Incident Response & Vendor Due Diligence
Even with good controls, incidents happen: a tool receives sensitive data, an output contains hallucinated citations, or an AI-generated draft is shared too broadly. The solution is a pre-planned response and better vendor vetting.

AI incident response: 7 steps
- Stop the spread: pause use; prevent further sharing.
- Preserve evidence: save prompts/outputs, timestamps, users, and tool settings.
- Assess scope: what data was involved, where did it go, who saw it?
- Escalate: notify the supervising attorney and the designated incident owner (risk/IT).
- Correct the record: if something was filed or sent, fix it quickly and transparently.
- Notify as required: clients, courts, insurers, or regulators if applicable.
- Improve controls: update policy, training, tool configuration, and checklists.
Vendor due diligence checklist (AI tools)
- Data use: Does the vendor train on your data? Can you disable training?
- Retention: How long are prompts/outputs stored? Can you configure retention?
- Security: Encryption in transit/at rest, access controls, audit logs, SOC2/ISO posture
- Subprocessors: Who else processes the data? Where are they located?
- Incident terms: Notification timelines and cooperation obligations
- Data export/deletion: Can you export logs and delete data on request?
- Model transparency: Versioning, known limitations, and change notifications
Red flags
- Vague language about data use (“may use to improve services” with no controls)
- No admin controls for retention, logging, or access
- No clear incident notification obligations
Practice tip: If you cannot explain where the data goes, you cannot defend confidentiality safeguards.