QuestionAI GovernanceLegal ServicesFinancial Services

How Should UK Professional Services Firms Assess AI Vendor Tenant Isolation?

5 October 2026
Answered by Rohit Parmar-Mistry

Short answer

A quick answer first, then the fuller context below.

Before using an AI vendor for confidential client work, professional-services firms should map the model-call data path, request evidence of tenant-separation controls and record unresolved questions, owners and the adoption decision.

What this points to

This usually points to Secure AI implementation

If this question reflects a real workflow, supplier, data or governance decision inside the firm, do not treat the answer as theory. Use it to decide whether you need a light assessment, a deeper audit, a controlled implementation path, governance support or recovery from a genuinely stalled AI attempt.

Detailed answer

The fuller context, trade-offs and practical steps behind the short answer.

What should a professional services firm check before putting client work through an AI vendor?

A firm should be able to explain how one customer's prompts, uploaded documents and outputs are kept separate from another customer's data at the point the AI service calls a model. A general statement that the platform is secure is not enough: ask for the specific tenant-isolation design, who can access each data path, and what evidence the vendor can provide.

How to assess tenant isolation at the model call

Start by mapping the full request path: the firm's user or application, the AI vendor's service, any foundation-model provider, and the systems that retain prompts, outputs and logs. Ask the vendor to identify where tenant identity is checked, how it is carried into each model request, and how the service prevents one customer's context or records from being exposed to another.

Ask whether model calls use per-customer credentials or deployments, or shared credentials protected by logical controls. Neither label proves safety on its own. Request an architecture explanation that covers the boundary, the controls applied to shared infrastructure, the people and service accounts able to cross that boundary, and how access is logged. Ask what changes if the vendor changes a model provider or adds a sub-processor.

Then request evidence appropriate to the sensitivity of the work: a current architecture or data-flow diagram, a description of tenant-separation tests, relevant independent assurance, and the contract or data-processing terms governing prompts, outputs, retention and model-provider access. Evidence should relate to the AI feature and service tier your team will actually use, not only to the vendor's wider platform.

Map AI vendor and client-data risks in an AI Risk & Efficiency Audit

What evidence should the review retain?

Record the vendor and product version, the data classes involved, the model providers and sub-processors identified, the isolation design described, the evidence reviewed, unanswered questions and the decision owner. Note whether prompts or outputs are retained, which features can access them, how long they remain available, and how a firm can retrieve or delete relevant records.

For client-facing or regulated work, also check how the service records who initiated a request, which model or feature handled it, what policy applied and where a reviewer can obtain the audit evidence. Confirm that the firm's own access controls and review points remain effective. A questionnaire answer is a starting point; verify material commitments in the applicable contract and product configuration.

When should a firm pause adoption?

Pause before entering confidential client material if the vendor cannot describe the model-call boundary, gives no usable evidence for its separation controls, or cannot explain its model-provider and retention arrangements. A refusal or material gap is a finding to document and resolve, not an assurance. Consider a lower-sensitivity use case, a controlled test with synthetic data, or a different service configuration while the gap is assessed.

This is a risk-based procurement check, not a guarantee that any architecture eliminates disclosure risk. The decision should reflect the actual work, client and regulatory obligations, contractual terms, available evidence and the firm's ability to monitor changes.

Make the control decision part of implementation

Assign an owner to approve the use case and evidence, set a review date, and define triggers for reassessment such as a new model, feature, sub-processor or contract term. Tell staff what information may be used, which tools and settings are approved, and where to escalate an exception. Keep a record of the decision and the human review required before AI-assisted work reaches a client.

Set ongoing AI governance and review controls

For a broader assessment of where AI can help or create risk, Pattrn Data's AI Risk & Efficiency Audit can map the work, data, owners, handoffs and controls before tool spend. Where the decision is to proceed, an AI implementation project can put the agreed controls into practice.

Frequently asked questions

Direct follow-up answers written for searchers, buyers and internal decision makers.

Does a shared model API automatically mean customer data is mixed?

No. Shared infrastructure can use logical separation, but the firm should understand and verify the specific controls, identity checks and evidence rather than assuming either safety or exposure from the word “shared”.

Is a vendor's security certification enough to prove tenant isolation?

Not by itself. Check that the assurance scope covers the AI feature and relevant data path, then ask for details about model calls, access, retention and the evidence available for the firm's use case.

What if the vendor will not provide its architecture diagram?

Ask for a suitably scoped explanation or independent evidence that answers the isolation questions without disclosing sensitive implementation details. If the remaining uncertainty is material to client confidentiality or regulatory duties, record the gap and pause that use case.

Should we test with live client data?

Begin with synthetic or otherwise approved low-sensitivity data. Use live client data only after the firm's authorised owner has reviewed the applicable client terms, data protections, vendor arrangements and safeguards.

How often should we revisit the decision?

Set a review date and reassess sooner when the vendor changes its model, AI feature, sub-processors, retention terms or isolation design, or when the firm's use case or data sensitivity changes.

Need More Specific Guidance?

Every organisation's situation is different. If you need help applying this guidance to a specific process, book a discovery call or take the assessment first.