Procurement Questions to Ask an AI Writing Vendor: A Question Bank for Universities (2026)

<![CDATA[

Send these in writing, before the demonstration. A demonstration is designed to show you a product working; a written question set is designed to find out what you are actually buying, and the difference between the two answers is where institutional risk lives.

The questions are grouped by the committee that will eventually ask them, so the document can be split and circulated without rewriting.

How to use this

Three practical notes before the list.

Ask for written answers with a deadline. Two weeks is reasonable. A vendor that cannot produce a sub-processor list in a fortnight during a sales cycle will not produce one faster once you are a customer, and that is genuinely useful information.

Distinguish contractual commitments from statements of practice. For every answer that matters, ask the follow-up: “is that in the agreement, or is it current practice?” Current practice changes in a release note. This single follow-up is the highest-value habit in edtech procurement.

Record non-answers as answers. Keep the responses in the procurement file exactly as received. An evasive reply is evidence, and it is much easier to explain a decision two years later with the original wording in front of you.

Data ownership and use — the four that end evaluations

  1. Who owns content submitted by our students and staff? State it as it appears in the agreement.
  2. Is submitted content used to train or fine-tune any model — yours or a third party’s? Answer separately for each.
  3. If training is off by default, who can turn it on, and can an individual user override an institutional setting?
  4. Is the training position contractual, or a statement of current practice?

Those four resolve more evaluations than any feature comparison. An institution cannot responsibly route unpublished doctoral research through a platform whose training position is a webpage rather than a clause — a thesis in progress is unpublished intellectual property, sometimes with commercial or patent implications, and sometimes containing research participants’ data gathered under an ethics approval that named no commercial processor.

Data protection and security

  1. Who is controller and who is processor, for which processing operations?
  2. Provide the named sub-processor list, and the notice period before it changes.
  3. In which jurisdictions is data stored and processed, including under failover and disaster recovery?
  4. What is the retention period for submitted content, and what is deleted at termination?
  5. How do you support access, rectification and erasure requests, and within what timescale?
  6. Which security certifications do you hold, and when was the last independent penetration test?
  7. What is your incident notification timescale to us, and does it start at detection or at confirmation?
  8. Have you had a reportable data breach in the last 36 months? If so, describe it.
  9. Do you have a documented AI-specific risk assessment we may review?
  10. Will you complete our DPIA data-mapping template, or only your own?

Question 11 catches a common asymmetry: a notification clock that starts at “confirmation” can run for a long time before it starts. The sequence in which to run this workstream is set out in our guide to running a data protection review.

Procurement meeting between institution and vendor
Ask in writing first. The meeting is for the answers you did not understand.

Regulatory posture

  1. Which data protection regimes have you built to, and can you evidence it?
  2. For US institutions: how do your terms handle FERPA, given that in higher education the rights holder is the student?
  3. What is your position on the EU AI Act, including any classification you have assigned to your system?
  4. What documentation do you provide to help us meet our own obligations as a deployer, including staff AI literacy?
  5. How do you handle jurisdictional divergence for a multi-campus institution?

Question 18 is increasingly load-bearing for European institutions, because the AI literacy duty in Article 4 of Regulation (EU) 2024/1689 falls on deployers rather than on suppliers. A vendor that supplies training materials mapped to that duty saves you building them; one that has not considered the question is telling you how mature its institutional practice is.

Academic integrity posture

  1. What does your product do to prevent it being used to substitute for a student’s own work?
  2. Does the product generate disclosable process evidence — version history, drafting records — that an institution could rely on?
  3. Do you sell, in any part of your portfolio, tools intended to disguise machine-generated text?
  4. What claims do you make about detection accuracy, and what independent evidence supports them?
  5. How do your outputs interact with our existing similarity screening contract?

Question 22 should be asked of every supplier and answered across the whole catalogue rather than the tendered product. It is not a rhetorical trap: portfolios in this market genuinely contain products pointing in opposite directions, as we document in our review of what changed in integrity platforms this year.

