Logistics and distribution
AI vendor due diligence checklist for logistics and distribution companies
By SourceX Editorial · Updated
Short answer
An AI vendor due diligence checklist for a logistics or distribution company asks 20 questions in five groups: data use, retention, security, model training and exit. The deciding question is whether the vendor may train on your shipment, driver or pricing data, or anything derived from it, and whether the contract, not a policy page, says so.
Key takeaways
- Get answers in the contract or a signed addendum; trust pages and policy pages can change without notice.
- Model training questions must cover derived, aggregated and de-identified data, not only raw inputs.
- Driver data, customer pricing and shipper identities deserve named handling rules in the vendor's answers.
- Exit terms decide whether you get your data back in a usable format and whether derived copies are deleted.
- A vendor review protects your data; licensing your data is a separate, deliberate decision.
How to use this checklist#
The AI vendor checklist below is written for the IT director or CIO reviewing a tool that will touch TMS, WMS, ERP, EDI, telematics or customer service data. It has 20 questions in five groups, and it works for standalone AI tools and for AI features added to systems you already run.
Send the questions before a demo turns into a pilot. Ask for written answers, and ask where each answer is enforced: the master agreement, the order form, the data processing addendum or an AI addendum. A link to a trust page is a starting point, not an answer.
Score each answer as acceptable, acceptable with conditions or not acceptable. A single not acceptable on model training or exit is usually reason enough to pause the purchase.
Data use: what the vendor touches and why#
Data use questions establish which records the tool reaches and what the vendor may do with them.
- Q1. Which of our data will the tool access: shipments, orders, rates, customer contacts, driver records, video, email?
- Q2. For which purposes may the vendor use that data, and is the list of purposes closed or open-ended?
- Q3. Does the vendor pass our data to subprocessors, including AI model providers, and can we see the list and object to changes?
- Q4. Where is our data processed and stored, and can we restrict either to specific regions?
Why data use questions mirror provenance standards#
Data use questions mirror what dataset provenance standards already ask about any dataset. The Use group of the Data & Trust Alliance's Data Provenance Standards, for example, includes elements for confidentiality classification, allowed and excluded processing and storage geographies, license to use and intended data use.
Asking a vendor for the same facts gives you answers you can file next to your own data inventory. It also exposes vague replies quickly: a vendor that cannot say where your rate tables are processed, or for what purpose, has not finished its own homework.
Retention and security questions#
Retention and security questions decide how long your data sits with the vendor and how well it is protected while there. Retention matters more in logistics than it first appears: a vendor copy of a rate table or a driver's ELD history, held for an unclear period, is exposure your customers and drivers never agreed to.
| Question | Good answer looks like | Red flag |
|---|---|---|
| Q5. How long are inputs, outputs, prompts and logs retained, and can we shorten that? | Defined periods in the contract, configurable by us | Retained as long as needed |
| Q6. Are logs or uploaded files kept for abuse monitoring, and who can read them? | Named roles, limited access, defined deletion | Unspecified human review |
| Q7. Do deletion requests reach backups, and when? | Backups expire on a stated schedule | Backups excluded from deletion |
| Q8. Does the tool copy data from our TMS, WMS or ERP, or read it in place? | Clear description of what is copied and where | Full replica with no stated purpose |
| Q9. Which independent security reports cover the AI feature itself? | A current report whose scope names the AI service | Report covers a different product |
| Q10. How are integrations authenticated? | Scoped credentials we can rotate and revoke | Shared admin logins |
| Q11. How is our data separated from other customers' data? | Tenant isolation described in writing | Vague reference to the cloud provider |
| Q12. How will you notify us of an incident involving our data? | Contractual notice duty with named contacts | Policy page only |
Model training: the questions that decide the deal#
Model training questions decide whether your operational history becomes part of someone else's product. Ask them in writing and check the answers against the contract text.
