AI Governance Study

Managing third-party risk: policies, vendor screening, and evaluating the licensing agreement

Most organisations deploy AI they did not build, which turns AI governance into vendor governance: the risks arrive through a contract, and most of the available controls live in it.

Why this matters for the AIGP exam

Third-party scenarios ask what should have been checked before signing and what the contract should have said. The screening list and the licensing terms are the tested content.

The essentials

What the exam asks

Pick the missing screening step or contract term in a described purchase, and remember that deploying a third-party system never outsources the deployer's own obligations.

Going deeper

This page is the condensed version. The full topic — with the detail above expanded and practice questions attached — is in the app, inside Domain IV. Domain I, a quarter of the course, is free to try first.

Start studying free

Back to the AIGP study guide.

AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.