A Practical MCP Vendor Due Diligence Questionnaire for Advisory Firms
An MCP vendor due diligence questionnaire helps advisory firms assess security and compliance risks by providing a structured set of questions on identity management, data handling, and audit capabilities.
Adopting the Model Context Protocol (MCP) to connect AI assistants with live business data requires careful evaluation of third-party software vendors. For advisory firms handling confidential client information, a structured due diligence process is not just a best practice; it is a necessity for managing risk and meeting fiduciary responsibilities. This questionnaire provides a framework for assessing the security posture of an MCP server or connector provider before integrating it into your workflows.
The business problem: managing third-party risk with client data
As a private equity, M&A, or financial advisory firm, you are a custodian of highly sensitive client data. Introducing any new technology that accesses systems like an ERP, CRM, or virtual data room (VDR) creates a potential new vector for a data breach. A security vulnerability in a third-party MCP vendor's software could expose your client's confidential information, leading to significant financial, reputational, and legal damage.
A formal due diligence process using a standardized questionnaire accomplishes several goals. It forces a systematic review of a vendor's security controls, creates a documented record of your firm's diligence efforts for compliance and audits, and provides a basis for comparing multiple vendors. It helps ensure that any tool you adopt aligns with your firm's security policies and your clients' expectations for data protection.
Illustrative example: an M&A advisor vets an MCP connector
An M&A advisory firm wants to pilot an MCP connector that would allow its deal team's AI assistant to query documents inside a client's Intralinks VDR. The goal is to speed up due diligence by asking natural language questions about the deal data. Before proceeding, the firm's IT security lead uses the questionnaire below to evaluate the proposed MCP connector vendor.
They pay special attention to sections on Identity and Access Management, ensuring the connector can integrate with their firm's SSO to enforce the same permissions as the VDR itself. They confirm the connector operates in a strictly read-only mode and cannot modify or delete VDR documents. Finally, they review the vendor's audit logging capabilities to ensure a clear record of which user's AI assistant queried which information and when. Based on the vendor's satisfactory responses and a review of their SOC 2 Type II report, the firm approves a limited trial for a single deal.
Asset: MCP vendor due diligence questionnaire
Use this checklist as a starting point for your vendor conversations. Not all questions will apply to every vendor or deployment model (e.g., hosted vs. self-hosted). Add your own firm-specific and client-specific requirements.
Vendor and Service Overview
- What is the full legal name and address of the vendor company?
- What is the specific name of the MCP server/connector product or service being evaluated?
- Is the service a multi-tenant hosted platform, or is it single-tenant/self-hosted software?
- Provide contact information for your security and compliance teams.
Identity and Access Management
- How does the service authenticate users? Does it support SAML 2.0 or OIDC for Single Sign-On (SSO) with our identity provider (e.g., Azure AD, Okta)?
- How are user permissions and access roles managed? Can roles be mapped from our identity provider?
- Describe the process for provisioning and de-provisioning user access. How is access revoked for departing employees or when a project ends?
- Does the service support multi-factor authentication (MFA)? Is it enforced by default?
- How does the service ensure access is segregated between different clients in a multi-client advisory environment? (See our guide on multi-tenant security).
Data Handling and Hosting
- If hosted, in which geographic regions are your data centers located? Do you offer region-specific hosting?
- Is client data encrypted at rest and in transit? Specify the encryption standards used (e.g., AES-256, TLS 1.2+).
- Does your service store or cache any client data? If so, what data is stored, for how long, and for what purpose?
- What is your data retention policy for any cached data or logs? What is the process for data deletion upon contract termination?
- Who are your cloud sub-processors (e.g., AWS, Google Cloud, Azure)?
Security Features and Auditing
- Does the MCP service have capabilities to modify or write data back to the source system? Can these be disabled to enforce a read-only state?
- What level of audit logging is available? Do logs record the user identity, source IP, timestamp, action performed, and the target resource for every request?
- How can we access these audit logs? Are they available via an API or a management console?
- What is the retention period for audit logs?
- What measures are in place to protect against common web application vulnerabilities, such as prompt injection, insecure direct object references, and cross-site scripting (XSS)?
Incident Response and Business Continuity
- Do you have a documented security incident response plan? Can you provide a summary?
- What is your policy and process for notifying customers in the event of a security breach involving their data? What are the notification timelines?
- Do you have a documented disaster recovery and business continuity plan? Can you share key metrics like Recovery Time Objective (RTO) and Recovery Point Objective (RPO)?
- Have you conducted third-party penetration tests of your service? Can you share a summary or attestation letter?
Compliance and Certifications
- Does your organization maintain any security certifications, such as SOC 2 Type II, ISO 27001, or CSA STAR?
- If so, can you provide a copy of the relevant report or certificate for our review?
- How does your service help our firm comply with data privacy regulations like GDPR or CCPA?
Prerequisites and limitations
Prerequisites: To use this questionnaire effectively, your firm should have a designated security or IT lead to review vendor responses. This individual should be familiar with your firm's internal security policies, risk tolerance, and the specific compliance requirements of your clients.
