A business buying or licensing someone else's AI tool almost never gets to see what it was trained on. That changes what “checking for bias” actually has to look like.
Short answer
You mostly can't check the training data directly, because you almost never have access to it. What you can do is test the outputs: run the same kind of request through the tool with different inputs — different names, different demographic details, different phrasings of an otherwise identical case — and see whether the results change in a way that has no legitimate reason to. And a clean result on one test doesn't mean the system is fair overall.
Canada’s Cyber Centre names the mechanism plainly — “generated content may be prejudiced if the training dataset lacks balanced representation of data points” (Cyber Centre, Generative artificial intelligence, ITSAP.00.041). That’s the developer’s problem to prevent, not something a business licensing a finished model can audit after the fact. Canada’s privacy commissioners put the actual duty on the party that can see the data: the duty, as stated, is to evaluate “the training data sets to ensure that they do not replicate, entrench, or amplify historical or present biases – or introduce new biases” before the tool ever reaches a customer (OPC, generative-AI principles). A business adopting the tool is generally left asking the vendor whether that evaluation happened, not doing it themselves.
Practically, that means checking a tool for bias looks less like a compliance audit and more like structured testing: hold the substance of a request constant and vary only the detail that shouldn't matter — a name that reads as more or less common in a particular community, a postal code, a phrasing associated with a particular group — and compare what comes back. A consistent, unexplained difference across otherwise identical inputs is the actual signal, not a single flagged output.
A widely cited framework, the U.S. National Institute of Standards and Technology’s AI Risk Management Framework — cited here for its structure, as a United States framework, alongside the Canadian sources above, not as Canadian authority — states the limit of any single test bluntly: “Systems in which harmful biases are mitigated are not necessarily fair.” A system can clear a demographic-balance check and still be inaccessible to people with disabilities, or produce fine average results while failing badly for a group too small to move the average (NIST AI RMF, AI Risks and Trustworthiness — U.S. framework). The full breakdown of where bias actually originates — not just how to test for it — is covered at how bias gets into an AI system.
Nobody adopting an off-the-shelf tool is going to run a research-grade fairness audit. What's realistic is picking a handful of the decisions the tool actually influences, testing each with a small set of deliberately varied inputs before relying on it, and repeating that check periodically rather than once — because a model can behave differently after a vendor update than it did at launch.
Whether a target business ever tested its AI tools for this kind of skew, and what it found, is a real diligence question with real downside if the answer is “we never checked.”