AI Governance Study

Managing third-party AI risk

Most organizations will buy far more AI than they build. The risk still lands on them, but the system that creates it belongs to someone else, and they cannot look inside it. The organization stays answerable for outcomes it cannot inspect, and has to build

Domain I · Establish policies and procedures to apply throughout the AI life cycle · about 8 min

Why this matters for the exam

Most organizations will buy far more AI than they build. The risk still lands on them, but the system that creates it belongs to someone else, and they cannot look inside it. The organization stays answerable for outcomes it cannot inspect, and has to build that answerability out of contracts and questions instead.

What you need to know

The last topic listed third-party risk as one input to a risk calculation. This one covers that input: where it reaches, what to ask before signing, and which contract terms decide what you can see afterward.

The core problem is visibility

Deployers and users of a third-party AI system usually do not have full visibility or control over it. A vendor's model can change under you, degrade over time, or have been trained on data you would never have approved, and none of it is visible from outside.

That gap creates a need for policies, assessments and contracts that are updated regularly and can adapt as the technology and the regulation move.

Where third-party risk reaches

A third-party AI policy has to cover four areas. Procurement is the one most organizations already have a process for, and the other three are usually gaps.

AreaWhat it has to cover
ProcurementScreening and vetting a vendor before signature, and the contract terms that follow.
Supply chainThe vendors behind your vendor. A supplier's model, training data or infrastructure may come from a fourth party you never assessed and cannot see.
Human resourcesAI used on your own people: hiring, promotion, performance and monitoring tools, which carry employment-law exposure on top of the usual risk.
Acceptable useWhat staff may and may not do with AI, including tools the organization never procured.

Acceptable use is the area with the most routine exposure. An AI acceptable use policy is the organization's own instrument governing how its employees behave. It is a different document from the vendor's acceptable-use policy, which governs how the product may be used. When an employee pastes confidential client text into a public generative AI tool, the acceptable use policy governs it most directly, reinforced by the confidentiality and security policies. No vendor contract covers employee conduct.

Due diligence continues after signature

Vetting a vendor before contract tells you what that vendor claimed at one moment. Ongoing monitoring through the life of the relationship tells you what it is actually delivering. A pre-signing questionnaire on its own does not satisfy third-party risk management, however thorough it was.

Both should be calibrated to the risk level the organization has assigned that system, rather than applied uniformly. In practice the work is:

Vendor certification is easy to over-read. A vendor holding an ISO/IEC 42001 certification has had its management system audited by an accredited third party. The buyer still has to assess the tool in its own context, for its own use case, and the certificate does not discharge the buyer's obligations.

Audit rights and exit terms

The contract is where most of that visibility is secured. Two clause types do different jobs.

ClauseWhat it gets youWhen it operates
Audit and information rightsThe vendor's performance data, or the right to commission an independent review, even over the vendor's trade-secret objections.Throughout the relationship.
Exit and portability termsData return, transition assistance, and protection against lock-in.Only on leaving.

Audit and information rights prevent a specific impasse: the customer suspects a vendor's model has degraded, and the vendor refuses to show any performance data. They have to be negotiated before signing, because once a dispute has begun the vendor has no reason to grant them.

A third term belongs alongside them. A breach and incident notification clause with a defined notice deadline obliges the vendor to report a problem within a stated number of days, and to help investigate and remediate it. Without a deadline in the contract, a customer can learn about a vendor-side incident long after it needed to act.

Diligence proportionate to risk

Governance resources are finite, so the depth of due diligence should be proportionate to the risk a use case creates rather than uniform across every tool an organization evaluates.

The system's legal effect on people sets the depth. Take a résumé-screening tool. It shapes who gets access to employment, which nondiscrimination law regulates closely: the EU AI Act classifies AI used in employment and worker management as high-risk under Annex III. It warrants the most rigorous diligence in a procurement portfolio even if it is one of the cheapest tools in it. A high-spend internal system that affects no one directly may warrant much less.

Proportionality governs how deep the diligence goes. Trustworthy-AI principles such as fairness still apply to every system.

Worked example

Acme, an insurance company, runs its AI program on the NIST AI RMF and an insurance-sector set of AI principles. Acme's policy requires supporting documentation whenever it buys a product with AI in it.

Alecia, Acme's assistant chief AI officer, is asked to fast-track the purchase of a third-party platform called Diaspro. She requests documentation of Diaspro's model development and fine-tuning practices. Diaspro will not provide it. Instead it offers contract warranties, indemnification, and last year's third-party audit results, while withholding the underlying audit work papers as confidential. Alecia does not believe any regulation specifically requires Diaspro to hand over what she asked for. Her question is whether what is on offer is sufficient for Acme.

This is not Alecia's call to make alone. Acme's own AI governance policy should already say who has authority to accept a documentation gap of this kind. An organization needs clear third-party risk policies so that accountability runs end to end. It also needs to expect vendors and products to keep changing, so documentation that is an acceptable substitute today may not be next year.

That completes the foundations of AI governance: what AI is, who governs it, and the policies, risks and contracts that govern it across a system's life. Next up: a new domain, and the laws all of this has to satisfy, starting with the privacy laws that applied long before AI arrived.

Remember

  • The defining problem of third-party AI risk is that deployers and users lack full visibility into, and control over, the vendor's system.
  • A third-party AI policy has to reach procurement, the supply chain, human resources, and acceptable use. The organization's own acceptable use policy governs employee behavior, and is a different document from the vendor's.
  • Pre-contract due diligence and ongoing monitoring are both required, calibrated to the system's assigned risk level. A questionnaire before signing does not satisfy the obligation on its own.
  • A vendor's ISO/IEC 42001 certificate attests its management system. The buyer still has to assess the tool in its own context.
  • Audit and information rights give visibility during the relationship and must be negotiated up front. Exit and portability terms govern leaving it, and a breach notification clause with a defined deadline governs being told when something has gone wrong.
  • Depth of diligence should be proportionate to the risk, set by the system's legal effect on people rather than by its cost.

Practise this topic

Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.

Start studying free

Previous: Categories of AI risk, and risk assessment and calculation
Back to the AIGP study guide.

AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.