Vendor diligence for document translation fails in a predictable way: buyers ask questions that can be answered with a badge. The questions worth asking force a scope statement instead — which standard covers which part of the work, which systems the security certificate actually names, what the contract says about retention and model training, who else touches the file, where processing happens, what "formatting preserved" is guaranteed to mean, and how you get your terminology back if you leave. Each has a specific good answer and a recognisable evasion, and the gap between them is usually visible in the first sentence.
This guide runs the questions in the order they matter, with the answer you want and the answer that should slow the process down.
Diligence Tests Whether the Vendor Can Be Specific
Before the individual questions, one framing that saves a great deal of time: you are not testing whether a control exists. You are testing whether the person answering knows how their own system works.
Substantive answers carry nouns and numbers — a standard's number, a region, a retention period in days, a file format, a named entity. Evasive answers carry adjectives. "Enterprise-grade", "military-grade", "fully compliant", "best in class" are all statements about how the vendor would like to be perceived, and none of them survives a follow-up question.
Two habits make the difference. Ask every question in a form that has a factual answer, not a yes. And ask where the answer lives: a claim in a sales deck, a claim on a help page and a clause in the agreement are three different objects, and only the third is enforceable when something goes wrong.
Standards Scope: Which Standard Covers Which Work
Start here, because this is where a confident-sounding answer is most often wrong. Translation standards are not interchangeable, and they do not all cover machine translation.
ISO 18587 is the standard for post-editing of machine translation output. It defines the process and the competences of the post-editor, and it is the relevant standard for essentially every AI-first translation workflow. ISO 17100 covers translation services delivered by human translators with a defined revision step — and it explicitly excludes the use of machine translation and its post-editing from its scope.
A good answer names the standard that matches the service you are buying, says which entity holds the certification and what it covers, and distinguishes conformity from certification without being pushed.
An evasive answer offers an ISO 17100 certificate as cover for a machine-translation workflow. That is a scope the standard expressly excludes, and claiming it signals either a misunderstanding of the certificate or a decision to market past it. Our guide to ISO certified translation services sets out which certificate applies to which workflow.
Security Certifications Live or Die on the Scope Statement
Every security certificate has a boundary, and the boundary is written down. ISO/IEC 27001 certifies an information security management system within a declared scope; a vendor can hold a genuine certificate whose scope covers corporate IT and the London office and says nothing about the translation platform you are buying.
So ask for the certificate, the Statement of Applicability and the scope statement, and read the scope for the name of the product. The same rule governs SOC 2: a Type II report covers a defined observation period and lists the systems in scope, a Type I is a point-in-time design opinion, and "SOC 2 compliant" with no report is a sentence. ISO/IEC 42001, the AI management system standard, is now appearing on the same questionnaires and takes the same treatment — scope first, badge second.
A good answer arrives as documents under NDA within days. An evasive answer is a logo wall and an offer to "share details later in the process."
Retention and Training Terms Belong in the Agreement
The retention question is not "do you delete files." It is "what does the executed agreement say about deletion, and does it match the marketing page." Those two documents disagree more often than not, and only one of them is enforceable.
Four commitments to look for in the DPA rather than the help centre: a stated retention period for the uploaded source and the translated output; an explicit term on whether submitted content is used to train, fine-tune or evaluate models, including any human review pathway; deletion on request, ideally callable through the API; and confirmation that deletion covers derived artefacts — extracted text, OCR output, caches, queue payloads — not just the original upload.
A good answer quotes the clause number. An evasive answer answers a narrower question than the one you asked, usually about encryption. What actually happens to a file across its lifecycle is worked through in what happens to your file after translation.
Sub-Processors and Data Residency, Named Rather Than Gestured At
Every translation service of scale has a chain behind it, and your document inherits the terms of each link. A vendor routing to an upstream model provider inherits that provider's retention and training posture whether or not the questionnaire mentions it.
