Skip to content
Cogio
Strategy· 10 min read· by Alexandre Sauvageau

How to choose an AI consulting firm: the 12 questions to ask before you sign

Twelve questions to put to any AI consulting firm before signing: hosting, milestones, Law 25, reversibility. With the red flag that goes with each one.

A handshake between two businesspeople
Photo: Bia Limova, Pexels

Jargon protects the seller, questions protect the buyer

The AI consulting market has the feel of a gold rush: demand is exploding, supply is following, and the shopfronts all look alike once you get past the website veneer. How do you tell the firm that will deliver from the one that will learn its trade at your expense? Not by comparing the logos in their decks: by asking precise questions and insisting on written answers. Here are twelve, grouped into four blocks: sovereignty and hosting, method and milestones, Law 25 compliance, contract and reversibility.

Let us be straight: Cogio is an AI consulting firm, and these twelve questions apply to us as much as to anyone. We are literally inviting you to put them to us. A serious firm answers in writing, without taking offence; a firm that bristles at them has just answered in its own way.

Sovereignty and hosting: where will your data live?

Question 1: where does our data physically sit, and does the model run on our premises or at a third party’s? The answer that reassures names a place: your building, an identified Quebec or Canadian data centre, a specific hosting contract. The red flag: “in the cloud, it is secure.” The cloud is a computer somewhere, and that somewhere determines which laws apply, starting with the US CLOUD Act.

Question 2: will our data be used to train or improve anything at all? The answer that reassures is a contractual no: your documents are used to answer your questions, nothing else, and it is written down. The red flag: a vendor who has to check their own subcontractor’s terms before answering. If they do not control their chain, neither do you.

Question 3: who, at your firm and at your subcontractors, can reach our data? The answer that reassures describes specific roles, logged access and a short list, ideally backed by practices verified by a third party. The red flag: no access log, or a subcontracting chain nobody can describe in full.

Method and milestones: how will you know it is moving?

Question 4: what is the first usable deliverable, and how soon? The answer that reassures describes a bounded pilot: a scope, named users, a date, a deliverable your people can actually try. The red flag: a full rollout sold as one block, with no intermediate stage where you can judge on the evidence.

Question 5: on what criteria will we jointly judge that it works? The answer that reassures sets acceptance criteria before starting, to be measured at your site: the share of answers judged usable, time saved on a specific task, real adoption by the teams. Our guide to measuring the return on an AI assistant shows what good indicators look like. The red flag: quantified gains promised before anyone has seen your data.

Question 6: what happens if the pilot does not deliver? The answer that reassures accepts that it might and plans for it: adjust the scope, change approach or stop cleanly, with the lessons documented. The red flag fits in one sentence: “it cannot fail.” Methodological honesty starts by admitting the opposite.

Law 25 compliance: who will sign the assessment?

Question 7: who runs the privacy impact assessment, and when? The answer that reassures puts the assessment before deployment, with a named owner on your side and documented support from the vendor. The red flag: it is presented as an optional formality, or worse, they do not recognize the term.

Question 8: how do you find and handle personal information in our documents? The answer that reassures describes a procedure: identification, redaction or exclusion before indexing, and written rules for what follows. The red flag: “the model is secure, it is not a problem.” System security and lawful processing are two different questions.

Question 9: what is your plan for a confidentiality incident? The answer that reassures exists on paper: a notification procedure, timelines, an incident register, roles on both sides, as Law 25 requires. The red flag: improvisation, or a stated conviction that an incident is impossible.

Contract and reversibility: can you leave without losing everything?

Question 10: who will own the code, the prompts, the configurations and the documentation you deliver? The answer that reassures: you, unambiguously, with sources handed over at each milestone. The red flag: intellectual property that stays with the vendor, alongside a licence to renew, which is rent in disguise.

Question 11: if we terminate the contract, how do we get everything back, and how fast? The answer that reassures describes an orderly exit: data in standard formats, indexes that can be rebuilt, up-to-date documentation, no exit penalty. The red flag: exit fees, proprietary formats, or a carefully maintained vagueness about what “everything” means.

