  2. ICO, International transfers , read 20 September 2026 . Covers restricted transfers, adequacy regulations, the UK IDTA and Addendum, and when a transfer risk assessment is needed.
  3. NCSC, Cyber Essentials overview , read 20 September 2026 . Describes Cyber Essentials as the minimum standard of cyber security recommended by government, built on five technical controls, with a Plus level that tests those controls in practice.

Last checked 20 September 2026.

Our workings are on the methodology page .

Free audit

Find out what the repeated work costs you

The audit counts every job the business repeats, ranks them by the hours they eat, and maps the five worth automating first. It is free, you keep everything, and there is no obligation at the end of it.

AI automation, explained

Plain answers to what businesses ask before they automate anything.

All of ai automation, explained

Read next