The Vendor Cutoff Call: Auditing AI Tools Across the Three Risk Surfaces
Objective: Given a table of six AI vendors a marketing team uses, sorted by what data they touch and whether a DPA and disclosure practice exist, decide which vendors get cut off from customer data immediately versus which get flagged for next-quarter review.
You're the marketing operations lead at Concord Biotech, the Ahmedabad-founded fermentation-based API manufacturer. Six AI tools now touch some part of the marketing pipeline, and you've been asked to produce a vendor risk audit before the next budget cycle locks in renewals.
Sort the six vendors by the lesson's three risk surfaces, data privacy, disclosure, vendor risk, and decide which lose data access today.
Before you start
What you'll need
Free path (everything below is enough to finish)
Free, sortable, easy to hand to legal for the DPA follow-up
The process
1 step
Step 01 of 01
The lesson splits AI governance risk into three separate surfaces, data privacy (customer data pasted into prompts), disclosure (AI content shown without a label), and vendor risk (sub-processors your DPA is your only visibility into), and insists the fix for one does not fix the others.
Of the six vendors, two touch customer PII with no signed DPA, one generates ad copy with no disclosure review step, and one is a sub-processor nobody on the team can even name. Which get data access cut today, and which just go on next quarter's review list?
Procedure
- List each of the 6 vendors with what customer data they touch
- Mark DPA status Y/N for each
- Mark whether a disclosure/review step exists before AI-generated content ships
- Flag any vendor whose own sub-processors are unknown to the team
- Assign each vendor a verdict: cut today, restrict pending DPA, or fine to keep
Concord Biotech, AI vendor risk audit (excerpt) Vendor A (ad-optimization): touches campaign performance data, DPA=N, sub-processor unknown -> CUT TODAY Vendor B (content generator): no customer data, DPA=N/A, disclosure step=missing -> RESTRICT, add disclosure review before next post Vendor C (email platform): touches customer contact data, DPA=Y, disclosure=N/A -> KEEP Vendor D (creator-matching tool): touches customer PII, DPA=N -> CUT TODAY Vendor E (analytics AI): touches aggregate data only, DPA=Y -> KEEP Vendor F (chat-based drafting tool): no data connector, DPA=N/A -> KEEP, add to approved-tools list
Healthy
Both PII-touching, no-DPA vendors are cut from data access the same day the gap is found, before renewal, not after.
Unhealthy
Adding a 'cut today' vendor to a 'review next quarter' list because cutting it feels disruptive to the campaign calendar.
What this means
A vendor with real customer data access and no DPA is not a lower-priority risk than one with a bigger contract, the fix has to match the risk surface, not the vendor's size.
So what do I do about it?
| Symptom | Action | Effort |
|---|---|---|
| A vendor with unknown sub-processors still has live access to customer PII | Suspend that vendor's data connection immediately, restore only after a signed DPA specifies its sub-processor chain | 5 min |
Final deliverable
A scored vendor risk table with a cut/restrict/keep verdict per vendor and the specific gap driving each verdict.
See a reference example
Yatharth Hospital, vendor risk audit (excerpt) Vendor: patient-review generation tool. Data touched: patient testimonial drafts. DPA: N. Verdict: CUT TODAY, no patient-facing content from this vendor until a signed DPA is on file.
Success criteria
You're done when you can:
- Every vendor touching real customer data with no DPA is marked cut-today, not deferred
- The verdict for each vendor traces back to a specific one of the three risk surfaces, not a general impression