Skip to content

Procurement, samples and ongoing supply

Ongoing Due Diligence of Data Vendors After Signature

Quick answer

Ongoing due diligence for data vendors means re-verifying, for the life of the contract, the facts you relied on at signature: who owns the data, what consent or contract basis covers it, how personal information is removed, how it is secured and where it now comes from. Run it on two clocks: a scheduled re-attestation (usually annual, tighter for high-risk suppliers) and event-driven reviews when something material changes, such as an acquisition, a breach, litigation or a new upstream source.

By SourceX Editorial · Updated

Initial diligence answers whether you can sign. Ongoing diligence answers whether the answers are still true at delivery twelve, twenty-four or thirty-six months later. Law-firm commentary on data vendors makes the same point: diligence is a process, not an event [1]. The initial questionnaire itself is covered in the data provider due diligence questionnaire guide; this page covers cadence, triggers and what to do when answers drift.

Why diligence decays during a data supply contract

Supplier answers go stale because the underlying data supply chain keeps moving after you sign. A refresh delivery may draw on a new CRM instance, a newly acquired subsidiary's ticket archive, or a contractor workforce that did not exist at onboarding. Each of those can change ownership, consent scope or security posture without changing a single word in the license.

A useful model is the third-party risk life cycle familiar from regulated industries: planning, due diligence and selection, contract negotiation, ongoing monitoring and termination, with oversight scaled to the risk of the activity [9].

Downstream obligations make stale answers expensive. California AB 2013 requires developers of generative AI systems offered to Californians to post documentation about training data [5], and signatories of the EU GPAI Code of Practice commit to keeping a copyright policy up to date [6]. If a supplier's source or rights basis changed mid-contract, your published documentation may now be wrong.

Setting review cadence by supplier risk tier

Review frequency should follow the risk the supplier carries, not a single calendar date for everyone. Use the tiers from your data supplier risk-tiering model and attach a cadence and depth to each.

Illustrative example: invented to show structure; it does not describe an available dataset.

TierTypical profileScheduled reviewDepth
HighRecords about individuals (support transcripts, health-adjacent, finance workflows), recurring refresh deliveries, model-criticalEvery 6 to 12 monthsFull re-attestation, refreshed security evidence, sample re-inspection of a recent delivery
MediumBusiness documents or engineering records with limited personal data, periodic deliveriesAnnualRe-attestation form, change log review, spot check of de-identification records
LowOne-time delivery already ingested, no personal data, no further supplyAt renewal or on trigger onlyConfirm license scope and any deletion or retention duties

A one-time delivery does not end the obligation entirely. If the license has usage limits or termination duties, your review shifts from the supplier to your own compliance, such as removing licensed content from vector indexes when a license ends.

Trigger events that should reopen diligence

A trigger event is any change that could make a prior diligence answer false, and it should start a targeted review within the contract's notice window rather than waiting for the annual cycle. Write the trigger list into the ongoing data supply agreement as a notice obligation, because you will not learn about most of these from monitoring alone.

Illustrative example: invented to show structure; it does not describe an available dataset.

Trigger eventWhat may have changedTargeted questions
Change of control, merger or asset saleWho owns the data and can grant the licenseDoes the acquirer accept the license? Did the data move to a new legal entity?
New upstream source or systemRights and consent basis for new recordsWhich system, which customers, under what terms of service or contract?
Privacy policy or customer contract changeWhether new records are covered for AI trainingEffective date, and which deliveries contain records collected after it
Security incident or breachIntegrity and confidentiality of delivered dataScope, affected deliveries, root cause, remediation evidence
Litigation or regulator inquiry about the dataOwnership or lawful-collection claimsNature of the claim, records affected, any hold or takedown request
New subcontractor or offshore workforceWho touches the data before deliveryNames, locations, access controls; see subcontractor disclosure
De-identification method changeResidual identifiabilityNew method, validation results, sample check
Data subject or customer objectionWhether specific records must be withdrawnRecord identifiers, your deletion or suppression duty

Pair each trigger with an internal owner and a response clock. Counsel owns ownership and litigation triggers, privacy owns consent and de-identification, and security owns incidents. Procurement holds the register and chases the evidence.

What an annual re-attestation should ask

An annual re-attestation is a short, signed statement that the original diligence answers remain true, plus evidence for anything that changed. Keep it much shorter than the onboarding DDQ so suppliers actually complete it; ask for deltas, not a re-run. The FISD Alternative Data Council DDQ, whose 2024 edition adds generative AI questions, is a reasonable reference for which sections to carry forward [3].

Illustrative example: invented to show structure; it does not describe an available dataset.

ANNUAL DATA SUPPLIER RE-ATTESTATION (template)
Supplier legal entity:            [name, registration no.]
License / order reference:        [contract ID, schedules covered]
Review period:                    [start date] to [end date]

1. Ownership and rights
   [ ] No change in ownership of the licensed data or the supplier entity
   [ ] Changes (describe, attach evidence): ______
2. Source systems and collection basis
   List every source system feeding deliveries this period
   (e.g., Zendesk instance, Salesforce org, Jira project, document store)
   [ ] Same as prior attestation  [ ] New sources (attach rights basis)
3. Consent, notice and contract basis
   Privacy policy / customer terms versions in force: ______
   [ ] No change affecting AI-training use
4. Personal data handling
   De-identification method and version: ______
   Date and size of last sample check: ______
   Health records: HIPAA method used (Safe Harbor / Expert Determination)
5. Security
   Incidents affecting licensed data this period: [none / describe]
   Current security evidence attached: ______
6. Subcontractors and workforce
   [ ] No new parties with access  [ ] Changes (names, locations)
7. Claims and requests
   Litigation, regulator inquiries, takedown or deletion requests: ______
Signed by (authorized officer), title, date

For health data, ask which HIPAA method was used and whether it changed; HHS describes Expert Determination and Safe Harbor as the two routes, and neither removes all re-identification risk [7]. If the method moved from Safe Harbor to Expert Determination, request the new determination and its scope.

