Free guide · 10 pages

Before you sign with
an AI vendor

Twelve questions to ask before you commit — with, for each one, what a good answer contains and the signal that should worry you. Written for regulated professions in Quebec.

Get the guide →

The twelve questions

The full content is below, freely accessible. The PDF adds the layout, the printable comparison checklist, and a format you can pass along to your partners.

Question 01

Where exactly does inference run?

Why it matters

This is the founding question. Everything else follows from it: applicable jurisdiction, legal exposure, and your ability to document your compliance.

A good answer

A precise, verifiable location — “on the server installed on your premises,” or “in this data centre, at this address, operated by this company.” The vendor should be able to show you where.

Warning sign

“In the cloud,” “on secure servers,” “at our infrastructure partner” with no further detail. Vagueness isn't commercial discretion, it's the absence of an answer.

Question 02

Is our data used to train a model?

Why it matters

If your documents are absorbed into a model, you lose all control over where they end up and you can no longer withdraw them.

A good answer

A clear no, together with an explanation of the architecture used instead — typically RAG. The vendor should also address the third-party providers it relies on.

Warning sign

“Your data is anonymized before training,” or an answer covering only the vendor without addressing the third-party models it calls.

Question 03

Does every answer cite its source?

Why it matters

Without citations you can neither verify nor defend an answer. In front of a client, a professional order or a court, “the tool told me” is not a defensible position.

A good answer

Yes, with the file, the section and the version. Ask for a live demonstration rather than an assurance.

Warning sign

Vague citations at document level rather than passage level. Or an answer along the lines of “the model is very reliable” — which sidesteps the question.

Question 04

What does the agent do when it can't find the answer?

Why it matters

This is the most revealing test of a deployment's quality. A well-designed system knows its limits.

A good answer

It says so explicitly and invents nothing. Some systems go further and cross-check an uncertain answer before presenting it.

Warning sign

“That doesn't happen,” or an evasive reply. Every system meets questions outside its scope; what matters is what it does at that moment.

Question 05

Who at the vendor can access our documents?

Why it matters

Vendor staff access is rarely volunteered, yet it is a real breach in confidentiality.

A good answer

Nobody, or strictly controlled access that is logged and requires your prior authorization. The vendor should be able to describe the technical mechanism that prevents it, not just its internal policy.

Warning sign

“Our employees sign a confidentiality agreement.” An agreement is a contractual commitment, not a technical barrier.

Question 06

Which subcontractors are involved, and where are they based?

Why it matters

The chain usually has more participants than advertised: host, model provider, email service, monitoring tool. Each one is a potential jurisdiction.

A good answer

A complete named list with countries of establishment. A vendor that has thought through its compliance knows this list by heart.

Warning sign

Hesitation, or a partial list that keeps growing as you ask more questions.

Question 07

Are we exposed to the CLOUD Act?

Why it matters

This is the point American vendors most often deflect, by steering the conversation toward the physical location of servers.

A good answer

A direct answer. If the vendor or one of its subcontractors is a US company, the exposure exists — even with servers in Canada. An honest vendor acknowledges this and explains how it limits it.

Warning sign

“Your data is hosted in Canada, so you're protected.” That is false, and it reveals either unfamiliarity with the statute or a willingness to reassure you cheaply.

Question 08

How is the document scope defined?

Why it matters

An agent with access to everything is an agent that can mix up two clients' files, surface an outdated version, or consult unvalidated internal notes.

A good answer

An explicitly defined scope, document by document or file by file, with the ability to exclude and withdraw. Ask how a document is removed once indexed.

Warning sign

“The agent learns from your entire history.” Framed as a benefit, it is in reality an absence of control.

Question 09

What happens if we terminate the contract?

Why it matters

The exit is negotiated at the entrance. It is also a Law 25 requirement in terms of portability.

A good answer

Your documents belong to you and are returned in a usable format. The index and copies are destroyed within a defined period, with written confirmation.

Warning sign

No written procedure, or data returned in a proprietary format unusable anywhere else.

Question 10

What audit trail exists?

Why it matters

Before the Commission d'accès à l'information or your professional order, you will need to document what data was processed, by whom and on what basis.

A good answer

A consultable log of access and queries, an inventory of indexed data, and the ability to reconstruct how a specific answer was produced.

Warning sign

“We are compliant” with nothing you can consult on your side. Compliance must be demonstrable by you, not merely asserted by the vendor.

Question 11

Who trains our teams, and what happens after deployment?

Why it matters

The most common cause of failure isn't technical. It's abandonment: the tool is delivered, nobody takes ownership, and six months later it goes unused.

A good answer

Training included, follow-up scheduled over time, and a named point of contact. Ask what happens in month three.

Warning sign

Training billed separately and left optional, or support available only through a ticketing system.

Question 12

Can we change hosting model later?

Why it matters

Your needs will evolve. A firm that starts cautiously in a sovereign cloud may want to bring its infrastructure in-house after growth or a sensitive mandate.

A good answer

Yes, with a description of the migration path and what it involves in time and cost.

Warning sign

An architecture that works in only one mode. You are then locked in, however good the service.


Get the document

The download starts immediately, and you also receive a copy by email.