How to Evaluate an AI Vendor in the Philippines: What to Ask Before Signing

The AI vendor market in 2026 has more players than any Philippine IT team can meaningfully evaluate. Every vendor claims to deliver AI-powered productivity, security, and efficiency. The differentiators are in the details — data handling commitments, reliability track records, integration depth, local support, and commercial terms that matter when something goes wrong.
This is the practical evaluation framework for Philippine businesses considering any AI tool, platform, or service — from Microsoft Copilot and Google Gemini to purpose-built AI applications.
1. Data Privacy and Processing
This is the most consequential question for Philippine businesses subject to RA 10173 (Data Privacy Act). You are the personal information controller for any client or employee data that your staff submit to an AI tool.
Questions to ask:
-
Does the vendor use your data to train their AI models? Enterprise plans from Microsoft and Google commit to not using customer data for training. Consumer-tier tools (ChatGPT Free, Claude.ai personal) may use inputs for training. Get this in writing.
-
Where is data processed? For Philippine businesses with sensitive data, processing in Singapore (Microsoft's and Google's Southeast Asia region) is acceptable for most use cases. Processing in regions outside ASEAN may trigger data transfer compliance issues under NPC guidance.
-
Who can access your data? Request the Data Processing Agreement (DPA) or Data Processing Addendum. Verify what personnel access controls exist, under what circumstances staff can access customer data, and what logging and audit trail is maintained.
-
What is the incident notification commitment? Under RA 10173, you must notify the NPC within 72 hours of a qualifying breach. Your AI vendor's notification timeline must be shorter than 72 hours to give you time to assess and report. Get the commitment in writing.
For cloud platforms like Azure and Google Cloud, this is covered in standard enterprise agreements. For SaaS AI tools, demand a DPA before any production deployment. See our AI data privacy guide and AI acceptable use policy guide for the governance framework.
2. Reliability and Performance
Questions to ask:
-
What is the documented SLA? For Philippine business-critical AI applications, 99.9% uptime (under 9 hours downtime per year) is the minimum acceptable. 99.95% (under 4.4 hours) for critical applications. Get the SLA and understand what credits apply for downtime.
-
What is the degradation behaviour? When the AI service is slow or degraded, does it fail gracefully or does your application break? Ask for the failure mode documentation.
-
What are the rate limits? Enterprise AI APIs have rate limits — requests per minute, tokens per day. If your application generates high query volume (customer service bot handling 10,000 queries/day), verify the rate limits match your requirements before signing.
-
What is the regional latency? For Philippine deployments, request latency data from Singapore-region endpoints. For real-time applications (voice AI, agent assist), latency above 500ms creates perceptible lag.
3. Integration Depth
Questions to ask:
-
What does native integration with our existing systems look like? An AI tool that claims to integrate with Microsoft 365 may integrate shallowly (reads emails only) or deeply (accesses SharePoint, Teams, Calendar, and Dynamics with user-level permissions). Get a demo of the specific integration, not just the marketing description.
-
Is there an API? For organisations that want to build custom workflows, verify the API's capabilities, rate limits, and pricing separately from the SaaS product.
-
What happens when our connected systems change? When Microsoft releases an M365 update that changes an API endpoint, who is responsible for maintaining the integration — the AI vendor or your IT team?
-
Can it handle Philippine-specific data formats? Philippine government IDs, BIR TINs, SSS numbers, PhilHealth numbers — does the AI tool handle these correctly, or does it require configuration? For Philippine compliance applications, test with actual Philippine data formats before committing.
4. Support and Implementation
Questions to ask:
-
Is there Philippine-based support? For business-critical AI deployments, support in the same timezone matters. A vendor with Singapore or Manila-based support is materially different from one where support is US-only (8–12 hour response lag during Philippine business hours).
-
What is the implementation support model? Does the vendor provide implementation support, or do you need a third-party partner? Who are the certified local partners? For Microsoft and Google products, Technica Solutions Inc. provides local implementation support.
-
What is the escalation path for outages? Get the escalation contact, the response time commitment, and the escalation criteria in writing before signing.
-
Is there training for staff? Enterprise AI tools require user training to realise value. Does the vendor provide training materials, or does this fall to you?
5. Commercial Terms
Questions to ask:
-
What is the per-user vs per-query pricing model? Some AI tools charge per user per month (Microsoft Copilot at USD $30/user/month). Others charge per query or per token (Azure OpenAI API). For high-volume applications, per-query pricing can be materially cheaper or more expensive than per-user — model this against your actual usage before deciding.
-
What happens to your data at contract end? If you stop using the service, how do you retrieve your data, and for how long is it retained after contract termination? Get the data portability and deletion commitments.
-
What are the auto-renewal and cancellation terms? Enterprise AI contracts increasingly include automatic renewal with 30–90 day cancellation notice requirements. Know the exit terms before committing.
-
Is the price stable? AI pricing has changed materially over 2023–2026. Request the price change notification commitment — how much advance notice do you get before a price increase?
The Philippine-Specific Due Diligence Checklist
Before signing any AI vendor contract in the Philippines:
- Data Processing Agreement or Addendum received and reviewed
- Confirmed data is not used for model training (for non-consumer plans)
- Data residency confirmed (Singapore SEA region for most Philippine use cases)
- Incident notification timeline committed in writing
- SLA with credit terms documented
- Rate limits confirmed against expected usage volume
- Integration tested with Philippine-specific data formats
- Local (Philippines or Singapore) support channel confirmed
- Cancellation terms and data portability confirmed
Related reading: AI data privacy guide · AI acceptable use policy · AI workflow automation for Philippine SMEs · Azure OpenAI vs Google Vertex
For Philippine organisations evaluating AI vendors and platforms, get in touch.
Talk to our Cloud & I.T. team →

