Skip to main content
Choose AI Stack
Search

Buyer template · Due-diligence checklist · Updated 2026-09-11

Vendor Pricing and Security Review Checklist

A due-diligence checklist for reviewing an AI vendor's pricing terms and security posture before signing.

When to use it: Use this before committing to a paid plan, especially at the team or company level.

Browse all templates

Pricing

  • Confirm what is included at the plan tier you are evaluating, not just the headline price.
  • Check for per-seat minimums, usage-based add-ons, and annual-commitment discounts or penalties.
  • Confirm what happens to your data and access if you downgrade or cancel.

Security and privacy

  • Confirm whether your data is used for model training by default, and how to opt out if so.
  • Check for SSO/SAML, role-based access control, and audit logs at your plan tier.
  • Confirm data retention and deletion timelines, and where data is stored and processed.
  • Ask for a current SOC 2, ISO 27001, or equivalent report if your compliance requirements need it.
  • Record when each pricing, security, privacy, and contract source you rely on was checked and what change or age would make it stale; recheck stale evidence before signing.

Contract and exit

  • Confirm data export options before you sign, not after you need to leave.
  • Before a company-wide or annual commitment, run one representative exit test: export a small but real working artifact or data set, open or reuse it outside the vendor, and record any format, permission, or dependency that would block a practical move.
  • Note the renewal and cancellation terms, including notice periods.
  • Record the renewal date, notice deadline, review owner, and a 30-60 day checkpoint for rechecking usage, value, pricing, and security before the contract rolls over.

Make the decision

  • Choose one disposition: approve, run a bounded pilot, hold for missing evidence, or reject. Do not let an incomplete review turn into an accidental purchase.
  • Record the decision owner, the reason, and any condition that must be cleared before the vendor can move forward.
  • For every missing pricing, security, privacy, contract, or exit check that keeps the decision on hold, name the evidence owner and due date; do not let waiting on evidence become an ownerless approval state.
  • For an approval or pilot, record the exact team, workflow, seat, data, and integration scope covered by the decision; treat anything broader as a new approval decision.
  • Record the expected recurring and usage-based spend for that approved scope, plus the spend or seat-growth threshold that forces a fresh approval before expansion.
  • If the vendor moves to a pilot, carry unresolved pricing, security, privacy, contract, and exit checks into the pilot record and require each one to be closed or explicitly accepted as a named exception before broader rollout; approval to test is not approval to scale.
  • For every named exception accepted before broader rollout, record the exception owner, expiry or review date, the condition required to renew it, and the evidence that will prove the exception can close; when it closes, record that evidence and the closure date. An expired exception reopens the vendor review instead of becoming permanent by default.
  • Reopen the review before purchase or broader rollout if the plan, pricing model, data-use terms, security posture, access scope, or contract terms materially change after approval.

Related workflows

Related comparisons

  • ChatGPT vs Claude

    A practical comparison for teams choosing a general AI assistant for writing, analysis, research, and lightweight coding help.

Not sure which stack fits first?

Take the stack quiz for a recommended starting point.

The deterministic quiz returns a recommended stack, avoid-for-now guidance, and a rollout note you can carry into this checklist.

Stack update memo

Get practical AI stack updates.

Low-frequency notes on pricing, privacy/security, new comparisons, and verdict changes across the workflows you care about.

  • Pricing and plan changes to review
  • Privacy and security documentation changes
  • New workflow guides and comparisons

Only when there is a material change to report — not on a fixed schedule, and no spam. See the sample issue or privacy policy before you sign up.