Third-Party AI Risk and Vendor Accountability: Contracts That Protect You
Overview
Your AI recruiting vendor's model has a bias problem. You discovered it in your quarterly audit. You want them to fix it. But what's their obligation? What happens if they refuse? What happens if they delay?
Most HR leaders don't negotiate vendor contracts carefully. They accept what the vendor proposes, sign, and move forward. Then when problems arise, they have no leverage. "The contract doesn't cover this." "There's no SLA." "We own the data but can't export it." "Liability is capped at annual fees, if they cause a $1M problem, we get $50K recovery."
This lesson teaches you vendor accountability, what to negotiate into contracts so you have leverage when things go wrong. You'll learn which contract clauses matter (accuracy warranty, SLA, DPA, liability). You'll understand where vendors push back and where you have leverage. And you'll build a vendor management approach that protects you while maintaining good relationships.
What Can Go Wrong With Vendors: The Risk Spectrum
Vendor provides bad service:
- Slow implementation (promised 8 weeks, takes 16)
- Accuracy lower than promised (promised 85%, delivers 70%)
- Model performance degrades over time (was accurate, now isn't)
- Support is slow or unhelpful (tickets go unanswered)
Vendor has security/compliance issues:
- Data breach (vendor's servers hacked)
- Doesn't comply with your data residency requirements (you need US-only data; they store in EU)
- Loses your data or can't guarantee availability (your data disappears)
Vendor changes model/service:
- Model is retrained; new version is less accurate
- Vendor adds features you don't want, breaks your workflow
- Vendor raises prices dramatically
Vendor goes out of business:
- You lose access to tool
- Can't get your data back
- Service stops mid-project
Solution: Good contracts. Contracts specify what vendor must do, what happens if they don't, and what your options are.
The Nine Essential Contract Clauses for HR AI
1. Accuracy & Performance Warranty
What it says:
"Vendor warrants that the model will achieve [X]% accuracy on [use case] when tested against [your data] or [vendor's benchmark data]. If accuracy falls below [X-10]%, vendor will remediate at no additional cost."
Why it matters:
- Vendor commits to specific accuracy level
- You have recourse if accuracy is lower
- Defines what "working" means upfront
- Protects you if they deliver sub-standard product
What to push for:
- Accuracy measured on your data, not vendor's curated test set
- Performance continues ongoing (not just at launch)
- Retraining at least annually to maintain accuracy
- Remediation obligation if accuracy drops
Example clause:
"Resume screening model will achieve 85%+ accuracy (measured by comparing AI recommendations to human review on a sample of 100 resumes) at launch and will be retrained annually to maintain this accuracy level. If accuracy drops below 80%, Vendor will at no additional cost either: (i) remediate within 30 days, or (ii) accept Customer termination without penalty."
2. Service Level Agreement (SLA)
What it says:
"System will be available 99.5% of the time, with maximum [4]-hour response time for critical issues. If SLA not met, Customer receives [X]% monthly fee credit."
Why it matters:
- Vendor commits to uptime
- You know what to expect when tool breaks
- You get credits if vendor misses SLA
What to push for:
- 99.5% or higher uptime (99% = 3.6 hours down per month; 99.5% = 22 minutes down)
- Response time for critical issues (ideally 1-4 hours)
- Credits/refund if SLA not met (e.g., "if uptime <99%, 10% monthly fee credit")
Example clause:
"Vendor warrants 99.5% system availability. Critical issues (system down, data access impossible) warrant 4-hour response time. High-priority issues warrant 24-hour response. If availability falls below 99%, Customer receives 10% monthly fee credit for each 0.1% shortfall."
3. Data Processing Agreement (DPA)
What it says:
"Vendor is a data processor. Customer is the data controller. Vendor processes personal data only as directed by Customer. Vendor cannot use Customer data for any purpose other than delivering the service."
