1
What is vendor due diligence?
In mergers and acquisitions, vendor due diligence is a report commissioned by the seller before a sale process opens. An independent adviser examines the business and prepares a report that bidders may rely upon, ordinarily under a reliance letter. Its purpose is to shorten the process and to spare the management team a succession of separate examinations.
In procurement, the same phrase describes the examination a buyer performs on a supplier before contracting: financial standing, security, data handling, continuity and the terms of exit. Both senses now bear on the same businesses, because the suppliers a company depends on increasingly hold its data.
2
Who pays for vendor due diligence?
In the transaction sense, the seller pays. The report is commissioned and paid for by the vendor, which is where the name comes from. Bidders obtain access as part of the process, and a successful bidder ordinarily takes reliance on the report, sometimes for a separate fee. In the procurement sense the buyer pays, because the buyer carries the risk.
A bidder reading a seller-commissioned report should keep in mind who instructed it. Such reports are usually accurate. They are not neutral in emphasis, and they are rarely the place to look for the questions that were not asked.
3
What should be asked of an artificial intelligence supplier?
Price and functionality are the straightforward part. The terms that matter later concern data, dependence and exit.
We ask for written answers to a short list. What data does the supplier receive, and what does it retain. Is customer data used to train or improve the supplier’s models, and under which clause. Which subprocessors are involved, and in which countries do they operate. What accuracy or availability is committed, and what is the remedy when it is not met. What happens to the data on termination, and in what format is it returned. Answers given in a sales call and answers given in writing are frequently different.
4
What happens to the data, and for how long?
Retention is the clause most often left at the supplier’s default. Copies held for training, for abuse monitoring or for support may persist well beyond the working life of the request that created them, and may sit with a subprocessor rather than the supplier itself.
Two questions settle most of it. What is the longest period for which any copy of our data may be retained, in any system, by any party in the chain. And what evidence can be produced that deletion occurred. A supplier that cannot answer the second question has not implemented the first.
5
How difficult would it be to leave?
Lock-in with a supplier of this kind is rarely contractual. It accumulates in the work: prompts, evaluation sets, tuned weights, integrations and the habits of the people who use the system.
The practical test is to ask what a move to a comparable supplier would require, and to insist on an answer expressed in weeks and named staff rather than in principle. Where that answer exceeds a quarter, the dependence is strategic, and it should be reflected in the term of the contract and in the price agreed.
6
How is a portfolio company’s own supply chain reviewed?
A portfolio company usually has more suppliers of this kind than its board believes. Tools are adopted by departments, paid on cards and never registered anywhere central.
The review begins with the ledger rather than the architecture diagram. Every recurring payment to a software or data supplier is listed, matched to a business owner, and assessed for the data it receives. The exercise is unglamorous, and it routinely finds customer records leaving the business under terms that nobody in the company has read.