Vendor Due Diligence on Your Recordings
Your recordings leave your estate. Where they go, who hears them, how long they stay and whether they train models are contract questions.
A speech analytics vendor processes recordings of your customers and your employees. The due diligence questions are specific and several have unsatisfactory standard answers.
Where the data goes
Which countries is it processed in? Relevant for data protection transfer rules and for sector-specific requirements.
Which sub-processors are involved? Transcription, storage, model inference and support may each be a different party. Ask for the list and for notification of changes.
Is any of it processed by a model provider? Where the platform uses a third-party language model, your call content reaches that provider, and the terms between the vendor and them matter to you.
Can processing be restricted to a region? Frequently available at a price.
Who can hear it
Which vendor staff can access customer audio, under what circumstances, and is that access logged?
Is support access to your data controlled and time-limited?
Are transcripts reviewed by humans for quality improvement? Several transcription services do this and it is disclosed in terms nobody reads.
Is there a route to prohibit human review of your data, and does it cost extra?
Training
The question with the most consequential answer.
Is our audio or transcript used to train or improve models?
Is it the default, and can it be turned off?
Does turning it off apply retroactively? Generally not.
If data was already used, can it be removed? Generally not, which is why the question belongs before deployment.
A vendor whose standard terms permit training on customer content is a vendor whose product is partly built from your customers' conversations, and that is a decision to make deliberately.
Retention and deletion
What does the vendor retain, and for how long?
Can we instruct deletion, and is it verified?
What happens on termination? Return, deletion, or a period of continued retention.
What about backups and derived data — indexes, models, aggregates?
Security and assurance
What certifications, and are the reports available rather than just the logo?
Encryption at rest and in transit, and who holds the keys.
Breach notification terms, with a timeframe.
Right to audit, even if rarely exercised.
Penetration testing, and whether results are shared.
The contract terms that matter
A data processing agreement meeting your jurisdiction's requirements.
Sub-processor notification and objection rights.
No training on customer content, or an explicit opt-out.
Deletion on instruction and on termination, with verification.
Export in a usable format, which is the exit provision and the one most often weak.
Liability that bears some relationship to the harm a breach of this data would cause.
The question that reveals the most
"Can you show us the sub-processor list and the data flow diagram?"
A vendor with mature governance produces both. A vendor who has not thought about it produces a marketing page about security.
The follow-up: "Which of these have access to raw customer audio?" The answer is frequently more parties than the buyer expected, and it is the answer that should drive the rest of the diligence.
The data flow diagram
The artefact that answers most due diligence questions at once, and the one that reveals whether a vendor has thought about this.
Where audio is captured and where it first lands.
Every system it passes through, including transcription, storage, indexing, model inference and support tooling.
Which of those are the vendor's and which are sub-processors.
Which countries each sits in.
Where copies are retained, and for how long.
Which components have human access, and under what controls.
Where derived objects live — transcripts, indexes, summaries, models.
Ask for it during evaluation. A mature vendor produces one. A vendor who cannot has not mapped their own processing, which is itself the finding, and it predicts how the deletion and export questions will go.
External reference: protecting personal information.