Insights

AI vendor due diligence for small-market buyers: the questions to ask before signing

Most AI that a Mauritian SME will use over the next five years will be bought, not built. That is sensible. The consequence is that the quality of the organisation’s AI depends on the quality of its vendor decisions, and those decisions are usually made by a managing director or a finance head with no procurement function, no in-house lawyer and limited time. This article is written for that person. It sets out ten questions to ask any AI vendor, the parts of the Data Protection Act 2017 that bear on the relationship, the contract clauses worth insisting on, and a table for comparing two offers.

It assumes the vendor is supplying a product that will touch your data: a customer-service assistant, a document-processing tool, a recruitment screening service, or a generative AI platform on an enterprise plan. For a free tool used for general drafting, an acceptable use policy is the right control.

Why small-market buyers carry more dependence risk

A large organisation in a large market can negotiate terms, hire specialists to audit a vendor, and switch supplier if it must. A 40-person firm in Port Louis can do none of those things easily, and the vendor knows it. This is a structural feature of small markets, now being described carefully in the literature on small island developing states (SIDS).

A paper presented at ITU Kaleidoscope 2026 by Mohamed Shareef of Nexia Maldives argues that the dominant AI governance models assume large, high-capacity states, and that SIDS “face the same AI risks with thinner institutions, smaller markets, and deeper vendor dependence.” From a review of 14 SIDS AI strategies, the paper identifies five recurring patterns, two of which concern any small buyer: structural vendor dependence and what it calls procurement impossibility. It observes that foundation-model-scale AI sits beyond domestic compute, forcing reliance on foreign platforms, and that lock-in creates “data gravity” that pulls data offshore. It also notes that many SIDS data-protection or digital regulators have between one and five specialist staff. Its proposed remedies include a model change notice of at least 30 days before a vendor alters a deployed model, and procurement transparency through a machine-readable software bill of materials.

Two caveats. The paper is about states and public-sector systems, and its numbers describe regulators rather than companies. The inference that the same dynamics apply to a small private buyer is ours, though it is not a large leap: a firm has less bargaining power than its regulator, and it will meet the same specialist scarcity when it looks for someone to evaluate a vendor.

The UNESCO needs assessment on AI, digital transformation and open data in SIDS (2024) supplies the context. It reports that 71.2 percent of SIDS lack quality data for artificial intelligence, that half have no official initiatives on the use of AI, and that 43 percent lack a data governance research framework, adding that many SIDS “still lack clear guidelines and regulations for data governance and AI implementation.” Mauritius is better placed than most on policy, with a Data Protection Act in force and a National AI Strategy published in 2026, but the point for a buyer stands: where data quality and governance capacity are scarce, the vendor’s practices become the buyer’s practices by default, because the buyer has little independent means of checking them.

Due diligence for a small buyer is therefore less about negotiating power and more about asking the right questions before signing, so that dependence is entered into with open eyes and an exit route.

The ten questions

Ask these in writing and keep the answers. A vendor that answers in writing has made a representation you can rely on later; one that will only answer on a call has not.

1. Where is our data processed and stored, and by whom?

Why it matters. The answer determines whether the Data Protection Act’s transfer provisions apply, which subprocessors touch your data, and what happens when the vendor’s cloud provider has an outage or a breach.

A good answer names the cloud provider and region, lists subprocessors, and states whether data is encrypted at rest and in transit.

Red flag. “It’s in the cloud” with no further detail, or a refusal to name subprocessors on grounds of commercial confidentiality.

2. Is our data used to train or improve your models, or anyone else’s?

Why it matters. If your client files, pricing or correspondence are used to train a model, you have lost control of them, and your clients did not agree to it. Consumer plans often permit training on inputs; enterprise plans typically do not.

A good answer is a clear “no” for your plan, stated in the contract rather than a marketing page, with the retention mechanism explained.

Red flag. “We may use data to improve our services” without a defined opt-out, or a gap between what the salesperson says and what the terms say.

3. What model or models sit underneath the product, and who supplies them?

Why it matters. Most AI products for SMEs are built on a foundation model from a large provider. Your vendor’s dependence is your dependence. If the model provider changes its pricing, terms or availability, your product changes with it.

A good answer names the underlying providers and explains what the vendor would do if one became unavailable.

Red flag. Presenting a wrapper around a third-party model as proprietary technology, or being unable to say which provider is used.

