Key Takeaways:
- AI Agents are becoming a criterion in vendor due diligence: Professional service firms must demonstrate how client data is processed, stored, and protected when applying AI.
- Data control must start at the infrastructure level: Clearly defining where data is processed and stored, legal jurisdiction, Zero-data retention mechanisms, and encryption key control are crucial factors to evaluate before deploying an AI Agent.
- Data security must be maintained throughout operations: Access control, data isolation between clients, and unauthorized query restriction help mitigate data leakage risks in AI systems.
In professional service sectors such as strategy consulting, independent auditing, and legal counsel, AI Agents are rapidly transitioning from experimental tools to core operational assistants. The ability to review thousands of M&A contract pages in minutes, cross-reference tax regulations across multiple periods, or automatically synthesize in-depth due diligence dossiers helps firms optimize thousands of working hours for their expert teams.
However, the superior analytical capability of AI Agents simultaneously creates a strategic bottleneck: information security risks. AI Agents processing client data which inherently contains trade secrets, undisclosed financial reports, and sensitive personal data requires a stringent infrastructure and legal control mechanism. Without an appropriate architectural blueprint, feeding client documents into AI models can lead to information leaks, Non-Disclosure Agreement (NDA) violations, and severe damage to the firm's reputation.
This article analyzes the core risks and suggests a B2B client data security control framework for the Executive Board and IT Management departments at consulting, audit, and law firms.
1. AI is becoming a criterion in professional service vendor due diligence
During vendor assessments or Request for Proposal (RFP) bidding, multinational corporations and large financial institutions have begun adding specialized checklists regarding AI application. Enterprise clients no longer just ask about the professional competence of the partner's team; they directly demand clarification on the data processing methods of the technological tools the firm uses.
Common due diligence questions include:
Does the company use Generative AI or AI Agent tools to process documents provided by the client?
Is the data in prompts and attached documents stored or used by the AI solution provider to train public models?
Where are the computing infrastructure and logging databases of the AI Agent located, and under which legal jurisdiction?
This reality forces consulting, auditing, and law firms to proactively standardize their AI architecture. Failing to demonstrate a transparent enterprise client data security mechanism can lead to the risk of being disqualified from the appraisal rounds of major clients.
2. Data Characteristics of the Professional Services Sector: High Sensitivity and Independent Confidentiality Obligations
Unlike the retail or consumer services sector, which processes millions of basic personal data records, the professional services block possesses datasets with distinct characteristics:
Extremely high sensitivity: Audit documents, litigation files, M&A transaction structures, or tax optimization plans may contain information that directly impacts enterprise valuation, financial transactions, or legal risks.
Per-contract confidentiality obligations: Each client has specific confidentiality clauses. Client A's data must not only be protected from external attacks but also fully isolated from Client B's data right within the internal system.
Industry-specific legal confidentiality obligations: Besides general regulations on personal data protection (Law No. 91/2025/QH15 and Decree 356/2025/ND-CP), firms are also governed by the Law on Lawyers and the Law on Independent Audit, which carry strict penalties regarding the obligation to maintain information secrecy.
3. Infrastructure requirements to verify before feeding customer data into AI
Before integrating AI Agents into document processing workflows, businesses must require providers to clarify the entire data lifecycle:
- Will the data be used for model training? Require the AI provider to confirm in writing that the data submitted by the company will not be retained or used to train public models; the standard contractual term to look for is "Zero-data retention".
- Clearly verify the data journey into the AI. Not only must the data storage location be verified, but businesses also need to clarify where components related to processing, management systems, databases, and backups are deployed. Specifically, it must be determined whether these components are operated on infrastructure outside of Vietnam and if the data undergoes cross-border processing.
- How is the data deleted upon contract termination? Require the provider to contractually commit to the ability to delete all data related to a project including backups immediately upon the termination of the service contract.
To better understand how to tier and manage AI technical layers, businesses can refer to the article on the Enterprise AI Stack Management and Tiering Framework.
4. 2 Infrastructure Criteria to Evaluate: Jurisdiction and Data Control
Beyond how data is processed and stored, businesses must evaluate two factors that directly impact data control capabilities: jurisdiction and encryption key control.
4.1. Whose jurisdiction does the data fall under?
Business Risk: Using AI services with servers located abroad easily exposes the company to risks of violating regulations on cross-border data transfer (Decree 356/2025/ND-CP).
