Skip to content
Academy
Marketing Academy · Field Work●AI in Marketing
CoreAudit· 40 minutes

The Vendor Cutoff Call: Auditing AI Tools Across the Three Risk Surfaces

Concord Biotech

Objective: Given a table of six AI vendors a marketing team uses, sorted by what data they touch and whether a DPA and disclosure practice exist, decide which vendors get cut off from customer data immediately versus which get flagged for next-quarter review.

You're the marketing operations lead at Concord Biotech, the Ahmedabad-founded fermentation-based API manufacturer. Six AI tools now touch some part of the marketing pipeline, and you've been asked to produce a vendor risk audit before the next budget cycle locks in renewals.

Sort the six vendors by the lesson's three risk surfaces, data privacy, disclosure, vendor risk, and decide which lose data access today.

Before you start

What you'll need

Free path (everything below is enough to finish)

FreeBuild and score the six-vendor risk table

Free, sortable, easy to hand to legal for the DPA follow-up

The process

1 step

Step 01 of 01

Auditing vendor risk across the three risk surfaces before an incident forces the issue

The lesson splits AI governance risk into three separate surfaces, data privacy (customer data pasted into prompts), disclosure (AI content shown without a label), and vendor risk (sub-processors your DPA is your only visibility into), and insists the fix for one does not fix the others.

Of the six vendors, two touch customer PII with no signed DPA, one generates ad copy with no disclosure review step, and one is a sub-processor nobody on the team can even name. Which get data access cut today, and which just go on next quarter's review list?

Google Sheets— Build a 6-row table with columns for data touched, DPA on file, disclosure step exists, and recommended action.

Procedure

  1. List each of the 6 vendors with what customer data they touch
  2. Mark DPA status Y/N for each
  3. Mark whether a disclosure/review step exists before AI-generated content ships
  4. Flag any vendor whose own sub-processors are unknown to the team
  5. Assign each vendor a verdict: cut today, restrict pending DPA, or fine to keep
Sample output
Concord Biotech, AI vendor risk audit (excerpt)

Vendor A (ad-optimization): touches campaign performance data, DPA=N, sub-processor unknown -> CUT TODAY
Vendor B (content generator): no customer data, DPA=N/A, disclosure step=missing -> RESTRICT, add disclosure review before next post
Vendor C (email platform): touches customer contact data, DPA=Y, disclosure=N/A -> KEEP
Vendor D (creator-matching tool): touches customer PII, DPA=N -> CUT TODAY
Vendor E (analytics AI): touches aggregate data only, DPA=Y -> KEEP
Vendor F (chat-based drafting tool): no data connector, DPA=N/A -> KEEP, add to approved-tools list

Healthy

Both PII-touching, no-DPA vendors are cut from data access the same day the gap is found, before renewal, not after.

Unhealthy

Adding a 'cut today' vendor to a 'review next quarter' list because cutting it feels disruptive to the campaign calendar.

What this means

A vendor with real customer data access and no DPA is not a lower-priority risk than one with a bigger contract, the fix has to match the risk surface, not the vendor's size.

So what do I do about it?

SymptomActionEffort
A vendor with unknown sub-processors still has live access to customer PIISuspend that vendor's data connection immediately, restore only after a signed DPA specifies its sub-processor chain5 min
YouYou can do this yourself, no engineering access required.

Final deliverable

A scored vendor risk table with a cut/restrict/keep verdict per vendor and the specific gap driving each verdict.

See a reference example
Sample output
Yatharth Hospital, vendor risk audit (excerpt)

Vendor: patient-review generation tool. Data touched: patient testimonial drafts. DPA: N. Verdict: CUT TODAY, no patient-facing content from this vendor until a signed DPA is on file.

Success criteria

You're done when you can:

  • Every vendor touching real customer data with no DPA is marked cut-today, not deferred
  • The verdict for each vendor traces back to a specific one of the three risk surfaces, not a general impression