4. How and when will you tell us the model has changed?

Why it matters. A model update can silently change the output your staff and customers rely on. The ITU paper’s proposal of a 30-day model change notice is designed for government systems, but the problem is identical for a business: a change you did not know about is a change you cannot test for.

A good answer commits to advance notice of material model or behaviour changes, defines “material”, and offers a way to test before the change reaches you.

Red flag. “We continuously improve the product” as the only answer, meaning changes happen whenever the vendor decides.

5. What happens to our data, and to our ability to operate, if we leave?

Why it matters. Dependence is only dangerous if you cannot exit. A vendor with a clean exit is a supplier; one without is a landlord.

A good answer describes the export format (structured and machine-readable), the timeframe for return, deletion certification, transition assistance, and whether anything you have built inside the product (prompts, workflows, integrations) can leave with you.

Red flag. No documented export process, data return only “on request” at unspecified cost, or a right for the vendor to retain data indefinitely for “legitimate business purposes.”

6. How accurate is the product for our kind of work, and how do you know?

Why it matters. AI products fail in ways that are hard to see. A tool that is right 92 percent of the time on invoices may be wrong on exactly the invoices that matter. The question is whether accuracy was measured on data like yours.

A good answer explains how accuracy is measured, on what data, what the known failure modes are, and offers a trial on a sample of your own data before you commit.

Red flag. A single headline accuracy figure with no method, or a refusal to run a trial on your data.

7. What human oversight does the product assume, and what does it not do?

Why it matters. Under the Data Protection Act, decisions based solely on automated processing that significantly affect individuals are restricted (section 38). A vendor should say clearly whether its product makes decisions or supports them, and where the human sits.

A good answer describes the product as decision support, shows where a person reviews, and provides logs that show who decided what.

Red flag. A product that decides on individuals (credit, recruitment, eligibility) with no review step, sold as “fully automated.”

8. What security assurance can you show, rather than claim?

Why it matters. Section 31 of the Act requires a controller using a processor to choose one providing sufficient guarantees on security and organisational measures. You need evidence, not a badge on a website.

A good answer is an independent report or certification (ISO/IEC 27001, a SOC 2 report, a recent penetration test summary), a named security contact, and a description of access controls and logging. For a very small vendor handling low-risk data, a candid account of what it does and does not have is acceptable.

Red flag. “Bank-grade security” with nothing behind it, or a certification that on inspection belongs to the cloud provider rather than the vendor.

9. How will you tell us about a breach, and how quickly?

Why it matters. Section 25 of the Act requires a controller to notify the Data Protection Commissioner of a personal data breach without undue delay and, where feasible, within 72 hours of becoming aware of it, and requires a processor to notify the controller without undue delay. If your vendor takes two weeks to tell you, you cannot comply.

A good answer commits to a notification window measured in hours, names the channel, and describes what you will receive.

Red flag. No incident notification clause, or one that says only “as required by applicable law” with no timeframe.

10. Who else in Mauritius or a comparable market uses this, and can we speak to them?

Why it matters. A reference from a firm of your size, in a market like yours, tells you more than any demonstration, including whether the vendor can support customers without large IT teams.

A good answer is two named references you can contact, ideally one that has been through a renewal or a problem.

Red flag. References only from very large customers in other markets, or none at all.

The Data Protection Act angle: processors and cross-border transfer

Where the vendor processes personal data on your behalf, the Data Protection Act 2017 places obligations on you as controller that no contract can remove. Section numbers below have been checked against the text of the Act; the labels distinguish what the Act says from what we advise.

Legal requirement. Under section 31(4), a controller using a processor must choose one providing sufficient guarantees in respect of security and organisational measures, and the two must enter into a written contract providing that the processor acts only on the controller’s instructions and is bound by the controller’s security obligations. A vendor’s standard click-through terms may or may not satisfy this.

Legal requirement. Under section 31(5), a processor that processes personal data other than as instructed by the controller is treated as a controller for that processing. This is the legal consequence of a vendor training on your data without instruction, and one reason to have question 2 answered in writing.

Legal requirement. Under section 25(2), a processor that becomes aware of a personal data breach must notify the controller without undue delay. The vendor’s notification clause should be at least this strong.

Legal requirement. Section 36 governs transfer of personal data outside Mauritius. A controller or processor may transfer personal data to another country where, among other grounds, proof of appropriate safeguards has been provided to the Commissioner, the data subject has given explicit consent after being informed of the risks, or the transfer is necessary for the performance of a contract with the data subject. Under section 36(4) the Commissioner may require the transferring party to demonstrate the effectiveness of its safeguards and may prohibit, suspend or condition a transfer. Since most AI vendors host outside Mauritius, question 1 is in practice a section 36 question, and the answer belongs in your record of processing operations, which under section 33(2)(e) must record transfers to another country and the safeguards relied on.