Why it matters:
- Legally required under GDPR
- Defines how data can be used (not sold, not shared)
- You retain control
- Protects you from vendor misusing data
What to push for:
- Vendor can't use your data to train models (without explicit consent)
- Vendor can't share data with sub-processors without approval
- You can request data deletion
- Vendor handles data according to your instructions only
Example clause:
"Vendor shall not use Customer Data to train or improve vendor's model without Customer's prior written consent. Vendor shall not share Customer Data with any third party without Customer's approval. Customer may request data deletion at any time; Vendor shall comply within 30 days."
4. Data Residency Commitment
What it says:
"All customer data will be stored in [geography], either [US data centers only] or [EU data centers only] or [specific regions only]."
Why it matters:
- You control where data lives
- Regulatory requirement (some jurisdictions)
- Risk mitigation (data doesn't leave country if that's your requirement)
What to push for:
- Specify: "US data centers only" or "EU data centers only"
- If vendor uses multiple geographies, specify primary location
- Right to audit (you can verify where data actually is)
5. Intellectual Property & Data Ownership
What it says:
"Customer owns all data and outputs. Vendor owns the underlying model and software."
Why it matters:
- You own your data (vendor can't claim it's theirs)
- You own reports/recommendations (you can use them however you want)
- Vendor owns the tool/model (you can't copy and use elsewhere)
What to push for:
- Clear statement that data is yours
- Right to export/access your data
- Model output is yours (you can use recommendations however you want)
6. Liability & Indemnification
What it says:
"Vendor is liable for damages caused by their negligence, breach of contract, or data breach. Vendor indemnifies Customer against IP claims."
Why it matters:
- If vendor causes harm, you can claim damages
- Vendor has insurance to cover
- Protects you from IP lawsuits
What to push for:
- Liability cap should be 2-3x annual contract value (not $50K cap on $500K contract)
- Vendor indemnifies you for IP claims (you're not sued because vendor stole their model)
- Vendor covers security breaches and data loss
Example clause:
"Vendor's liability is capped at the greater of $1M or 3x annual fees. Vendor indemnifies Customer against claims that Vendor's service infringes third-party IP rights. Vendor indemnifies Customer against claims arising from Vendor's data breach."
7. Exit Rights & Data Portability
What it says:
"If customer terminates contract, vendor will export all customer data within [X] days in a standard format at no cost."
Why it matters:
- You're not locked in forever
- If vendor isn't working, you can leave
- You can move to different vendor
What to push for:
- Data export within 30 days of termination (not 180 days)
- Data in standard format (CSV, JSON, not proprietary format)
- No fees for data export
- Right to audit vendor's data retention (confirm they deleted your data after contract)
8. Regulatory Compliance Commitment
What it says:
"Vendor commits to compliance with [GDPR, CCPA, state AI laws, employment laws, FCRA, etc.]."
Why it matters:
- Vendor won't put you in legal jeopardy
- Your legal team has assurance
- Protects you from regulatory liability
What to push for:
- Specific compliance certifications (SOC 2, ISO 27001)
- Commitment to emerging regulations (EU AI Act)
- Regular compliance audits (vendor conducts, shares with you)
- Right to audit (you can verify compliance)
9. Bias Audit & Fairness Commitments
What it says:
"Vendor will conduct quarterly bias audits and report results to Customer at no additional cost."
Why it matters:
- Vendor is accountable for fairness
- You have early warning if model is biased
- Protects you from discrimination liability
What to push for:
- Quarterly bias audits (minimum)
- Audit methodology defined upfront
- Results shared with you (not hidden)
- Remediation plan if bias is detected
- No additional cost for audits
Example clause:
"Vendor shall conduct quarterly bias audits using [methodology] comparing selection rates across [protected characteristics]. Results shall be shared with Customer within 30 days of audit completion. If adverse impact is detected (4/5ths rule violation), Vendor shall provide remediation plan at no additional cost."