Integration and operations

  1. Which SSO protocols do you support, and which identity providers are in production with comparable institutions?
  2. Which VLE or LMS integrations are generally available today, at which versions? Distinguish available from roadmap.
  3. What is a realistic implementation effort in institutional staff days, not vendor days?
  4. How are licences allocated and reclaimed as students enrol and graduate?
  5. What administrative reporting is available, and can we export it?
  6. What is your release cadence, and how much notice do we get of changes that affect users?

Question 30 has a specific history in this sector. When AI detection was switched on across a major platform, institutions reported receiving less than 24 hours’ notice and having no option to disable it. Ask for a notice commitment for feature changes that affect assessment, and ask for it in the contract.

Accessibility and inclusion

  1. Provide your current accessibility conformance statement and its date.
  2. What are the known exceptions, and what is the remediation timetable?
  3. Which assistive technologies have you tested with, and when?
  4. What evidence do you have about performance for users writing in a second language?

Question 34 matters more than it looks. Where products make judgements about writing, differential performance by language background is a documented risk in adjacent tooling, and an institution with an equality duty needs to have asked.

Commercial, support and exit

  1. What is the licensing model — per seat, per department, per institution — and how does it behave if enrolment falls?
  2. What are the price protection terms at renewal?
  3. What support is included, with what response targets, and in which time zones?
  4. What training is included for staff, and is it repeatable each year for new starters?
  5. On termination, in what formats can we export institutional and user data, and over what window?
  6. What happens to student accounts and their content when a student graduates?
  7. If you discontinue this product, what notice and transition support do we receive?

Question 41 stopped being hypothetical this year. At least one product in the standard comparison set for this category was withdrawn on a stated end date, so a written continuity answer belongs in the file rather than in the risk register as an unquantified entry.

Scoring the answers

Weight the sections against the problem you wrote down, not evenly. An institution buying to relieve a writing centre bottleneck should weight support, training and accessibility heavily; one buying to strengthen integrity casework should weight process evidence and the integrity posture section.

Then apply one rule that keeps the exercise honest: score what is contractual, and record separately what was merely stated. When two vendors score closely, the difference is almost always that one made commitments and the other made claims.

We are happy to answer this question set in writing for Tesify for Institutions before any call, including the training, sub-processor and exit questions. Request an institutional evaluation.

Frequently asked questions

Should we send all of these to every vendor?

Send the ownership, data protection and exit sections to everyone. The remainder can be scaled to the size of the contract.

What if a vendor answers verbally?

Ask them to confirm in writing and file the written version. Verbal assurances are not usable in a committee paper.

Which single question matters most?

Whether submitted content trains models, and whether that answer is contractual.

How long should we allow for responses?

Two weeks. Treat the response time itself as a data point about support quality.

Do we need a full tender?

That depends on your thresholds and rules. The question set is useful either way — for a tender it becomes the specification, and below threshold it becomes the due diligence record.

Can we reuse our standard IT questionnaire?

Use it as the base and add the model training, integrity posture and AI literacy sections, which standard questionnaires predate.

Should the academic side or procurement own this?

An academic owner should own the problem and the weighting; procurement should own the process.

How do we handle roadmap promises?

Score only what ships today. If a roadmap item is decisive, make it a contractual milestone with a remedy.

What if the vendor will not name sub-processors?

That is usually a stopping point for a data protection review, since you cannot assess a chain you cannot see.

Should we ask for references?

Yes, and ask for one institution that has been a customer for more than two years and one that has been through a renewal.

How does this fit with a pilot?

Shortlist on the written answers first, then pilot the leading candidate with pre-agreed criteria — see our guide to running a departmental pilot.

]]>

Bring Tesify to your institution

Scope a departmental pilot: one cohort, one term, and your own measures of what worked.

Request an evaluation We reply within 2 business days

Categories