Prudex AI

Plain answers

The questions your compliance officer should ask any AI vendor

Prudex AI · September 2, 2026 · 3 min read

If your firm is a registered adviser or broker-dealer, vendor oversight stopped being a courtesy some time ago. Amended Regulation S-P expects written policies for overseeing service providers that touch customer information, examiners have started asking for AI tool inventories and due-diligence files by name, and "we use a reputable vendor" is not an answer that survives an examination.

The good news: the diligence itself is not complicated. A handful of questions separates vendors who have thought about regulated work from vendors who have thought about a demo. Here they are, with what a real answer sounds like for each.

Where does our data live, exactly?

Not "in the cloud." Which environment, whose account, and in what jurisdiction. The strongest answer for a custom system is that production runs in your own environment, on accounts your firm controls, so the vendor never holds your production data at all. If a vendor hosts it themselves, they should be able to name where, under what controls, and what happens to it when you leave.

A vendor who has to check with engineering does not know. That is itself an answer.

Whose AI account does the system run on?

This one is quietly decisive. If the system calls an AI provider through the vendor's account, everything about how your data is handled depends on a contract you have never seen. If it runs on your own account, under your own key, you hold that relationship directly and can read the terms yourself. You are no longer taking anyone's word for anything.

We build on the client's own AI account for exactly this reason. It converts a trust question into a reading assignment.

Is our data used to train anything?

The answer you want has two parts. First, the provider-level fact: business API traffic is not used to train models by default at the major providers, and that is verifiable in the provider's own terms. Second, the vendor-level practice: no consumer chat products anywhere in the workflow, because consumer tools carry different terms than business APIs. A vendor who cannot articulate the difference between the two has not handled regulated data before.

Who can access it, and how is that decided?

Least privilege should be the starting position: access to the specific systems the project requires, nothing else, read-only where the work allows. Every person with access should be named, approved by you, and under a signed confidentiality agreement. Blanket administrative access requested on day one is a red flag with few rivals.

What happens when something goes wrong?

You are looking for a written commitment to a notification window, and the number matters less than the posture. The regulatory expectation runs to 72 hours; a vendor confident in their monitoring will commit to less. Ours is 48, in writing, with support for your own reporting obligations. A vendor who has never been asked this question will improvise, and improvised incident response is how a bad day becomes a bad quarter.

What happens when the engagement ends?

Credentials revoked immediately, working copies of your data returned or destroyed inside a defined window, and a documentation package good enough that a competent developer who is not the vendor could run the system. Exit terms are where you learn whether a vendor plans to earn your renewal or hold it hostage.

Can you show us all of this in writing?

Every answer above should exist as a document you can file, because your obligation is not just to do diligence but to record it. Ask for the vendor's written data-handling practices before the first system is touched. If the document does not exist, you are being asked to build your vendor file out of emails.

One more thing worth asking for: whether the vendor will complete your security questionnaire in your format and take a call with your compliance team. Certificates and badges are fine; a vendor willing to sit with your CCO and answer follow-ups is better.

Our own answers to all of the above are written down and public on our trust page, and the full document travels with every proposal. If it would be useful to talk through what diligence should look like for a system your firm is considering, that is a fine use of a complimentary consultation.