Question 12: what is included in the price, what recurs, and what depends on a third party? The answer that reassures breaks it out: design, any licences, hosting, upkeep, and what will move if a third-party supplier changes its rates. The red flag: a lump sum with no breakdown, where the recurring costs appear after signature.

The 12 questions and their red flags, on one page

Keep this table to hand at the next meeting. Twelve questions, twelve flags: a serious vendor clears them all, ourselves included.

12

questions to ask, with written answers required, before any signature

4

blocks to cover: sovereignty, method, Law 25, reversibility

Summary: the question to ask and the red flag that goes with it
The questionThe red flag
1. Where does our data physically sit?A vague answer along the lines of “in the cloud, it is secure.”
2. Is our data used to train anything?The vendor has to check with their own subcontractor to answer.
3. Who can reach our data, at your firm and your subcontractors?No access log, and a subcontracting chain nobody can describe.
4. What is the first usable deliverable, and when?A full rollout sold as one block, with no pilot and no milestone.
5. On what criteria will we judge that it works?Quantified gains promised before anyone has seen your data.
6. What happens if the pilot does not deliver?“It cannot fail”: no serious firm says that.
7. Who runs the privacy impact assessment, and when?The assessment is presented as an optional formality.
8. How do you handle personal information?No procedure for identifying or redacting it before indexing.
9. What is your plan for a confidentiality incident?No written procedure, no notification timeline, no register.
10. Who will own the code, the prompts, the configurations?Ownership stays with the vendor, with a licence to renew.
11. How do we get everything back if we leave?Exit fees, or proprietary formats unreadable anywhere else.
12. What is included, recurring, or dependent on a third party?A lump sum with no breakdown and no detail on recurring costs.

Where to start

Before your next meeting with a firm, pick the four questions that touch your biggest worry (the data, the budget, compliance) and ask for written answers. Writing takes the shine off charisma: a beautiful presentation does not always survive a follow-up email. Add the other eight when you compare finalists, and be wary of any answer that changes between the meeting and the page.

At Cogio we built our offering to pass this test: custom agents hosted at the client’s site, ownership of the deliverables to the client, milestones where you can stop, and one rule that sums up how we work, AI prepares and people decide. Come and put the twelve questions to us, in writing if you prefer: it is the best way to compare firms, ours included.

Frequently asked questions

Can a small local firm compete with a large one?

Yes, if it answers the twelve questions well. Size guarantees processes, not the quality of the deliverable: what counts is control of the chain (hosting, subcontractors, method) and the ability to deliver a pilot your people actually use. A small team that answers in writing and without evasion beats a big name that routes your questions to its legal department.

Should we insist on certifications such as ISO 27001 or SOC 2?

It is an asset, not an absolute prerequisite. A certification attests to practices verified by a third party, which strengthens the answers on access and security. But it replaces neither contractual reversibility nor Law 25 compliance, which live in the contract and in the method. Ask for written answers first; certification corroborates them.

What if the vendor refuses to answer in writing?

Move on to the next one. All of these questions have factual answers: a hosting location, an ownership clause, an incident procedure. A refusal to write them down means the spoken answer would not survive the contract. That is precisely the information you were after, at the best possible price: free, and obtained before signing.

Is the cheapest vendor automatically suspect?

No, but price alone tells you nothing: the breakdown does the talking. A low price with fuzzy recurring costs often ends up dearer than an honest all-in price. Compare the offers on the same grid: what is included, what comes back every month, what depends on a third party, and what leaving costs. On an equal grid, cheapest wins.

Can we ask these questions after signing?

You can, but your leverage has evaporated. Intellectual property, reversibility and exit penalties are negotiated before signature; afterwards you depend on the vendor’s goodwill. If you are already committed, ask anyway: the answers will tell you what to renegotiate at renewal.

Does Cogio answer these twelve questions itself?

Yes, in writing, and it is an exercise we recommend putting every shortlisted vendor through, ourselves included. Our answers fit in a few lines: hosting at the client’s site, no data used to train anything, a pilot with acceptance criteria, a privacy impact assessment before deployment, ownership of the deliverables to the client, exit with no penalty.

This article is a plain-language summary, accurate as of the date shown. It is not legal advice: for your own situation, consult a legal adviser or contact the Commission d’accès à l’information.