The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training - Zian AI

The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training

The Voice-AI Vendor Security Questionnaire: 12 Questions About Recordings, PII and Model Training

Short answer: Before signing an AI voice or AI sales-agent vendor, get written answers to twelve questions: recording storage and location, retention and deletion, whether your conversations train anyone’s models, sub-processors, transcript PII redaction, encryption, access logs, breach commitments, cross-border transfer, the underlying model provider, private deployment, and deletion on termination. A vague answer to any of them is itself the finding.

Most questionnaires sent to AI voice vendors were written for SaaS that stores form submissions. They ask about SSO and uptime and miss what makes voice agents different: every call produces audio and a transcript, both dense with personal information, both liable to travel somewhere you did not expect. This is the buyer’s list, narrowed to recordings, PII and training data. The identity, uptime and third-party-attestation layer sits in our enterprise readiness checklist; the adversarial side is in prompt injection and autonomous sales agents.

The frameworks worth anchoring to

NIST. AI 600-1, released 26 July 2024 as a companion profile to the AI Risk Management Framework 1.0, names twelve risks unique to or exacerbated by generative AI. Two are yours to procure against: risk 4, “Data Privacy”, defined as “Impacts due to leakage and unauthorized use, disclosure, or de-anonymization of biometric, health, location, or other personally identifiable information or sensitive data”, and risk 12, “Value Chain and Component Integration”.

ISO/IEC 27001 and 42001. 27001 is the information security management system standard; 42001 is the AI management system standard, which Standards Australia adopted as AS ISO/IEC 42001:2023 on 16 February 2024, describing it as covering internal governance and risk management. Neither certifies a product; both certify a management system within a declared scope, so ask for the scope statement.

Australian Privacy Act and GDPR. APP 11.2 requires reasonable steps to destroy or de-identify personal information once it is no longer needed; APP 8 matters more still (question 9). For EU contacts, GDPR Article 28(3) writes half this questionnaire for you: sub-processor conditions, audit rights, and deletion or return at the end of the service.

The twelve questions

1. Where are recordings stored, and in which country?

Why: audio is the highest-value artefact a voice agent produces, and the least often mapped.
Good answer: a named cloud region, per-tenant separation, an architecture diagram on request.
Red flag: “our infrastructure is global”, or no answer without checking.

2. What is the retention period, and can we set it?

Why: APP 11.2 puts the destruction obligation on you. If the platform cannot expire recordings, you cannot comply.
Good answer: a configurable per-workspace window covering audio, transcripts and derived metadata, backups included.
Red flag: “we keep everything so you always have history”, or retention that covers the recording but not the transcript.

3. Does our conversation data train your models, or anyone’s?

Why: the OAIC’s guidance on commercially available AI products (21 October 2024) warns that “Some commercial AI products will include terms or settings that allow the product owner to collect the data input by customers for further training and development of AI technologies.”
Good answer: no training by default, stated in the contract rather than a blog post.
Red flag: “aggregated and anonymised data to improve the service”, with neither word defined.

4. Who are your sub-processors, and how do we hear about changes?

Why: a voice agent is a chain: carrier, speech-to-text, LLM, text-to-speech, storage, analytics. This is NIST’s risk 12.
Good answer: a published sub-processor page, notice before additions, a right to object.
Red flag: a list that stops at “AWS”.

5. Is PII redacted in transcripts, and at what point?

Why: calls collect card numbers, dates of birth and health details, often unprompted. Redaction after storage is not redaction.
Good answer: configurable entity redaction applied before the transcript is persisted, plus audio suppression during payment capture.
Red flag: redaction that masks the UI while raw text stays in the database.

6. How is data encrypted in transit and at rest?

Why: table stakes, which is why a fuzzy answer here predicts fuzzy answers everywhere.
Good answer: named TLS versions on every leg including telephony, encryption at rest with a stated key-management approach, a straight answer on customer-managed keys.
Red flag: “bank-grade encryption”.

7. What access control and admin audit logging do we get?

Why: the realistic incident is an over-privileged internal account playing back recordings, not an outside attacker.
Good answer: role-based access down to playback, exportable immutable admin logs, a documented position on vendor staff access.
Red flag: support engineers with standing production access and no log you can read.