Limitations: This questionnaire is a template and not a substitute for professional legal or security consultation. Vendor self-attestations should be verified with independent documentation (like a SOC 2 report) wherever possible. This process evaluates the security of the MCP vendor; it does not assess the functional performance of their product. Most importantly, this diligence process covers the use of MCP for access to data. It does not establish the right to sell, redistribute, or license client data for AI training. Data licensing rights are a completely separate legal and commercial matter requiring explicit authorization from the data owner.
Questions to ask your software provider or implementation team
Before you sign a contract, discuss these points with your internal team or implementation partner.
- How will this MCP server integrate with our existing identity provider (e.g., Azure AD, Okta)? What is the estimated effort?
- What is our firm's policy for connecting third-party tools to client systems like a QuickBooks or NetSuite instance?
- Who will be responsible for configuring and monitoring the audit logs from the MCP server?
- How will we configure the tool and our processes to ensure that access is segregated between different client engagements, preventing data cross-contamination?
- What is our standard operating procedure for revoking access for team members who leave the firm or when a client engagement ends?
Next step with SourceX
The process of vetting an MCP vendor forces a detailed look at a company's data governance, access controls, and record-keeping quality. As you perform this diligence for your clients or portfolio companies, you are also effectively assessing their readiness for other data opportunities.
Well-governed, high-quality operational data may be a valuable asset for external AI training. SourceX builds, contracts, and manages the supply and transaction layer for AI data, helping companies license their anonymized business records to AI labs and data buyers. Our partner program is designed for advisors who can make qualified, permissioned introductions to decision-makers at these companies.
Use our free, confidential Company Fit Checker tool to see if a client might qualify for data licensing. As a SourceX partner, you receive 25% of the platform fees SourceX collects, up to $100,000 per referred company, for successful introductions.
Related MCP guides
- MCP Security Checklist for CFO, M&A and PE Firms
- A Practical Guide to Multi-Client MCP Security
- MCP, SOC 2 and ISO 27001: Controls Buyers Will Ask About
- All MCP resources
Sources
- Intralinks confidential deal data (Current guide)
- OWASP MCP security cheat sheet (Current security guidance)
- Enterprise-managed authorization (June 18 2026)
Vendor capabilities change. Check current official documentation before relying on any product detail.
- Step 1Share your linkSend your personal link to a company you know.
- Step 2Company appliesThe company applies itself at /apply.
- Step 3Buyer selects and paysThe buyer selects and pays for the data and SourceX receives its fee.
- Step 4You get your rewardYour share of SourceX fees becomes payable.
Common questions
Who is responsible for security: the MCP server vendor or our firm?
It's a shared responsibility. The vendor is responsible for the security of their software and, if hosted, their infrastructure. Your firm is responsible for proper configuration, secure user access management, monitoring audit logs, and securing the underlying data systems you connect to the MCP server.
Can we use this questionnaire for both hosted and self-hosted MCP servers?
Yes. While some questions about physical data centers are specific to hosted solutions, the core principles of identity management, data handling, and software security apply to both deployment models. For self-hosted software, you will need to add questions about the security of the underlying infrastructure that your firm will be responsible for.
Does a vendor's SOC 2 compliance mean their MCP server is secure?
A SOC 2 report is a critical piece of evidence about a vendor's controls, but it is not a blanket guarantee of security. You must review the scope of the report to ensure it covers the specific service you are buying and assess the auditor's findings. It's one important input into your overall diligence process. Learn more about [MCP, SOC 2 and ISO 27001](/resources/mcp/mcp-soc-2-iso-27001).
How often should we review our MCP vendor's security?
An in-depth review should be conducted before signing an initial contract. Subsequently, you should plan for at least an annual review. A new review is also warranted whenever there is a significant change in the vendor's service, your usage patterns, a reported security incident, or a major shift in the threat landscape.
Related pages
- Read-Only vs. Write-Enabled MCP: A Security-First Approach to AI Data Access
- MCP Audit Logging for Client and Deal Data
- MCP Access Revocation: A Security Checklist for Offboarding
- A Practical Guide to Multi-Client MCP Security
- MCP Access vs. Data Licensing Rights: What Advisors Must Know
- Check Company Fit for Data Licensing
Free resources
- PDF bank statement to CSV converter — Turn Chase, Bank of America or Wells Fargo PDF statements into CSV, privately in your browser.
- Client data licensing eligibility checker — A transparent preliminary screen for one company.
- Enterprise value calculator — Enterprise value from equity value, debt and cash.
- All free tools · MCP resource center
By SourceX Partnerships Team · Published 2026-10-09 · Facts checked 2026-10-09 · Updated 2026-10-09
Know a US company with valuable proprietary data?
Become a referral partner from anywhere we support, get your link and introduce an owner or authorized decision-maker.
Refer a company →I own a business
Explore licensing your company's data to AI developers worldwide. Start a short assessment; no uploads needed.
Start an assessment