Monitoring data vendor risk between reviews

Between scheduled reviews, monitor the deliveries themselves, because the data is the best evidence of upstream change. Compare each refresh against the accepted baseline in your training data acceptance criteria: schema drift, new field names, new locales, new date ranges, unexpected record volumes, or identifiers that should have been replaced.

Concrete signals worth automating include a new value in a source_system or tenant_id column, a jump in the share of records containing email or phone patterns after de-identification, a new language in support transcripts, and timestamps that fall before the documented collection start. Any of these is a reason to open a trigger review, even if the supplier has sent no notice.

External signals matter too: press coverage of an acquisition, court dockets naming the supplier, breach notifications and changes to the supplier's public privacy policy. Industry benchmarking of DDQ responses shows which risk areas buyers are pressing hardest on, which helps you decide where to look first [2].

Benchmarking and scoring refreshed answers

Score refreshed answers against both the supplier's own prior answers and what comparable suppliers disclose. A supplier whose security answers were adequate three years ago may now lag what peers routinely provide; Neudata's DDQ wrap-up is one example of how answers are benchmarked across data vendors [2]. Re-run the relevant rows of your data vendor evaluation scorecard so the score reflects the current state, not the onboarding state.

Track three outcomes per review: unchanged, changed with acceptable evidence, and changed with open risk. Only the third needs escalation, but logging all three gives you a defensible history if a regulator, auditor or counterparty later asks how you kept the supply chain under review.

Remedies when answers change

Contract terms decide what you can do when re-diligence finds a problem, so negotiate them before you need them. Useful levers include suspension of future deliveries pending remediation, the right to reject affected deliveries, replacement records, and termination for an uncured rights defect. Commentary on AI data contracting expects vendors to obtain rights in their data and to flow obligations down to their own suppliers, with those obligations surviving the contract [4].

Investment-firm buyers of alternative data have long built these expectations into vendor contracts, and their practice is a useful reference for AI teams [8]. If a defect cannot be cured, plan the exit with your supplier switching playbook so training pipelines do not stall, and decide what happens to records already used in training.

Where SourceX fits in ongoing supply

SourceX sources operational datasets from US companies and manages the commercial process, including licensing agreements and ongoing purchases. Every dataset is rights-reviewed for ownership and consents and delivered under a license that defines records, uses, term and delivery, and diligence materials covering source, rights, preparation and allowed use are prepared per dataset. Personal details such as names, emails, phone numbers and account numbers are removed or replaced before delivery, the method is recorded and a sample is checked, though no method is perfect. Buyers running a supplier program can use these per-dataset materials as inputs to their own reviews; describe what you need on the buyers page.

For the wider program view, see managing many data suppliers, the training data due diligence checklist and the AI training data procurement hub.

Keep data vendor due diligence current with SourceX

SourceX sources operational data from US companies on request, with every release approved by the supplying company and each dataset rights-reviewed and delivered under a license. Nothing is contracted until a supplier agrees, and delivery runs through private, access-controlled workflows only after an executed agreement. Describe the data you need to SourceX.

Sources

  1. [AI Vendor Contracts: Negotiation Tactics and Comprehensive Due Diligence](https://www.foley.com/insights/events/2025/03/ai-vendor-contracts-negotiation-tactics-due-diligence/), Foley & Lardner LLP, 2025.
  2. Neudata, "2025 DDQ wrap-up: Key factors in data vendor risk" (2025). https://www.neudata.co/sentry-intelligence/2025-ddq-wrap-up-key-factors-in-data-vendor-risk
  3. FISD Alternative Data Council, "Data Provider Due Diligence Questionnaire (DDQ) with GenAI questions" (2024). https://fisd.net/wp-content/uploads/2024/02/FISD-Alternative-Data-Council-Due-Diligence-Questionnaire-with-GenAI-Questions-022824.docx
  4. [Key Considerations for Alternative Data and AI Vendors to Investment Firms: Demonstrating Compliance in the Face of an Evolving Regulatory Environment](https://www.lowenstein.com/news-insights/publications/articles/key-considerations-for-alternative-data-and-ai-vendors-to-investment-firms-demonstrating-compliance-in-the-face-of-an-evolving-regulatory-environment), Lowenstein Sandler LLP, 2025.
  5. California Legislature, "AB-2013 Generative artificial intelligence: training data transparency" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
  6. European Commission (AI Office), "General-Purpose AI Code of Practice: Contents of the Code (Copyright chapter)" (2025). https://digital-strategy.ec.europa.eu/policies/contents-code-gpai
  7. U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule" (2012). https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification
  8. Lowenstein Sandler LLP, "Key considerations for alternative data and AI vendors to investment firms". https://www.lowenstein.com/media/iyrpwxij/key-considerations-for-alternative-data-and-ai-vendors-to-investment-firms.pdf
  9. [Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17)](https://www.occ.gov/news-issuances/bulletins/2023/bulletin-2023-17.html), Office of the Comptroller of the Currency, 2023.

Tell us what your models need

Share scope, volume, language, format, timing and licensing requirements.

Request data