Skip to content

Rights and contracts

Supplier due diligence questionnaire: what a buyer's counsel will ask

By SourceX Editorial · Reviewed by Noah Loul ·

Short answer

An AI training data supplier due diligence questionnaire is the set of questions a buyer's counsel sends before licensing a dataset: who holds rights to the records, what personal information was removed, where the data came from and how it is protected. Suppliers answer fastest when every answer points to a document prepared before the questionnaire arrives.

Key takeaways

  • Buyer's counsel usually groups supplier diligence into rights, privacy, provenance and security.
  • Each answer should point to a document: a contract, a policy version, an export log or a signed approval.
  • Provenance questions ask which system each record came from, over what dates, and what changed before delivery.
  • Answering unknown is better than guessing, because a wrong answer can become a warranty problem later.
  • The SourceX Evidence Packet maps to all four groups through provenance, licensing rights, permitted use, the privacy record and release authorization.

Why does a buyer's counsel send a supplier questionnaire?#

A buyer's counsel sends a supplier questionnaire to build a record that the dataset was obtained, prepared and licensed lawfully, because the buyer will rely on that record if its model or its training practices are ever challenged. The answers also shape the warranties the supplier will be asked to give in the license.

Published standards explain the shape of many questionnaires. One example is the Data Provenance Standards published by the Data & Trust Alliance, which split what a dataset should carry into Source, Provenance and Use metadata; the specification calls that metadata necessary for choosing datasets properly for AI model training. Buyer forms often mirror the split without citing it.

The questions below are representative rather than a fixed form. Wording varies by buyer, but the groups and the evidence behind them stay consistent from one questionnaire to the next.

What will counsel ask about rights?#

Rights questions test whether the supplier can grant the license without breaching a contract or someone else's ownership. Expect these early, because a weak answer here can stop the deal before anyone looks at the data.

What will counsel ask about rights?
QuestionEvidence to have ready
Which company entity owns the archive, and who has authority to sign?Entity chart, signing authority and owner or board approval
Are any records owned or controlled by customers or other third parties?Customer contract review and a list of carved-out records
Do customer contracts, terms of service or DPAs restrict reuse?A contract version map and the clauses relied on
Do software vendor terms limit export or reuse of the records?A vendor terms review for each source system
Has any of this data been licensed to anyone else, exclusively or not?A schedule of existing data licenses
Are lender, investor or acquisition-related consents needed?Credit agreement and investor document review
Does the dataset include source code, open-source components or client deliverables?Code scan results, open-source license list and carve-outs

What will counsel ask about privacy?#

Privacy questions test whether personal information was handled lawfully and removed to the agreed standard before release. Counsel will usually ask to see the method, not just the conclusion.

What will counsel ask about privacy?
QuestionEvidence to have ready
Which personal information did the source records contain?A field inventory by record family
Which privacy laws may govern these records and their transfer?Counsel's analysis, including state laws and any international records
What did privacy notices say when the records were collected?Dated privacy policy versions
How were personal and confidential details removed from structured and free-text fields?Preparation method, tools used and exceptions
How was the removal checked?Sampling plan, reviewer sign-off and residual findings
Were sensitive categories excluded or handled separately?An exclusion list with reasons

Why automated scanning alone rarely satisfies counsel#

Automated scanning alone rarely satisfies counsel because the tools themselves say they can miss things. Presidio, an open-source de-identification SDK, warns its own users that automated detection cannot promise to catch every piece of sensitive information, and recommends layering further systems and protections on top.

A human review record therefore carries real weight in the answers. Keep the sampling plan, who reviewed which batches, what they found and how residual findings were fixed, and attach that record to the privacy answers rather than describing it from memory.

What will counsel ask about provenance?#

Provenance questions test where each record came from and what happened to it between the source system and delivery. They are the questions suppliers most often underestimate, because the answers live with IT rather than legal.

What will counsel ask about provenance?
QuestionEvidence to have ready
Which systems did each record family come from, and over what dates?A source system list with date ranges
How were records exported, and by whom?Export logs, scripts or vendor tickets
Were any records generated by AI tools or copied from public sources?A statement on synthetic or copied content, with exceptions
What transformations were applied before delivery?A change log covering removal, normalization and deduplication
Can each delivered file be traced back to its source?A manifest with file hashes and source mapping
What metadata accompanies the dataset?A dataset description covering source, provenance and permitted use

What will counsel ask about security and release?#

Security and release questions test whether the records were protected before delivery and whether someone with authority approved them going out. The Use group of the Data Provenance Standards covers similar ground: its elements include how the data is classified for confidentiality, where consent documentation is kept, which privacy-enhancing technologies were applied, where processing and storage may happen, the license to use and the intended use.