Executive Board Requirement: Prioritize domestic Cloud infrastructure providers with legal entities in Vietnam. This ensures that in the event of a security incident or compliance audit, all data and processing workflows fall entirely under the protection of Vietnamese law, helping the company maintain a solid legal upper hand.
4.2. Who controls the encryption keys?
Business Risk: Migrating data to the Cloud while the provider holds the decryption keys means the security perimeter can be breached from the partner's end.
Executive Board Requirement: Mandate the implementation of a Customer-Managed Encryption Keys (CMEK) mechanism. This principle is akin to a company renting a safe deposit box at a bank (renting the Cloud), but keeping the only key themselves. This way, even the Cloud provider's engineering team is absolutely unable to intervene or read the contents of the client's documents.
Businesses can review a detailed set of Cloud infrastructure evaluation criteria in the Cloud Sovereign Checklist for Enterprises.
5. Access Control and Conflict of Interest Management in AI Systems
In consulting and legal operations, conflicts of interest pose a strategic risk. If two teams within the same consulting firm are advising opposing parties in a takeover or litigation, an absolute information wall must be established.
When deploying AI Agents as Retrieval-Augmented Generation (RAG) systems, "context leakage" can occur if access control mechanisms are not strictly configured. The AI Agent might accidentally extract information from Project A's documents to respond to a specialist working on Project B.
The core solution is to implement a multi-tier authorization model:
- Role-Based and Attribute-Based Access Control (RBAC/ABAC): It is mandatory that every document fed into the AI is tagged with its respective project and the required clearance level to view it. The AI will only retrieve data corresponding to the specific project assigned to the inquiring personnel.
- Data Space Isolation (Tenant Isolation): The AI system's storage space must be partitioned like separate safes rather than a shared warehouse. The AI is only granted permission to open the safe corresponding to the operating user's authorization.
- Out-of-Bounds Query Control: The system must automatically reject, block, and log alerts if a prompt shows signs of probing or requests information extraction outside the scope of the assigned project.
6. GreenNode partners with NGSC to build flexible and compliant cloud infrastructure
Throughout its partnership with NGSC, GreenNode has deployed a comprehensive Cloud infrastructure ecosystem (including vServer, vStorage, and vMonitor), helping the enterprise solve the challenge of rapid system scaling. This platform not only meets the rigorous performance demands of a hybrid architecture but also places a strong emphasis on strict compliance with Decree 13/2023/ND-CP regarding domestic data localization for banking clients.
On this platform, NGSC has deployed core systems such as CRM and the Customer Center. Leveraging GreenNode's capabilities, the system scaled from 500 to 2,000 users in under 24 hours a process that would have previously taken weeks using traditional on-premise infrastructure. Currently, 100% of NGSC's solutions are deployed on GreenNode, optimizing operational costs with near-zero downtime.
Beyond providing robust infrastructure, the comprehensive deployment of cloud server solutions is also a strategic collaboration focus between GreenNode and NGSC to support banks in expanding their systems with full control over data, infrastructure, and workloads. In the future, NGSC expects GreenNode to continue expanding specialized products like eKYC and BShield for integration into its banking partner network.
Read the case study to learn how GreenNode partners with enterprises in deploying AI Cloud infrastructure while ensuring data sovereignty compliance.
7. The Compliance Portfolio Businesses Should Prepare for Appraisal
To proactively address information security audit requests from enterprise clients, consulting, auditing, and law firms should prepare an AI Compliance Portfolio consisting of 4 core documents:
| No | Required Document | Technical and Legal Content |
| 1 | Data Protection Impact Assessment (DPIA) | Detailed assessment template of the data processing flow when using AI Agents, identified risks, and corresponding mitigation measures. View the template here: Link |
| 2 | AI Data Processing Addendum (AI DPA) | A commitment ledger outlining data processing boundaries between the company and the Cloud infrastructure provider, confirming the Zero-data retention mechanism. View the template here: Link |
| 3 | Architecture Diagram & Security Whitepaper | Detailed description of the Tenant Isolation model, CMEK encryption mechanism, RBAC/ABAC authorization protocols, and the physical location of the Data Center. |
| 4 | Information Security Certifications | Copies of certificates proving the Cloud infrastructure's compliance with international and domestic standards (ISO 27001, SOC 2 Type II, ISO 27017/27018). |
By proactively building a secure AI Agent architecture and maintaining a transparent compliance portfolio, consulting, audit, and law firms not only optimize internal operational efficiency but also transform technology governance capabilities into a distinct competitive advantage to win over large enterprise clients.