Watch for training rights hidden in feedback clauses. When staff correct an AI-drafted carrier email or rate quote, some terms treat that correction as feedback the vendor may use without limits, which can carry your pricing logic along with it.
| Question | Why it matters for shipment, driver and pricing data |
|---|---|
| Q13. Will you train, fine-tune or evaluate any model on our inputs, outputs or system data? | Rates, lanes and customer patterns used in training can shape outputs other customers see |
| Q14. Do you claim rights to aggregated, de-identified or derived data, and for how long? | Benchmarks and models built from your data can outlive the contract |
| Q15. Is training off by default, and is any opt-out written into the contract? | A settings page can change; a contract term binds |
| Q16. Do your model providers train on data you send them? | Your vendor's promise means little if its subprocessor's terms allow training |
Exit: getting your data back#
Exit questions are the ones most often skipped and most often regretted, because they are hardest to negotiate after signing.
Ask for a test export during the pilot rather than at termination. A sample export of tickets, logs and configurations shows whether the format is usable and whether links between records survive, while you still have leverage to fix gaps.
- Q17. In what format, and within what period, can we export all our data, including logs and configurations?
- Q18. Will you delete our data and derived data at exit, and certify the deletion?
- Q19. May we keep using outputs created during the contract?
- Q20. What happens to our data if you are acquired or shut down?
Illustrative: a 3PL reviews an email triage tool#
Illustrative: a fictional 3PL's IT director evaluates an AI email triage tool for customer service. The tool would read client inboxes and pull order status from the WMS. The written answers show training is off by default, but the vendor's terms grant it rights to de-identified data for product improvement, and its model provider is described only as a category.
The IT director scores Q14 and Q16 as not acceptable and asks for an AI addendum that removes the de-identified data right and names the model provider. Counsel confirms that several client contracts prohibit sharing their data with unnamed subprocessors. The vendor signs the addendum, and the pilot starts only with clients whose contracts allow it.
Where data licensing fits#
A vendor review keeps your data from being used in ways you did not choose. Licensing is the opposite case: a deliberate, scoped decision to let a model developer use de-identified records for a defined purpose, in exchange for payment.
SourceX handles that side through the SourceX five-step transaction of Supply, Rights, Preparation, Approval and Delivery. Each package carries a SourceX Evidence Packet that states the permitted use, so the terms you set are written down rather than implied by a settings page.
Frequently asked questions
Is a SOC 2 report enough for an AI vendor?
It helps, but it is not enough on its own. A SOC 2 report describes controls over a defined system for a defined period, and the AI feature may sit outside that scope. It also says little about model training rights, which are a contract question. Check the report's scope and read the data terms separately.
Should we accept a vendor's statement that it anonymizes our data?
Ask what anonymized means in practice: which fields are removed, whether rates and lanes remain, and whether the result could identify a customer when combined with other data. A de-identified data right in the contract can still allow broad use, so the definition matters as much as the promise.
Who on our side should answer and score the checklist?
IT or security usually owns the review, with counsel reading the contract terms and an operations leader confirming which data the tool really needs. For tools touching driver data, include safety and HR. One person should own the final scoring so the decision is recorded.
Do these questions apply to AI features in our existing TMS or WMS?
Yes. An AI feature added to a system you already use can bring new subprocessors, new retention and new training terms, sometimes through an updated online agreement. Run the same questions before enabling the feature, even though the underlying product has already been approved.
What if the vendor refuses to change its data terms?
Decide whether the tool can work with less data. Some tools can run on records with rates, names or driver details removed, or only for clients whose contracts allow it. If the tool needs exactly the data its terms would let the vendor reuse, the safer choice is usually a different vendor.
Sources
- The Use group of the Data & Trust Alliance Data Provenance Standards includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, allowed and excluded processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
Related resources
- IndustryFreight brokerages data
- QuestionShould companies sell or license their data?
- QuestionDo AI labs buy legal documents?
- InsightCan licensing pricing data to AI create antitrust risk?
- InsightOpt-in vs opt-out for AI training in B2B SaaS contracts
- InsightCan a distributor license its pricing and quote history?
See if your company qualifies
A short company assessment. No data uploads are needed.