page

How to evaluate an AI-native service provider: a checklist

Sixteen things to check before you hire a company that delivers outcomes with AI: delivery capabilities, commitments, evidence of results, and the questions a sales call will not answer. The same checklist Toolsfine uses for every company profile.

An AI-native service provider sells you an outcome — resolved tickets, signed-off documents, qualified leads — produced mostly by AI and reviewed by people. Evaluating one is not a technology question. It is a question of what they will actually deliver, what they commit to in writing, who is responsible when it goes wrong, and what evidence exists that it has worked for anyone else. This checklist covers those four areas in sixteen items, each of which can be checked against the company's own public pages before you ever speak to sales.

Toolsfine uses exactly this list to build every company profile in our AI-Native Services section. Each item is recorded as one of three states — confirmed, not stated, or explicitly absent — with a link to the source and the date we checked. We publish the method so that you can check our work, and so that you can do the same check on a company we have not listed yet.

Why "not stated" is not the same as "no"

Before the list: one rule that changes how you read everything else.

When a company's website does not mention something — an SLA, a data-training policy, who signs off on the work — that is a gap in their public statements, not evidence that the thing does not exist. Plenty of good providers have thin websites. Plenty of weak ones have thorough ones. So the checklist does not score companies by how many boxes they tick. It tells you which questions you still have to ask, and it flags the one case that should actually worry you: when a company explicitly says it does not do something that matters to you.

Three states, then:

State Meaning What to do
Confirmed The company states it publicly, and we found the page Verify it survives into the contract
Not stated We found no public statement either way Ask. Write the answer into the contract
Absent The company publicly says it does not offer this Decide whether it matters for your case

Part 1 — Delivery capabilities (what they actually do)

These seven items describe the shape of the service. They determine whether you are buying an outcome or buying software with extra steps.

  1. End-to-end delivery. Do they run the whole process, or do they hand you a tool and a dashboard? If your team still has to operate something, you are on the tool route, not the service route, and should price it that way.
  2. Human review included. Is a person checking the AI's output before it reaches you, and is that review part of the standard service or a paid add-on? "AI-powered with human oversight" on a homepage can mean anything from every item to a monthly sample.
  3. Signed off by licensed professionals. For regulated work — clinical notes, tax filings, legal documents, financial advice — is a licensed CPA, attorney, physician or equivalent putting their name on the output? If not, the regulatory responsibility stays with you.
  4. Works inside your existing systems. Can they deliver into the tools you already run (your CRM, EHR, ticketing system, accounting software), or do you have to adopt theirs? Most onboarding delays we hear about are integration delays.
  5. Private or on-prem deployment available. If your data cannot leave your environment, is there a deployment option that respects that, and at what price? Many providers quietly exclude this from standard tiers.
  6. API or data export. Can you get your data, and their outputs, out in a usable format at any time? If the answer is no, every future price increase is one you have to accept.
  7. Multilingual delivery. If you operate in more than one language, is that a supported mode or a "contact us" footnote?

Part 2 — Commitments (what they put in writing)

These nine items are what separates a provider from a vendor. Each one is cheap to claim and expensive to honor, which is why the public statement matters.

