Procurement, samples and ongoing supply
Ongoing Due Diligence of Data Vendors After Signature
Quick answer
Ongoing due diligence for data vendors means re-verifying, for the life of the contract, the facts you relied on at signature: who owns the data, what consent or contract basis covers it, how personal information is removed, how it is secured and where it now comes from. Run it on two clocks: a scheduled re-attestation (usually annual, tighter for high-risk suppliers) and event-driven reviews when something material changes, such as an acquisition, a breach, litigation or a new upstream source.
By SourceX Editorial · Updated
Initial diligence answers whether you can sign. Ongoing diligence answers whether the answers are still true at delivery twelve, twenty-four or thirty-six months later. Law-firm commentary on data vendors makes the same point: diligence is a process, not an event [1]. The initial questionnaire itself is covered in the data provider due diligence questionnaire guide; this page covers cadence, triggers and what to do when answers drift.
Why diligence decays during a data supply contract
Supplier answers go stale because the underlying data supply chain keeps moving after you sign. A refresh delivery may draw on a new CRM instance, a newly acquired subsidiary's ticket archive, or a contractor workforce that did not exist at onboarding. Each of those can change ownership, consent scope or security posture without changing a single word in the license.
A useful model is the third-party risk life cycle familiar from regulated industries: planning, due diligence and selection, contract negotiation, ongoing monitoring and termination, with oversight scaled to the risk of the activity [9].
Downstream obligations make stale answers expensive. California AB 2013 requires developers of generative AI systems offered to Californians to post documentation about training data [5], and signatories of the EU GPAI Code of Practice commit to keeping a copyright policy up to date [6]. If a supplier's source or rights basis changed mid-contract, your published documentation may now be wrong.
Setting review cadence by supplier risk tier
Review frequency should follow the risk the supplier carries, not a single calendar date for everyone. Use the tiers from your data supplier risk-tiering model and attach a cadence and depth to each.
Illustrative example: invented to show structure; it does not describe an available dataset.
| Tier | Typical profile | Scheduled review | Depth |
|---|---|---|---|
| High | Records about individuals (support transcripts, health-adjacent, finance workflows), recurring refresh deliveries, model-critical | Every 6 to 12 months | Full re-attestation, refreshed security evidence, sample re-inspection of a recent delivery |
| Medium | Business documents or engineering records with limited personal data, periodic deliveries | Annual | Re-attestation form, change log review, spot check of de-identification records |
| Low | One-time delivery already ingested, no personal data, no further supply | At renewal or on trigger only | Confirm license scope and any deletion or retention duties |
A one-time delivery does not end the obligation entirely. If the license has usage limits or termination duties, your review shifts from the supplier to your own compliance, such as removing licensed content from vector indexes when a license ends.
Trigger events that should reopen diligence
A trigger event is any change that could make a prior diligence answer false, and it should start a targeted review within the contract's notice window rather than waiting for the annual cycle. Write the trigger list into the ongoing data supply agreement as a notice obligation, because you will not learn about most of these from monitoring alone.
Illustrative example: invented to show structure; it does not describe an available dataset.
| Trigger event | What may have changed | Targeted questions |
|---|---|---|
| Change of control, merger or asset sale | Who owns the data and can grant the license | Does the acquirer accept the license? Did the data move to a new legal entity? |
| New upstream source or system | Rights and consent basis for new records | Which system, which customers, under what terms of service or contract? |
| Privacy policy or customer contract change | Whether new records are covered for AI training | Effective date, and which deliveries contain records collected after it |
| Security incident or breach | Integrity and confidentiality of delivered data | Scope, affected deliveries, root cause, remediation evidence |
| Litigation or regulator inquiry about the data | Ownership or lawful-collection claims | Nature of the claim, records affected, any hold or takedown request |
| New subcontractor or offshore workforce | Who touches the data before delivery | Names, locations, access controls; see subcontractor disclosure |
| De-identification method change | Residual identifiability | New method, validation results, sample check |
| Data subject or customer objection | Whether specific records must be withdrawn | Record identifiers, your deletion or suppression duty |
Pair each trigger with an internal owner and a response clock. Counsel owns ownership and litigation triggers, privacy owns consent and de-identification, and security owns incidents. Procurement holds the register and chases the evidence.
What an annual re-attestation should ask
An annual re-attestation is a short, signed statement that the original diligence answers remain true, plus evidence for anything that changed. Keep it much shorter than the onboarding DDQ so suppliers actually complete it; ask for deltas, not a re-run. The FISD Alternative Data Council DDQ, whose 2024 edition adds generative AI questions, is a reasonable reference for which sections to carry forward [3].
Illustrative example: invented to show structure; it does not describe an available dataset.
ANNUAL DATA SUPPLIER RE-ATTESTATION (template)
Supplier legal entity: [name, registration no.]
License / order reference: [contract ID, schedules covered]
Review period: [start date] to [end date]
1. Ownership and rights
[ ] No change in ownership of the licensed data or the supplier entity
[ ] Changes (describe, attach evidence): ______
2. Source systems and collection basis
List every source system feeding deliveries this period
(e.g., Zendesk instance, Salesforce org, Jira project, document store)
[ ] Same as prior attestation [ ] New sources (attach rights basis)
3. Consent, notice and contract basis
Privacy policy / customer terms versions in force: ______
[ ] No change affecting AI-training use
4. Personal data handling
De-identification method and version: ______
Date and size of last sample check: ______
Health records: HIPAA method used (Safe Harbor / Expert Determination)
5. Security
Incidents affecting licensed data this period: [none / describe]
Current security evidence attached: ______
6. Subcontractors and workforce
[ ] No new parties with access [ ] Changes (names, locations)
7. Claims and requests
Litigation, regulator inquiries, takedown or deletion requests: ______
Signed by (authorized officer), title, date
For health data, ask which HIPAA method was used and whether it changed; HHS describes Expert Determination and Safe Harbor as the two routes, and neither removes all re-identification risk [7]. If the method moved from Safe Harbor to Expert Determination, request the new determination and its scope.
