Check suppliers and test the controls
Course overview · 4 min reading + 12 min practice, estimated
Principles and method
Before introducing a supplier, understand what information leaves your system, where it is handled, who can access it and how it is returned or removed. Review contractual and security arrangements with the appropriate specialists. Ask whether inputs are used for model training and whether settings and contracts actually support the intended restriction. Test export, correction and deletion using fictional data. Maintain an incident route for misdirected information or unauthorised access. A privacy review is incomplete if the team cannot operate the agreed controls during ordinary work or supplier exit.
Worked example
A demo account offers a delete button but leaves data in exported evaluation files. The buyer asks for an end-to-end deletion procedure and tests it with synthetic records before approval.
Put it into practice
Write six supplier questions and a fictional deletion test with expected results.
Use fictional information and keep your work in your own notes.
Compare your approach: self-review guidance
Include secondary copies, subprocessors, access, training use, retention and exit. Record what is evidenced versus merely asserted by the supplier and route unresolved issues to the accountable owner.
Sources and further reading
Original Academy teaching and fictional examples. These references provide context, not endorsement. Edition 2026.09; updated 2026-09-24.
- ICO: Recruitment and selection
UK guidance. Check its current status and updates before implementation.
- GOV.UK: Responsible AI in recruitment
UK guidance on procuring and deploying recruitment AI.