QuestionAI GovernanceLegal ServicesImplementation

How can UK professional-services firms check whether an AI vendor trains on client data?

25 September 2026
Answered by Rohit Parmar-Mistry

Short answer

A quick answer first, then the fuller context below.

Check the contract and settings for the exact AI service and account tier to establish how prompts, files and outputs are used and retained. Before client work is in scope, record the evidence, set an approved-data boundary and assign a human reviewer.

What this points to

This usually points to Secure AI implementation

If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.

Detailed answer

The fuller context, trade-offs and practical steps behind the short answer.

Before using an AI service for client work, a UK law, accountancy, insurance or advisory firm should establish what happens to prompts, uploaded files and outputs. Product labels alone do not answer whether content is used for training, how long it is retained or which parties may access it. Check the terms and settings for the exact service and account tier, then document the decision before confidential client material is used.

Check the service, account tier and evidence

Ask the vendor to clarify whether customer prompts, files or outputs are used to train or fine-tune models; whether the answer differs by plan or configuration; how content and logs are retained; and which subprocessors may receive it. Distinguish contractual commitments from configurable settings and general product descriptions. Record what you reviewed, the account tier, the date and the evidence source, as terms and settings may change.

Set a client-data boundary before a pilot

Until the firm has assessed and approved the relevant controls, keep confidential, privileged and personal client information out of the service. A bounded test may use public, synthetic or suitably anonymised material, after considering whether people or clients could still be identified. Define approved tools and uses, who can authorise an exception, and what staff should do if information is entered into an unapproved service.

Make the decision owned and reviewable

Assign an owner to maintain the vendor evidence and approved-use decision. Keep a dated record of the service tier, terms and settings checked, permitted data categories, decision rationale and review date. Use an approved account, provide a route for staff to raise uncertain cases, and require a competent professional to review material outputs before they inform advice or are sent to a client.

Review the decision when terms, models, retention controls or subprocessors change, or when the firm proposes a new use case. A Pattrn Data AI Risk & Efficiency Audit can help map use cases, data, owners and control gaps before wider rollout. Where ongoing ownership is needed, explore governance retainers. For help implementing an agreed, bounded use case, see AI implementation projects.

Source and scope

Source question: “Will the vendor use your prompts and documents to train or fine-tune models that serve other customers?” Source: Compyl, “Vendor AI questionnaire template”. This article provides an operational risk-check framework, not a legal determination or a claim that any vendor is compliant or non-compliant. Firms should have the appropriate privacy or legal owner assess their specific circumstances.

Frequently asked questions

Direct follow-up answers written for searchers, buyers and internal decision makers.

Does every AI vendor train on customer prompts?

No single answer applies to every service, account tier or configuration. Check the current terms and settings for the specific service rather than relying on a general product description.

Is turning off chat history enough to protect client data?

Not necessarily. Separately verify training use, retention, logging, access and subprocessors, and record the evidence used for the firm's decision.

What should a firm do if it cannot verify the controls?

Keep confidential, privileged and personal client information out of that service until an authorised owner has assessed the risk. Consider a bounded test with appropriate non-sensitive material or select a service whose controls can be assessed.

Need More Specific Guidance?

Every organisation's situation is different. If you need help applying this guidance to a specific process, book a discovery call or take the assessment first.