HIPAA Compliance Checklist for 2025
The AI Vendor Security Questionnaire: What to Ask Before Approving Claude, ChatGPT, or Copilot
Legal asks whether Claude trains on your contracts. The honest answer starts with another question.
Q: Which Claude did you approve?
Most approvals don't say. They name a brand, not a tier, a set of settings or a date.
Copilot shows why that matters. Tenants approved in 2025 have since had Anthropic, then OpenAI, switched on by default.
And 47% of enterprise AI conversations run through personal accounts, according to LayerX.
This guide covers what to ask the vendor, what to check in your console, and what only your environment can tell you.
What Does an AI Vendor Security Review Actually Approve?
An AI vendor security review approves a snapshot: the vendor's contract, your configuration and the usage you assumed, all as they stood on one date. When any of the three moves, the approval quietly stops describing reality.
Copilot is the cleanest proof. In September 2025, Anthropic models arrived in certain Copilot experiences as an opt-in under Anthropic's own terms. On January 7, 2026, Microsoft made Anthropic a subprocessor and switched its models on by default for most commercial tenants, except in the EU, EFTA and UK (MC1193290).
Then OpenAI followed. Its subprocessor setting appeared on July 9, 2026, switched off, and flipped to on for all users on July 24 unless an admin had already chosen otherwise (MC1422074). A fifteen-day window decided whether a second outside lab processed your staff's prompts. Nobody signed anything.

None of this was a breach, and Microsoft brought both providers under its own DPA. The point is narrower and harder: the vendor answered your questions honestly, and the answers expired anyway. Reco makes the same observation, calling questionnaire answers claims made on one day about a product that changes weekly.
Why Do Claude, ChatGPT and Copilot Each Carry More Than One Risk Profile?
Each brand is several products for data purposes, and the tier your employee picks decides which contract governs the prompt. Approving "Claude" without naming the tier approves nothing specific.

Look at the last row of that table again. Even the tier you bought, used exactly as intended, sends web-grounding queries somewhere your DPA doesn't reach.
The procurement ticket says "ChatGPT: approved." Nobody wrote down which ChatGPT.
Claude shows the spread. Free, Pro and Max users choose whether chats train models, with five-year retention for those who allow it; Claude for Work and the API sit under commercial terms and are excluded. Claude inside Copilot runs under Microsoft's DPA, and its processing happens outside the EU Data Boundary.
ChatGPT splits the same way, consumer tiers train unless the user opts out, while Business, Enterprise and the API don't by default. Copilot adds a twist: since August 2026, one Copilot app accepts both personal and work sign-ins, and enterprise controls apply only to the work account.
This would be a footnote if people stayed on the tier you bought. They don't. LayerX found 47% of enterprise AI conversations run through personal identities, and on ChatGPT, Claude and Copilot, over 60% do.
Harmonic Security adds the uncomfortable half: 64.5% of activity on personal and free accounts is business work. Your Enterprise contract is excellent, and it covers a minority of the prompts carrying your data.
What Should You Ask the Vendor Before Approving Claude, ChatGPT or Copilot?
Ask the eight questions whose answers differ between vendors and change your decision. Skip what all three answer identically: each holds SOC 2, encrypts at rest and in transit, and supports SSO on business tiers.