Ask for the sub-processor list as a schedule to the DPA — with entity name, function, processing location and content exposure — plus a notification period before a new sub-processor starts processing. Ask for residency by region, including any failover region used during an incident, and ask which specific step runs where: ingestion, storage, extraction and inference can sit in four different places.
A good answer names entities and regions and offers the list under NDA if it is not public. An evasive answer declines on grounds of commercial confidentiality, which in practice tells you the vendor cannot support your own processor-disclosure obligations. The full mapping exercise is in sub-processor risk in translation pipelines.
Format Fidelity Is a Test, Not a Claim
"Formatting preserved" is the least examined claim in the category, and the easiest to verify rather than argue about.
Push the claim into specifics. Which file types round-trip natively rather than through a PDF conversion? What happens to automatic numbering, cross-reference fields, tables of contents, headers and footers, tracked changes and comments in a Word file? To named ranges, formulas and cell formatting in a spreadsheet? To slide masters, text boxes that overflow when German expands, and grouped objects in a deck? What happens when text expands by thirty per cent and the table cell does not?
A good answer distinguishes between file types and admits the hard cases — scanned PDFs, complex tables, right-to-left layouts. An evasive answer is "all formatting is preserved perfectly," which no one who has debugged a numbering field would say. Then stop asking and send three real documents: your ugliest contract, a live financial model, and a deck built by someone who used text boxes instead of layouts.
Exit, Portability and Ownership of Your Term Base
The question almost nobody asks in a first procurement round is how the relationship ends, and it is the one that determines switching cost three years later. Your term base and translation memory are your asset — they encode decisions made by your lawyers about your documents.
Ask four things. Who owns the term base and translation memory produced during the engagement, in writing. What export formats are available on demand — TBX under ISO 30042 for terminology and TMX or XLIFF for memory and bilingual files. Whether export is self-service or a support request. And whether export survives termination, including a defined window after the contract ends.
A good answer is "you own it, export it yourself, here is the format." An evasive answer describes the glossary as a feature of the platform rather than as your data. A resource you cannot export is a resource you cannot take to a second vendor, price against, or hand to an auditor.
Continuity, Support and the Questions About People
Two smaller items that surface real differences once the commercial terms are close.
Continuity: what is the uptime commitment, and the remedy if it is missed? What happens to a sudden 500-document batch on a Friday afternoon — dedicated capacity, or a longer queue? Which support tier includes an actual human, and what is the response time in hours when a job fails mid-deal?
People: who reviews content if human review is part of the service, under what confidentiality obligation, and in which country? For regulated material this is a scope question as much as a security one. Practitioners work through the same trade-offs in a thread on privacy-compliant translation software, where the vendors who answer quickly and concretely tend to be the ones running their own stack rather than reselling someone else's.
Turning the Answers Into a Decision
Score the answers, not the impressions. A three-way mark per question — answered with evidence, answered in prose, not answered — turns a stack of similar-looking vendors into a ranked list within an hour, and leaves a record of what you were told, worth keeping alongside your translation process documentation.
Weight the questions by your own exposure. A firm translating public filings can live with a vague sub-processor answer; one moving unannounced M&A material cannot. Everyone should care about the exit question, because its cost rises with every month you stay.
Run the list at Bluente too. Ask which standard we say covers which part of the work, ask what sits behind the enterprise security posture rather than accepting the phrase, ask how the API handles retention, and ask for your terminology back in TBX. The format question is the one not to ask at all — send the worst document you have and see what returns, across 120+ languages and 22+ file types.
Sources and Further Reading
ISO 17100 — translation services, which excludes machine translation post-editing from its scope
Data privacy compliant translation software, r/machinetranslation — buyers comparing what vendors will put in writing
Related Reading
Last reviewed 24 August 2026 by the Bluente document engineering team, who build and test the pipeline described here. We update these guides when the underlying standards, regulations or file formats change.
The cheapest diligence step is uploading one difficult document. Try BluTranslate free.