Vendor due diligence
What security and privacy questions should you ask an automation vendor?
Review an automation vendor's access, data path, technical controls, subprocessors, incidents, recovery, retention, and exit process.
Start with the proposed access
List the systems, fields, and actions needed for the job. A workflow that routes public contact requests should not automatically receive administrator access to billing, employee files, or the entire customer database. Ask why each permission is needed and whether a narrower role, test account, or limited dataset will work.
Use business-owned accounts, individual identities, multifactor authentication where available, least privilege, and time-bounded consultant access. Avoid sending passwords through email. Log access where the system supports it and remove external access promptly when the project or support period ends.
Draw the data path in plain language
The vendor should be able to explain what is collected, where it is processed and stored, which service providers or subcontractors receive it, how long each copy remains, and how deletion or return works. If AI is involved, identify the specific product and verify its current training, retention, and data-use terms.
Ask about data location when it matters to contracts, customers, or applicable obligations. Minimize what enters the workflow and keep sensitive customer content out of routine logs and email alerts.
Look for controls and evidence proportionate to risk
Ask how the vendor protects data in transit and at rest, manages patches and vulnerabilities, separates customer access, records administrative activity, and protects the devices and project records used by its staff. For higher-consequence work, ask for appropriate independent assurance rather than accepting a policy document as proof of every control.
Evidence should match the claim and the size of the engagement. A low-risk form routing project does not require the same review as a workflow handling payment, health, or employee information, but a small vendor should still be able to explain what it actually does.
- Which controls are operated by the vendor, customer, and platform provider?
- How are security updates and reported vulnerabilities handled?
- What audit or activity records are available to the business?
- How is deletion confirmed when access or the engagement ends?
Test failure, backup, and recovery claims
Ask how failed work is detected, where protected exception records are kept, and who responds. A backup statement is incomplete without the configuration and data covered, retention, restoration process, and evidence that recovery is tested.
For an incident, understand the contact path, notification timing, investigation support, containment, and recovery commitments. The business's own response obligations depend on the information and applicable agreements or rules, so have the arrangement reviewed when the risk warrants it.
Put the important answers into the project
Record permitted data use, account ownership, deliverables, support boundaries, deletion or return of information, removal of access, and the exit path. Make sure another qualified person can understand the workflow and that the business controls the essential accounts and documentation.
Repeat the review before adding a new data source, customer group, or consequential decision. A contained first project makes the review practical because its systems, duration, and result are explicit.
Better follow-up and less busywork for small businesses. Have a task like this? Tell me what happens today and what you’d like to change.
Book a 20-minute call