Negotiation Leverage: When You Can Push, When You Can't
You have leverage if:
- You're a large customer (vendor wants your business)
- You can credibly walk away (other vendors available)
- You're early adopter of their product (they want your success story)
- Your industry is strategic (vendor wants foothold in your sector)
You have limited leverage if:
- Vendor is the only option (no realistic alternatives)
- You're small customer (vendor doesn't care much)
- Vendor is well-established and doesn't need you
Negotiation strategy:
- Ask for everything. Vendors expect negotiation.
- Prioritize: which terms are must-haves vs. nice-to-haves?
- Compromise on timeline and price; don't compromise on liability and data control
- Get it in writing. Verbal promises don't matter. "The vendor said..." isn't enforceable.
Where vendors push back (and how to respond):
- "We don't warrant accuracy. AI is inherently unpredictable."
-
Response: "Then we need to measure accuracy before signing. If it's not 85% on our data in POC, we don't buy."
"Our liability is capped at annual fees."
Response: "That's unacceptable. If you cause a $5M data breach, we need to recover more than $100K. Liability should be 2-3x fees or unlimited for data breach."
"You can't audit our model. That's proprietary."
Response: "Fine. But you need to provide quarterly bias audit results. We need to verify fairness."
"Data export will take 6 months."- Response: "Unacceptable. You have 30 days. After that, we're paying for manual data retrieval."
Red Flags in Vendor Contracts
"Liability is capped at annual fees"
- Red flag: If vendor causes $5M breach, you get $100K recovery. Unacceptable.
- Fix: Cap should be 2-3x annual fees, or unlimited for data breach/indemnification
"Vendor owns model and all outputs"
- Red flag: Reports you generate are vendor's property; you can't use them
- Fix: You own outputs generated from your data
"Vendor can use your data to train models"
- Red flag: Vendor uses your recruiting data to improve their model (competes with you)
- Fix: Vendor can use only with explicit consent, and only for [specific purpose]
"No SLA or SLA with <99% uptime"
- Red flag: System can be down 7+ hours per month; you have no recourse
- Fix: 99.5%+ uptime, with credits for missed SLA
"Data export only in proprietary format"
- Red flag: You're locked in; can't leave because you can't get your data
- Fix: Export in standard format (CSV, JSON) at no cost
"No liability for data breach"
- Red flag: Vendor has no accountability if they get hacked
- Fix: Vendor is liable for data breach
"Vendor can terminate at will"
- Red flag: Vendor can leave you stranded
- Fix: Vendor can terminate for non-payment, but must give notice and help transition
"Contract auto-renews with price increase"
- Red flag: You're locked in, and costs keep rising
- Fix: Annual renewal; price locked for term; either party can decline renewal
Template Contract Clause: AI Accuracy & Bias
Here's a real clause you can use:
"Vendor warrants that the [Tool Name] will:
(a) Achieve [85]% accuracy as measured against [manually-scored reference set from Customer data] at launch and will maintain this accuracy level through [annual retraining/ongoing monitoring];
(b) Show no statistically significant adverse impact by [protected characteristic] as measured by [4/5ths rule or other standard] in quarterly bias audits conducted by Vendor at Vendor's expense;
(c) Be retrained or recalibrated if accuracy drops below [80]% or adverse impact is detected;
(d) Provide quarterly bias audit reports to Customer within 30 days of each audit, including: selection rates by demographic group, statistical significance testing, any adverse impact detected, and remediation plan if needed;
(e) Include all remediation costs in contract price if accuracy or fairness issues are detected.
If accuracy falls below [80]% or adverse impact is detected and not remediated within [30] days, Customer may terminate contract without penalty and receive full refund of remaining contract value."
Vendor Due Diligence Checklist
Before signing, verify:
- [ ] Accuracy/performance warranty (specific %, tested on your data, remediation commitment)
- [ ] SLA (99%+ uptime, response time for critical issues, credits for missed SLA)
- [ ] DPA (required for GDPR; defines data processing)
- [ ] Data residency (where does data live? Can you control it?)
