← Dealer AI insights
  • Data & Governance
  • Dealer AI vendors
  • Vendor due diligence
  • DMS and CRM security

Dealer AI Vendor Scorecard: 25 Questions Before DMS or CRM Access

A practical dealership AI vendor scorecard covering outcomes, DMS and CRM access, data use, security, human control, integration, measurement, and exit terms.

Direct answer

What dealership leaders need to know

Before an AI vendor receives dealership DMS, CRM, call, inventory, or customer-data access, require clear answers on the exact outcome, minimum data needed, write permissions, model and subprocessor use, human approval, testing, logs, incident handling, measurement, and data return or deletion.
  • Score the deployed workflow and its permissions, not the quality of the sales demo.
  • A vendor should explain every system read, write, retention period, human handoff, and stop control.
  • Do not move to production until success, failure, security, ownership, and exit conditions are written down.

A dealership AI vendor scorecard is a repeatable way to compare what a product will do inside the store, which data and systems it will touch, how people retain control, and whether the economics survive implementation. It keeps a polished demonstration from becoming the decision standard.

This scorecard is operational guidance, not legal advice or a substitute for the dealership’s qualified security, privacy, compliance, procurement, or legal review. The questions should be answered for the product configuration the dealership will actually deploy—not for the vendor’s company in general.

How to use the scorecard

Bring the operating owner, technical or security owner, and executive sponsor into the same review. Score each question from 0 to 2:

  • 0 — unanswered: the response is missing, generic, or deferred until after signature;
  • 1 — partial: the answer is specific but lacks evidence, ownership, or contract support;
  • 2 — operational: the answer is specific to the deployment and supported by a demonstration, document, control, or contract term.

Do not treat the total as an automatic buying decision. A zero on customer-data use, access revocation, incident notification, high-consequence approvals, or data deletion can be a stop condition even when the overall score looks strong.

Outcome and operating fit

1. Which dealership constraint does the product solve?

Require a sentence that names the team, workflow, and consequence. “Improve engagement” is not enough. “Recover declined service work that receives no follow-up within one business day” can be baselined and tested.

2. Which result should move in 30, 60, and 90 days?

Separate an operating result—appointment show rate, recovered repair orders, lead response time, productive hours—from product activity such as messages sent or records summarized.

3. What work remains for dealership employees?

Document review queues, exceptions, customer escalations, knowledge maintenance, reporting, and quality checks. Automation can move work to managers instead of removing it.

4. Show three failure paths, not only the successful path

Use a stale record, conflicting customer information, an unsupported request, or an upset customer. Watch how the system expresses uncertainty, refuses, and hands off context.

5. What would make the vendor recommend no deployment?

A credible answer should identify data, integration, volume, process, risk, or ownership conditions under which the tool will not work well.

Data, DMS, CRM, and integration

6. Which systems and fields does the product read?

List each DMS, CRM, scheduler, call platform, inventory feed, website, document source, and field. “DMS integration” is not a data map.

7. Which systems and fields can it write or change?

Identify message sends, appointment changes, notes, prices, statuses, record merges, task creation, and configuration changes. Begin in read-only or recommendation mode where practical.

8. What is the minimum access needed?

Ask whether access can be restricted by store, department, role, field, action, and time. The AI should not inherit broad employee permissions just because that is easier to integrate.

9. How fresh is each source, and what happens when sources disagree?

The vendor should expose synchronization timing, source priority, stale-data behavior, and the owner responsible for correction. Cox Automotive’s discussion of AI discovery, data, and decisions emphasizes data quality and system connectivity as foundations for useful dealership AI.

10. Can the dealership revoke access immediately?

Confirm who can disable the integration, invalidate tokens, stop automated actions, and restore the previous workflow without waiting for vendor support.

Model, privacy, and security

11. Which companies process dealership data?

Name the application provider, model provider, hosting platform, speech or transcription service, analytics tools, integration providers, human reviewers, and material subprocessors.

12. Is dealership data used to train or improve any model?

Ask separately about prompts, files, customer records, audio, transcripts, corrections, ratings, outputs, and usage telemetry. Require the answer and available controls in writing.

13. What is retained, where, and for how long?

Cover production data, backups, logs, support copies, model inputs and outputs, and derived data. Establish deletion timing and evidence.

14. How are authentication, authorization, encryption, and administrative access handled?

Request product-specific evidence. The FTC’s automobile dealer Safeguards Rule FAQs describe access controls, encryption, multifactor authentication, monitoring, personnel training, service-provider oversight, and incident response among the elements relevant to covered dealers.

15. How are service providers assessed and contractually controlled?

The FTC says covered financial institutions should take reasonable steps to select capable service providers, require safeguards by contract, and periodically assess providers based on risk and continued adequacy. Ask who performs that work across the AI delivery chain.

16. What is the incident-notification process?

Record the notification clock, contact path, information provided, preservation of evidence, remediation responsibility, and support for the dealership’s own obligations.

17. How does the system resist prompt injection and untrusted content?

Test direct malicious prompts and instructions hidden in webpages, documents, emails, CRM notes, and retrieved content. The NIST Generative AI Profile is a useful reference for generative-AI risks and lifecycle controls.

Human control, testing, and evidence

18. Which actions always require human approval?

Set thresholds for customer-specific price or finance representations, safety or recall statements, record deletion, permission changes, sensitive communications, employment decisions, and code running against production.

19. What does the reviewer see before approving?

The person should see the source facts, proposed action, uncertainty or exception, and ability to edit or reject. A context-free approval button is weak control.

20. How are decisions and actions logged?

Logs should reconstruct who or what initiated the action, data used, output produced, approval or override, downstream change, and time. Establish dealership access and retention.

21. How will the dealership test before launch?

Require a sandbox or controlled pilot with normal cases, edge cases, hostile inputs, unavailable integrations, authorization changes, human handoffs, and rollback.

22. Who owns model or workflow changes after launch?

Ask how the vendor communicates model, prompt, integration, feature, subprocessor, and policy changes that could alter behavior or risk.

Economics, ownership, and exit

23. What is the full cost to operate the workflow?

Include subscription, setup, integration, data cleanup, training, monitoring, exception handling, management time, support, and switching cost. Use the dealership AI ROI calculator with a documented baseline.

24. Who owns the outcome inside the dealership?

Name an operating owner, technical owner, and executive sponsor. NIST’s AI Risk Management Framework organizes work around govern, map, measure, and manage, with documented roles and ongoing review—not a one-time approval.

25. How do we leave?

Write down data export format, configuration and log access, deletion, credential revocation, transition support, contract termination, and the manual fallback. Test the stop path before production.

A practical decision rule

A strong vendor is not one that answers “yes” 25 times. It is one that can make the workflow, boundaries, evidence, and tradeoffs inspectable. The dealership should be able to say:

  1. which constraint is being solved;
  2. which systems and data are involved;
  3. which actions are permitted and approved;
  4. how success and harm are measured;
  5. who owns the system; and
  6. how the store can stop, recover, or leave.

If those six statements are still vague, the decision is not ready for production access.

Sources and scope

This scorecard synthesizes dealership operating questions with the FTC’s automobile-dealer Safeguards Rule guidance and NIST’s voluntary AI risk-management resources. Requirements vary by dealership, jurisdiction, data, workflow, and relationship. Verify applicable obligations with qualified advisers.

Continue the evaluation: Pair this scorecard with the dealership AI security checklist, the data-readiness framework, and the AI operator decision framework.

Continue the operator briefing

Top