What will counsel ask about security and release?
QuestionEvidence to have ready
Where are the records stored before delivery, and who can access them?An access list and storage location
How will the data be delivered?Delivery method: supplier-controlled storage, secure transfer or encrypted drive
Were credentials, keys and secrets removed from code, logs and tickets?Secret-scan results and remediation notes
Has the company had security incidents affecting these systems?An incident summary and remediation record
What happens to working copies after delivery?A retention and deletion plan
Who approved release, and on what date?A signed release authorization

Illustrative: an engineering firm answers its first questionnaire#

Illustrative: a fictional civil engineering firm plans to license request-for-information threads, submittal review histories and internal design review markups kept in Procore and in its Deltek project records. The buyer's counsel sends a questionnaire close to the one above.

The firm answers most rights questions from a contract review it had already finished: many client agreements assign drawings and reports to the client, so deliverables are carved out, while internal review markups and RFI threads remain the firm's own records. Two answers about software vendor export terms are marked unknown, with IT named as the owner to confirm them. The buyer accepts the carve-out and agrees to proceed, on condition that the export terms are confirmed and the export logs shared before signing.

Two privacy answers need more work than expected. RFI threads name client project managers and contractors' staff, and some markups carry engineers' stamps and signatures, so the firm adds a sampling review of free-text fields and image regions and attaches the reviewer sign-off to its privacy answers.

How should a supplier answer, and how does SourceX help?#

A supplier should answer from documents, with one owner coordinating IT, legal and operations so answers do not contradict each other. The most common problem is not a bad answer but an inconsistent one, such as a date range that differs from the export log.

SourceX builds the answers during the SourceX five-step transaction rather than after a questionnaire lands. Rights questions map to licensing rights and permitted use, privacy questions to the privacy record, provenance questions to provenance, and security and approval questions to release authorization, all held in the SourceX Evidence Packet. The supplier approves every step.

  • Attach or reference the supporting document in every answer.
  • Mark unknowns as unknown, with the step that will resolve them.
  • Keep answers consistent with the license warranties, and have counsel review both together.
  • Keep a dated copy of the submitted answers with the dataset record.

Frequently asked questions

Do all buyers use the same questionnaire?

No. Each buyer's counsel uses its own form, ranging from short checklists to long schedules. The underlying groups are consistent, so a supplier that has prepared rights, privacy, provenance and security evidence can adapt its answers quickly to any format.

Should questionnaire answers be kept confidential?

Yes. Answers often reveal customer contract terms, system architecture and security practices. Exchange them under a nondisclosure agreement or the confidentiality terms of a signed term sheet, and share only what each question requires.

Do questionnaire answers become warranties?

They can. Some licenses attach the questionnaire as a schedule or include a warranty that the answers were accurate. Have counsel review the answers with the same care as the contract, and qualify answers to the supplier's knowledge where that is appropriate.

How is this different from the buyer's own diligence checklist?

The buyer's checklist covers everything it must confirm about a dataset, including technical quality, coverage and fit for its models. The supplier questionnaire is the part of that work the buyer cannot do alone, because only the supplier knows its contracts, source systems and preparation steps.

What if we cannot answer a question?

Say so and explain why: the records may predate a system migration, or a vendor may need to confirm export terms. A supplier can often narrow the dataset to records it can document, which usually serves both sides better than a qualified answer about the whole archive.

Sources

  • The Data & Trust Alliance's Data Provenance Standards (version 1.0.0) define dataset metadata in three groups, Source, Provenance and Use, and say this metadata is needed to enable proper dataset selection for AI model training. Source
  • The Use group includes elements for confidentiality classification, consent documentation location, privacy-enhancing technologies applied, processing and storage geographies, license to use, intended data use, and copyright, patent and trademark status. Source
  • Presidio's documentation warns that because it uses automated detection mechanisms there is no guarantee it will find all sensitive information, and that additional systems and protections should be employed. Source

Related resources

See if your company qualifies

A short company assessment. No data uploads are needed.

See if you qualify