- Is "no training" a contract term on every tier our people can reach, or a setting?
- What is the longest any copy of a prompt can live, flagged content included?
- Which model providers touch our prompts, and how much notice do we get before that list changes?
- Which of those providers sit outside our residency or data-boundary commitments?
- What can connectors, plugins and MCP servers reach, and can we allowlist them centrally?
- Can we export per-user activity and admin logs to our SIEM?
- What happens to a user's chats, files, agents and API keys when we deprovision them?
- Does your SOC 2 or ISO 42001 scope name the exact feature and model route we're buying?
The answers diverge more than the marketing suggests. Rajesh Beri's September 2026 teardown found Anthropic's standard DPA offers only "reasonable notice" of new subprocessors, and its API docs allow flagged content to be kept up to two years even under zero data retention.
Microsoft scores well on evidence, yet the same teardown notes Copilot's Bing web-grounding queries fall outside its DPA entirely. Question eight exists because of a SOC 2 quirk: under the carve-out method, a vendor's report can exclude the model provider's controls, which is exactly where your prompt goes.
Treat question one as a gate. If the vendor can't prevent consumer-tier use on your corporate domain, everything else you negotiate applies to the minority of usage shown in the previous section.
If the contract is your whole problem, Beri's teardown is the most thorough on the web and worth its 20 minutes. This guide spends its words on the two layers a contract can't see.
If spend is part of the same review, see how teams handle tracking Claude spend alongside Cursor and Gemini.
What Should You Check in Your Own Admin Console Before Go-Live?
Record five settings, with a date and an owner, before a single user logs in. Vendor answers describe what the product can do; your console records what you chose, and an unused control protects nothing.
- Model providers switched on. In Copilot, this sits under Copilot, Settings, AI providers operating as Microsoft subprocessors; screenshot it, because defaults change.
- Workspace retention, set to your records schedule rather than the vendor default, with the exceptions (flagged content, legal holds) noted beside it.
- Connector and MCP policy, meaning who can add a data source, whether an allowlist exists, and whether new connectors need approval.
- Agent building and sharing, covering custom GPTs, Claude projects and Copilot Studio agents, and whether a user can publish one org-wide.
- Personal-workspace controls, such as domain capture or ChatGPT Enterprise's workspace blocking, which limits access to approved workspace IDs on managed network paths.
This list becomes your baseline. When a setting later differs from it, that difference is a finding, whether an admin changed it or the vendor did.
Write it down even if it feels obvious. In plenty of companies, the only record of why Anthropic is switched off lives in one admin's head, and it leaves when they do.
What Does Your Environment Show That a Vendor Questionnaire Can't?
Your environment answers the questions a vendor never sees: who is actually using the tool, on which account, through which agent, and at what cost. These five need telemetry, not a form.
Who Uses Each Brand, and on Which Tier?
Count users per brand across SSO logins, browser activity and expense reports. A Claude Pro subscription on a corporate card is a consumer-terms account holding company data, whatever your policy says.
Which Workspaces Exist Outside Your Tenant?
Look for the second ChatGPT Team workspace a department bought for itself, or the Claude Team plan a product group expensed. Each is a separate contract with its own admin, often a manager who never saw your questionnaire.
Which Agents, MCP Servers and API Keys Sit on Top of the Approved Tool?
The approved seat is now a runtime. Researchers cited by The Hacker News found roughly 7,600 malicious GitHub repositories, over 800 of them posing as AI Skills or MCP servers. Every key and connector needs an owner, a scope and an expiry.
What AI Access Survives When Someone Leaves?
Offboarding usually kills the SSO account and stops there. The personal Claude account holding last quarter's board deck survives, as does the API key hard-coded into a teammate's script.
What Is It Costing, by Team and by Token?
Usage-based billing hides duplication. Three teams paying for overlapping assistants is a spend problem and a data-sprawl problem at once, because each copy of the work lives under a different contract.
One honest limit: no tool closes this gap completely. A personal account on a personal phone, off the corporate network, sits outside everyone's telemetry. The goal is to make that the exception, not 47% of the traffic.
Our take: a questionnaire tells you what a vendor promises to do with the data it receives. Only your environment tells you what data it is receiving, and through which door.
When Does an AI Vendor Approval Expire?
An approval expires the moment one of its three layers changes, so write the reopen triggers into the approval record itself. Five events should pull a signed-off vendor back into review:
- The vendor adds a model provider or subprocessor, as both Copilot changes did in 2026.
- Terms change on any tier your people use, including consumer tiers you never bought, as Anthropic's August 2025 update did.
- A new capability class ships, such as agents, computer use, connectors or a plugin marketplace.
- Your usage crosses a line, with a new team, a new data class, or a rising share of personal-tier traffic.
- Renewal comes within 90 days, the one moment your leverage is highest.
Assign each trigger an owner and a source of truth. Triggers one and two come from vendor notices; three to five come only from watching your own environment.
What Should an AI Vendor Approval Record Contain?
A useful approval record fits on one page and names the exact thing approved, so the next reviewer can tell in minutes whether it still holds. Most teams file the vendor's completed questionnaire and a sign-off email; neither says what was actually approved.
The record does two jobs. It makes the approval specific enough to break, and it tells whoever inherits the tool what to check first when something changes.
Keep it next to the contract, not in a security team's shared drive. Procurement opens the contract at renewal; if the record sits beside it, the reassessment happens by default.
How Does CloudEagle.ai Keep an AI Vendor Approval Current?
CloudEagle.ai runs the third layer continuously, so the environment questions stop being an annual exercise. It correlates SSO, finance, browser and firewall data to show every AI app in use, including personal-tier accounts the IdP never sees, and risk-scores each one through its EagleIQ inventory.
The same AI governance layer discovers AI agents and MCP servers, and puts API keys and service accounts under NHI management with an owner and a status. When someone reaches for an unapproved tool, a redirect page points them to the one you signed off.
On the vendor side, AI-extracted contract metadata tracks renewal dates and terms, and renewal workflows fire up to 90 days ahead with usage attached. That turns trigger five into a routine rather than a scramble.
A passed questionnaire was never the goal. Knowing, on any given Tuesday, what you are actually running is. Aditya Khosla, CTO at Iterative Health, describes the shift as moving from ad-hoc approvals to structured, defensible AI governance once adoption outran visibility.
Your questionnaire records what you approved. CloudEagle.ai shows you, every day, whether that is still what's running. See how shadow AI discovery works across SaaS, AI and non-human identities.
Frequently Asked Questions About AI Vendor Security
What Is an AI Vendor Security Questionnaire?
It is the AI-specific layer of a vendor risk review, covering training on your data, prompt retention, model subprocessors, connectors and agent access. Standard SIG or CAIQ templates miss most of it, because they assume data stays inside the vendor's own application.
Is ChatGPT Enterprise, Claude for Work or Microsoft 365 Copilot Safe for Company Data?
Each business tier commits not to train on your data by default and supports SSO, audit logs and admin controls. The risk sits elsewhere: in consumer tiers your people also use, in model providers added after approval, and in connectors and agents built on top of the approved seat.
How Often Should You Reassess an AI Vendor?
At least once a year and at every renewal, but annual is the floor, not the rule. Reopen the review whenever the vendor adds a model provider, changes terms on any tier your people use, or ships a new capability class such as agents or connectors.
Does a SOC 2 Report Cover the AI Features You Are Buying?
Not necessarily. Under the SOC 2 carve-out method, a vendor's report can describe a model provider without testing that provider's controls. Ask which subservice organizations were carved out, and confirm the AI feature and its model route sit inside the audited scope.
Who Should Own AI Vendor Approvals?
Security usually runs the review, but the approval needs three owners: procurement for the contract and renewal, IT for console settings, and security or GRC for the environment evidence. Without all three, one layer goes unwatched, and that is where the approval quietly expires.




.avif)




.avif)
.avif)




.png)




.avif)
.avif)
.avif)