  1. Public delivery SLA. Is there a stated turnaround, accuracy or availability target that anyone can read, or does it exist only in sales decks? A public SLA is a commitment the company has to keep for everyone; a private one is whatever you negotiated.
  2. Outcome-based pricing. Is at least part of the price tied to the result you care about — resolutions, signed documents, booked meetings — rather than to inputs you cannot control? Outcome pricing aligns incentives; per-seat pricing for a service you do not operate is a warning sign.
  3. Refund or satisfaction guarantee. Is there a stated remedy when the service fails to deliver? The existence of a guarantee matters less than its definition: what counts as failure, who decides, and how fast.
  4. Customer data not used for training. Do they state, in a privacy policy or terms page, that your data is not used to train their models or anyone else's? If this is not stated, assume the opposite until the contract says otherwise.
  5. SOC 2. 13. ISO 27001. 14. HIPAA. 15. GDPR. Four separate checks, because they are four separate things. A SOC 2 report is an audit of controls; ISO 27001 is a management-system certification; HIPAA compliance is a legal posture for US health data; GDPR applies if you have EU data subjects. "Enterprise-grade security" is a phrase; a certificate with a date and an auditor is a status. Look for the trust page, the certificate date and the auditor's name. Treat a claim with no document behind it as "not stated".
  6. Named party responsible for outcomes. Somewhere in the terms, does a legal entity accept responsibility for the delivered work? This is the single most important line in any service contract, and it is the one most often missing from the website. If it is absent publicly, it is the first thing to settle before signing.

Part 3 — Evidence (whether it has worked for anyone)

Capabilities and commitments are promises. Evidence is the past. We grade it on three levels, and we recommend you do the same.

Grade What exists How much weight to give it
A Third-party verifiable results: named customers who will speak, published case studies with numbers, independent audits, regulatory filings High. Verify one reference yourself
B Results reported by the company or its investors: metrics on the website, press releases, funding announcements that cite traction Moderate. Ask how the number was measured
C No publicly verifiable outcomes yet: demos, roadmaps, "trusted by" logo walls without named results Low. You would be an early customer; price that in

Early-stage providers are often grade C and still worth hiring — but you should know that you are the evidence, and negotiate accordingly: pilot pricing, shorter terms, an exit clause.

What we found in the first 50 profiles

Numbers from the first 50 companies we checked, so you know what "normal" looks like before you judge any one provider:

Item Confirmed Not stated Absent
End-to-end delivery 40 10 0
Human review included 35 15 0
Signed off by licensed professionals 8 42 0
Public delivery SLA 5 45 0
Outcome-based pricing 7 40 3
Refund / satisfaction guarantee 10 37 3
Customer data not used for training 10 38 2
SOC 2 11 39 0
HIPAA 10 39 1
Named party responsible for outcomes 1 49 0

Two things stand out. Almost everyone states what they deliver; almost no one states what they commit to. And the item that matters most in a dispute — a named party responsible for the outcome — was public for one company in fifty. That is not a reason to distrust the other forty-nine. It is the reason the contract conversation exists.

Part 4 — Questions a website will not answer

Once the public checks are done, the remaining questions go to the sales call. Keep them short and keep the answers in writing.

  • Who, by name and role, reviews the AI's output for our account, and what fraction of items do they see?
  • What happens when the AI is not confident — does the item wait for a human, get returned to us, or go out anyway?
  • Show us the last incident: what went wrong, how you found out, what you told the customer.
  • If we leave, what do we get, in what format, how fast, and what does it cost?
  • Which of your public commitments are in the contract, verbatim?

A provider that answers these quickly and specifically has usually been asked before. One that redirects to the product demo has not.

How to use the checklist

Do the sixteen public checks first; they take about an hour per company and need no one's permission. Mark each item confirmed, not stated or absent. Everything "not stated" becomes a question for the call. Everything "absent" becomes a decision for you. Then weigh the evidence grade against how much you are exposing: a grade-C provider for a low-stakes back-office task is reasonable; a grade-C provider for work that reaches your customers or your regulator is a bet.

The checklist does not tell you whom to hire. It tells you what you know, what you still have to find out, and where the risk sits. That is usually enough.

How Toolsfine uses this

Every profile under AI-Native Services on Toolsfine shows the sixteen items above as two tables — capabilities and commitments — with each row marked confirmed, not stated or absent, linked to the source page and dated. Evidence is graded A, B or C with a one-line reason. Companies can claim their profile and ask us to correct a fact against a public source; a claim never changes what we publish until the source checks out, and paid plans never change what we report.

Related guides

Koyama, Operation Master of Toolsfine.com