Questions to Ask About AI Workspace Isolation
A security review checklist for identity, workspace access, connectors, model providers, retention, and auditability.
- Keep material claims connected to their evidence.
- Assign review responsibilities before work begins.
- Evaluate the complete IC preparation and review process.
Before sharing confidential deal evidence with an AI service, involve the people responsible for information security and data processing. Evaluate the proposed service and its documented commitments against your firm’s requirements.
Establish permission and access
Identify which deal documents may be processed and who may access them. Confirm organization boundaries, team membership and reviewer roles. Source permissions should be established before upload.
Understand the data flow
Ask where documents, extracted text, prompts and outputs are processed. Identify model providers and other subprocessors, their permitted uses and the terms covering confidential information.
Agree retention and deletion
Review hosting location, storage, backups, retention periods and deletion responsibilities. Ask how access is removed when a team member leaves and what happens to deal materials when the engagement ends.
Document the decision
Keep the security review materials, agreed controls and any exceptions with the commercial scope. Assign an owner to resolve outstanding questions before data is shared.
Underlying reviews access, provider handling, region, retention, deletion and exports with your security owner before a pilot. The commitments for your engagement are documented in the applicable agreement and review materials.
Put this into practice
Evaluate one authorized deal pack, your firm’s memo format, and a named analyst and senior reviewer.