8. What will you commit to in writing on breach notification?

Why: under Australia’s Notifiable Data Breaches scheme, an entity must take all reasonable steps to assess a suspected eligible breach within 30 calendar days; GDPR Article 33 gives controllers 72 hours, and requires processors to tell controllers without undue delay. Neither clock survives a vendor who takes a fortnight.
Good answer: a contractual notification window measured in hours.
Red flag: notification “as required by applicable law”.

9. What is the cross-border transfer position?

Why: the one Australian buyers most often skip. APP 8.1 requires an entity, before disclosing personal information overseas, to “take such steps as are reasonable in the circumstances to ensure that the overseas recipient does not breach the APPs (other than APP 1) in relation to the information”. Section 16C then makes you accountable for that recipient’s acts as though they were your own: your vendor’s offshore processing becomes your breach.
Good answer: a leg-by-leg map of what leaves Australia, contractual APP flow-down, an onshore option.
Red flag: “the data stays in Australia” said about storage while inference runs offshore. More in AI agent data sovereignty in Australia.

10. Whose LLM is behind the agent?

Why: a vendor’s no-training promise is worth nothing if the model API underneath carries none. The majors publish theirs. OpenAI states “data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)”, with abuse-monitoring logs “retained for up to 30 days” by default. Anthropic states “By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models”.
Good answer: named providers, named regions, retention terms for each.
Red flag: “we use a proprietary model” as a way of not answering.

11. Can this run in our own environment?

Why: for regulated buyers this is sometimes the only configuration that survives internal review.
Good answer: a described topology, an honest account of which components cannot be self-hosted.
Red flag: “yes, on-premise” with no detail; it usually means a dedicated cloud tenancy, which is a different thing. See private AI deployment for sales agents.

12. What happens to everything on termination?

Why: GDPR Article 28(3)(g) requires processors to delete or return personal data at the end of the service. Ask for the same regardless.
Good answer: export in an open format, a stated deletion window covering backups, written confirmation.
Red flag: no export path, or deletion of the live database with backups quietly out of scope.

Scoring the five highest-stakes answers

Question Strong Acceptable Red flag
Training on your data Contractual “no training”, model-provider terms attached No training, in policy docs only Undefined “aggregated and anonymised” rights
Retention Configurable window across audio, transcripts, backups Fixed default, deletion on request Indefinite, or transcripts excluded
Cross-border transfer Leg-by-leg data map, APP flow-down, onshore option Offshore, documented, contractually covered Storage location cited, inference location dodged
Sub-processors Published list, advance notice, right to object List on request, notice by email No list, or “our cloud provider”
Breach notification Fixed hours in contract, named contact, tested runbook “Without undue delay” plus an escalation path “As required by applicable law”

Where Zian sits

Zian AI is at waitlist and partnership beta stage, and we hold no security certifications we could point you to. If your process requires a current ISO/IEC 27001 certificate before a pilot, we are not the right vendor today.

What is genuinely on the capability list is private model deployment on customer infrastructure, our honest answer to question 11. Put every other question here to us in writing exactly as you would to anyone else. A beta-stage supplier that answers crisply is telling you something real; one that deflects is telling you something too.

Frequently asked questions

Is ISO/IEC 42001 certification the same as saying an AI product is safe?

No. Standards Australia adopted AS ISO/IEC 42001:2023 on 16 February 2024, describing it as covering internal governance and risk management for organisations using AI. It certifies a management system within a declared scope, not the behaviour of a particular model or agent. Ask for the scope statement, not the badge.

If a vendor is offshore, are we still responsible under Australian law?

Largely yes. The OAIC’s guidance on APP 8 explains that section 16C of the Privacy Act makes an entity accountable for an overseas recipient’s acts in relation to disclosed personal information as though it had done them itself.

Do we need transcript redaction if we already restrict recording access?

Yes. Transcripts are what get indexed, searched, piped into analytics and fed back into prompts. Access control protects the audio; the personal information escapes as text. Redact before persistence, not at display time.

Where does this fit against a general AI risk framework?

NIST’s AI 600-1 Generative AI Profile (26 July 2024) recommends organisations “Update and integrate due diligence processes for GAI acquisition and procurement vendor assessments to include intellectual property, data privacy, security, and other risks” (action GV-6.1-009). This questionnaire is one concrete way to do that for the voice-agent category.

Apply For Partnership

Want to run these twelve questions past us directly? That is the conversation we want during beta. Apply For Partnership and bring your questionnaire with you.

Related Blogs

Related from Zian AI