Legal requirement. Under section 23(2)(j), where a controller collects personal data directly from a data subject and intends to transfer it to another country, the data subject must be informed of that intention and of the level of protection afforded by that country. If a new vendor introduces an overseas transfer your privacy notice does not mention, the notice needs updating.

Legal requirement. Under section 34, a data protection impact assessment is required before processing likely to result in a high risk to data subjects, including a systematic and extensive evaluation of individuals based on automated processing on which decisions with legal or similarly significant effects are based. An AI product that screens candidates or scores customers is likely to fall within this; a document summariser is not.

Best practice. Ask the vendor for a data processing agreement that maps onto section 31(4) explicitly. Keep a one-page record for each AI vendor showing what personal data it receives, where it is processed, on what transfer ground, and when the arrangement was last reviewed. The Data Protection Office publishes DPIA guidance and forms, which is the place to start if question 7 suggests the product touches decisions about individuals.

Best practice. Where the vendor cannot provide the safeguards that would support a transfer, treat that as a reason not to send personal data to the product at all.

Contract clauses to insist on

Consultaix recommendation. These six clauses are the ones we would want in any AI vendor contract for a small buyer. A small buyer will not win every negotiation, but the vendor’s response to each request tells you something about the relationship you are entering.

Data ownership. You own the data you put in and the outputs generated from it. The vendor’s licence is limited to providing the service to you. No training, benchmarking or product improvement using your data without separate written agreement.

Exit and data return. On termination for any reason, the vendor returns your data in a documented, machine-readable format within a fixed period, deletes it and certifies deletion, and provides transition assistance at a stated rate. Anything you have configured in the product is exportable in usable form.

Model change notification. Advance written notice, ideally 30 days, of any material change to the underlying model or product behaviour, with the option to test before the change is applied and a right to terminate without penalty if the change materially degrades the service.

Subprocessors. The contract lists current subprocessors, requires notice of additions, gives you a right to object, and makes the vendor responsible for its subprocessors’ compliance with the same data terms.

Audit and assurance. The vendor provides, on request and at least annually, current independent security reports or certifications, answers reasonable security questionnaires, and cooperates with any enquiry from the Data Protection Commissioner concerning your data.

Liability. Liability for breach of confidentiality and data protection obligations is not capped at the annual fee, or is capped at a meaningful multiple of it. Most vendor paper caps liability at fees paid, which for a small subscription is trivial against the cost of a breach. This is the clause where negotiation is hardest and the answer matters most.

Comparing two vendors

Score each question from 0 (no answer or a red flag) to 3 (a good answer in writing), then weight by importance for your use case. The weights below assume the product will handle personal or confidential data; for a tool that will only touch public information, reduce the weights on questions 1, 2, 8 and 9.

Question Weight Vendor A score (0 to 3) Vendor A weighted Vendor B score (0 to 3) Vendor B weighted
1. Data location and processors 3
2. Training on our data 3
3. Underlying model and supplier 2
4. Model change notification 2
5. Exit and data return 3
6. Accuracy on our data 3
7. Human oversight 2
8. Security evidence 3
9. Breach notification 3
10. Comparable references 1
Total (maximum 75)

Two rules make the table useful. First, a score of 0 on questions 1, 2, 5 or 9 should be treated as disqualifying regardless of the total, because those are the questions where a poor answer creates a legal exposure or an exit trap that product quality cannot offset. Second, record the source of each score (the email, the contract clause, the call note) so that at renewal you can check whether the vendor still meets the standard it was scored against.

A managing director can complete this exercise in an afternoon for two vendors. The cost of not doing it is usually discovered at exit, at breach, or when a client asks where their data has been.

Where Consultaix fits

Vendor selection sits within Consultaix’s AI Implementation and Automation service, where the questions above are applied to a specific use case and the trial in question 6 is designed and run on the client’s own data. Where an organisation wants the vendor register, data processing agreements and transfer records to form part of a standing framework, the AI Governance Advisory service provides that structure, informed by the Data Protection Act 2017 and ISO/IEC 42001. Firms unsure whether their data is ready for a vendor at all may find it useful to begin with the AI Readiness Assessment.

Sources