- [ ] Liability cap (2-3x annual fees, not arbitrary low amount; unlimited for data breach)
- [ ] Exit rights (data export within 30 days, standard format, no fees)
- [ ] Compliance commitments (GDPR, CCPA, FCRA, state AI laws, employment law)
- [ ] Bias audit commitment (quarterly minimum, results shared, no additional cost)
- [ ] IP & data ownership (clear terms; you own data and outputs)
- [ ] Indemnification (vendor covers security breaches, IP claims)
- [ ] Sub-processor policy (can vendor use other vendors? You approve first?)
CALLOUT BOX: The Negotiation Dance
How a typical vendor negotiation goes:
You: "We need 99.5% uptime SLA with credits."
Vendor: "We can't guarantee that. We're a startup."
You: "Then we can't sign. What can you guarantee?"
Vendor: "99% is our max."
You: "99% is 3.6 hours down per month. That's too much for employment decisions. What about credits?"
Vendor: "We'll do 5% credit for 99%."
You: "That's not enough. 10% credit, or we walk."
Vendor: "Can you do 8%?"
You: "Done. But only for downtime >1 hour. Maintenance windows don't count."
Vendor: "Agreed."
This is normal. Vendors expect negotiation. If they don't budge on anything, that's a red flag.
Deliverable: Your Vendor Accountability Checklist (1 page)
Create a one-page document you review before signing any contract:
- [ ] Accuracy/performance warranty
- [ ] SLA (uptime, response time)
- [ ] Data Processing Agreement (if GDPR applies)
- [ ] Data residency commitment
- [ ] Liability cap (2-3x annual fees)
- [ ] Exit rights (30-day export, standard format)
- [ ] Compliance commitments (GDPR, CCPA, state laws)
- [ ] Bias audit commitment (quarterly)
- [ ] IP & data ownership
- [ ] Indemnification
What to Do Monday Morning
Review your current vendor contracts. What clauses are missing? What's weak?
Prioritize your must-haves. Which 3-5 clauses are non-negotiable for you?
Create your negotiation checklist. Use the 9 essential clauses above.
Brief your Legal team. Make sure they know what matters for HR AI contracts.
Start renegotiating. If you're mid-contract, ask for amendments. If you're renewing, use this as leverage.
For new vendors: Use your checklist. Don't sign without these protections.
Key Takeaways
Get it in writing. Verbal promises don't count.
Liability cap matters. Don't accept unreasonably low caps ($50K cap on $500K tool is unacceptable).
Data residency is non-negotiable. You need control over where your data lives.
Exit rights matter. You need ability to leave if vendor isn't working.
Bias audits are non-negotiable for employment AI. Vendor must be accountable.
Compliance commitments protect you. Make vendor warrant they comply with law.
FAQ
Q: Is DPA required?
A: Yes, if you're GDPR-regulated (Europe) or processing EU residents' data. Even US companies handling EU candidates need DPA. Most vendors have standard DPA; some will negotiate terms.
Q: What if vendor won't agree to accuracy warranty?
A: Red flag. It means they're not confident in their accuracy. Either push harder or find different vendor.
Q: Can we negotiate price instead of contract terms?
A: Yes, but don't trade away critical protections for 5% discount. Better terms matter more than small discounts. Bad contract + low price = expensive mistake.
Q: What if we're locked into a bad contract?
A: Renegotiate. Most vendors prefer to negotiate than lose customer. "We need these amendments or we're leaving when contract ends" is powerful leverage.
Q: How often should we review vendor contracts?
A: Before signing (obviously). Before renewal (renegotiate). After any incident (did vendor breach their obligations?). Annually as part of vendor review.
What's Next
You've managed vendor accountability through contracts. Now you need to navigate the regulatory environment. Employment AI is regulated differently in the EU (EU AI Act) than in the US (state laws, EEOC guidance). Next chapter: Employment Law and Regulatory Strategy.
Your vendor contracts protect you from vendor risk. Regulatory compliance protects you from legal risk.
Skill.re