How to Assess an AI Tool Before Your Business Uses It
IT Club provides practical technology guidance, not legal advice. Laws, contractual obligations and regulatory requirements vary according to the organisation, sector, data, location and use case. Obtain appropriate legal, data-protection, employment or regulatory advice where required.
An AI tool is a supplier relationship, not just an app. Before business information flows into it, the same questions you would ask of any supplier apply — plus a few that are specific to AI. This guide provides a due-diligence framework sized for a small business, and a status system for recording the outcome.
The principle
A popular AI tool is not automatically an approved business system.
1. The supplier and the service
- Supplier identity — who is the legal entity, where are they established, and are you contracting with them or a reseller?
- Service description — what does the tool actually do, and which parts involve AI processing of your data?
- Product changes — how are new features, model changes and terms updates communicated?
- Pricing — what does the plan you need actually cost at your usage, and what triggers overage?
- Support — what support exists when something goes wrong, and at what response time?
2. Your data
- Data use — what may the supplier do with the content you submit?
- Model training — is your data used to train models, and is that setting contractual or a toggle?
- Storage and locations — where is data stored and processed, and what transfer mechanisms apply?
- Subprocessors — who else processes your data, and how are changes notified?
- Retention and deletion — how long is data kept, and can you delete it on demand?
- Exit and data export — can you get your data out in a usable format when you leave?
3. Security and control
- Security certifications and audit reports (for example ISO 27001 or SOC 2) — current and covering the service you use
- Encryption in transit and at rest
- Administrator controls — can you manage users, permissions and settings centrally?
- Access logging — can you see who did what?
- Single sign-on and multi-factor authentication support
- Role-based access — can you limit who can use which features and data?
- Incident notification — what does the contract commit to when the supplier has a breach?
- Service availability — uptime commitments and business continuity arrangements
4. The contract
- Intellectual-property terms and output ownership
- Prohibited uses — what the supplier forbids, which may rule out your use case
- Indemnities — what the supplier stands behind, if anything
- Liability limits — the cap on what you could recover if their failure costs you
- Regulatory commitments — data-processing terms, and any sector-specific commitments you need
Record the outcome with status labels
| Status | Meaning |
|---|---|
| Approved | Cleared for the stated business uses by the named owner |
| Approved with restrictions | Usable, but only for defined tasks or data classes |
| Pilot only | Time-limited trial with defined users, data limits and an end date |
| Not approved | Assessed and rejected — recorded so the question is not re-litigated monthly |
| Retired | Previously used; access removed, data exported or deleted |
Keep the assessment proportionate: a free brainstorming tool that never sees business data needs a lighter pass than a system processing customer records. The downloadable AI Tool Approval Checklist and AI Tool Register in this hub give you a ready-made structure for both the assessment and the record.
Plain-English Takeaway
Assess an AI tool the way you would any supplier who will hold your information: identity, data handling, security, contract and exit. Record a clear status — approved, restricted, pilot, not approved or retired — so everybody knows where each tool stands.
Sources and further reading
- NCSC — Supply chain security guidance
- NCSC — Cloud security guidance
- ICO — Controllers and processors contracts and liabilities
External guidance changes. Check the source itself for the current position before acting on it.