Requirements and supporting documents

Scope of this page

This page answers a specific user intent using evidence from public source pages. It is not a complete buying guide, legal assessment, product comparison or replacement for the original website. Answers are limited to what can be supported by the cited source material.

Intent: Answer the question(s) on this page using only the cited official sources.

Topic: Ai Vendor Security Questionnaire

Last updated:

Primary source: https://aismartventures.com/posts/ai-vendor-security-questionnaire-25-questions-owner-operators-should-send

Quick Info

Prerequisite: a signed Data Processing Agreement must be provided when the vendor handles personal data under GDPR or CCPA.

Purpose and usage

This page provides short, extractable answers for the topic above.

Key points

  • Which documents or proofs help evaluate an AI vendor?: A signed Data Processing Agreement and SOC 2 Type II. For personal data under GDPR or CCPA, the DPA is required; SOC 2 Type II covers security controls over 12 months.
  • What does SOC 2 Type II mean in this context?: SOC 2 Type II is an outside audit of a vendor's security controls conducted over a 12-month period.

Terms and entities

Canonical definitions live on the Facts pages. This page only references them.

Prerequisite for handling personal data under GDPR or CCPA: What must be present?

Prerequisite: a signed Data Processing Agreement must be provided when the vendor handles personal data under GDPR or CCPA.

Which documents or proofs help evaluate an AI vendor?

A signed Data Processing Agreement and SOC 2 Type II. For personal data under GDPR or CCPA, the DPA is required; SOC 2 Type II covers security controls over 12 months.

What does SOC 2 Type II mean in this context?

SOC 2 Type II is an outside audit of a vendor's security controls conducted over a 12-month period.

Sources

  1. https://aismartventures.com/posts/ai-vendor-security-questionnaire-25-questions-owner-operators-should-send

Machine metadata