Monitoring data vendor risk between reviews
Between scheduled reviews, monitor the deliveries themselves, because the data is the best evidence of upstream change. Compare each refresh against the accepted baseline in your training data acceptance criteria: schema drift, new field names, new locales, new date ranges, unexpected record volumes, or identifiers that should have been replaced.
Concrete signals worth automating include a new value in a source_system or tenant_id column, a jump in the share of records containing email or phone patterns after de-identification, a new language in support transcripts, and timestamps that fall before the documented collection start. Any of these is a reason to open a trigger review, even if the supplier has sent no notice.
External signals matter too: press coverage of an acquisition, court dockets naming the supplier, breach notifications and changes to the supplier's public privacy policy. Industry benchmarking of DDQ responses shows which risk areas buyers are pressing hardest on, which helps you decide where to look first [2].
Benchmarking and scoring refreshed answers
Score refreshed answers against both the supplier's own prior answers and what comparable suppliers disclose. A supplier whose security answers were adequate three years ago may now lag what peers routinely provide; Neudata's DDQ wrap-up is one example of how answers are benchmarked across data vendors [2]. Re-run the relevant rows of your data vendor evaluation scorecard so the score reflects the current state, not the onboarding state.
Track three outcomes per review: unchanged, changed with acceptable evidence, and changed with open risk. Only the third needs escalation, but logging all three gives you a defensible history if a regulator, auditor or counterparty later asks how you kept the supply chain under review.
Remedies when answers change
Contract terms decide what you can do when re-diligence finds a problem, so negotiate them before you need them. Useful levers include suspension of future deliveries pending remediation, the right to reject affected deliveries, replacement records, and termination for an uncured rights defect. Commentary on AI data contracting expects vendors to obtain rights in their data and to flow obligations down to their own suppliers, with those obligations surviving the contract [4].
Investment-firm buyers of alternative data have long built these expectations into vendor contracts, and their practice is a useful reference for AI teams [8]. If a defect cannot be cured, plan the exit with your supplier switching playbook so training pipelines do not stall, and decide what happens to records already used in training.
Where SourceX fits in ongoing supply
SourceX sources operational datasets from US companies and manages the commercial process, including licensing agreements and ongoing purchases. Every dataset is rights-reviewed for ownership and consents and delivered under a license that defines records, uses, term and delivery, and diligence materials covering source, rights, preparation and allowed use are prepared per dataset. Personal details such as names, emails, phone numbers and account numbers are removed or replaced before delivery, the method is recorded and a sample is checked, though no method is perfect. Buyers running a supplier program can use these per-dataset materials as inputs to their own reviews; describe what you need on the buyers page.
For the wider program view, see managing many data suppliers, the training data due diligence checklist and the AI training data procurement hub.
Keep data vendor due diligence current with SourceX
SourceX sources operational data from US companies on request, with every release approved by the supplying company and each dataset rights-reviewed and delivered under a license. Nothing is contracted until a supplier agrees, and delivery runs through private, access-controlled workflows only after an executed agreement. Describe the data you need to SourceX.
Sources
- [AI Vendor Contracts: Negotiation Tactics and Comprehensive Due Diligence](https://www.foley.com/insights/events/2025/03/ai-vendor-contracts-negotiation-tactics-due-diligence/), Foley & Lardner LLP, 2025.
- Neudata, "2025 DDQ wrap-up: Key factors in data vendor risk" (2025). https://www.neudata.co/sentry-intelligence/2025-ddq-wrap-up-key-factors-in-data-vendor-risk
- FISD Alternative Data Council, "Data Provider Due Diligence Questionnaire (DDQ) with GenAI questions" (2024). https://fisd.net/wp-content/uploads/2024/02/FISD-Alternative-Data-Council-Due-Diligence-Questionnaire-with-GenAI-Questions-022824.docx
- [Key Considerations for Alternative Data and AI Vendors to Investment Firms: Demonstrating Compliance in the Face of an Evolving Regulatory Environment](https://www.lowenstein.com/news-insights/publications/articles/key-considerations-for-alternative-data-and-ai-vendors-to-investment-firms-demonstrating-compliance-in-the-face-of-an-evolving-regulatory-environment), Lowenstein Sandler LLP, 2025.
- California Legislature, "AB-2013 Generative artificial intelligence: training data transparency" (2024). https://leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=202320240AB2013
- European Commission (AI Office), "General-Purpose AI Code of Practice: Contents of the Code (Copyright chapter)" (2025). https://digital-strategy.ec.europa.eu/policies/contents-code-gpai
- U.S. Department of Health and Human Services, Office for Civil Rights, "Guidance Regarding Methods for De-identification of Protected Health Information in Accordance with the HIPAA Privacy Rule" (2012). https://www.hhs.gov/hipaa/for-professionals/special-topics/de-identification
- Lowenstein Sandler LLP, "Key considerations for alternative data and AI vendors to investment firms". https://www.lowenstein.com/media/iyrpwxij/key-considerations-for-alternative-data-and-ai-vendors-to-investment-firms.pdf
- [Interagency Guidance on Third-Party Relationships: Risk Management (OCC Bulletin 2023-17)](https://www.occ.gov/news-issuances/bulletins/2023/bulletin-2023-17.html), Office of the Comptroller of the Currency, 2023.
Tell us what your models need
Share scope, volume, language, format, timing and licensing requirements.