Managing third-party AI risk
Most organizations will buy far more AI than they build. The risk still lands on them, but the system that creates it belongs to someone else, and they cannot look inside it. The organization stays answerable for outcomes it cannot inspect, and has to build
Why this matters for the exam
Most organizations will buy far more AI than they build. The risk still lands on them, but the system that creates it belongs to someone else, and they cannot look inside it. The organization stays answerable for outcomes it cannot inspect, and has to build that answerability out of contracts and questions instead.
What you need to know
The last topic listed third-party risk as one input to a risk calculation. This one covers that input: where it reaches, what to ask before signing, and which contract terms decide what you can see afterward.
The core problem is visibility
Deployers and users of a third-party AI system usually do not have full visibility or control over it. A vendor's model can change under you, degrade over time, or have been trained on data you would never have approved, and none of it is visible from outside.
That gap creates a need for policies, assessments and contracts that are updated regularly and can adapt as the technology and the regulation move.
Where third-party risk reaches
A third-party AI policy has to cover four areas. Procurement is the one most organizations already have a process for, and the other three are usually gaps.
| Area | What it has to cover |
|---|---|
| Procurement | Screening and vetting a vendor before signature, and the contract terms that follow. |
| Supply chain | The vendors behind your vendor. A supplier's model, training data or infrastructure may come from a fourth party you never assessed and cannot see. |
| Human resources | AI used on your own people: hiring, promotion, performance and monitoring tools, which carry employment-law exposure on top of the usual risk. |
| Acceptable use | What staff may and may not do with AI, including tools the organization never procured. |
Acceptable use is the area with the most routine exposure. An AI acceptable use policy is the organization's own instrument governing how its employees behave. It is a different document from the vendor's acceptable-use policy, which governs how the product may be used. When an employee pastes confidential client text into a public generative AI tool, the acceptable use policy governs it most directly, reinforced by the confidentiality and security policies. No vendor contract covers employee conduct.
Due diligence continues after signature
Vetting a vendor before contract tells you what that vendor claimed at one moment. Ongoing monitoring through the life of the relationship tells you what it is actually delivering. A pre-signing questionnaire on its own does not satisfy third-party risk management, however thorough it was.
Both should be calibrated to the risk level the organization has assigned that system, rather than applied uniformly. In practice the work is:
- Establish a risk level for each third-party AI system in use.
- Adapt existing procurement and vendor-screening processes to cover AI-specific considerations.
- Set internal use policies that complement the vendor's acceptable-use policy rather than duplicating it.
- Work with engineering to maintain testing practices and contingency plans for vendor or model failure.
Vendor certification is easy to over-read. A vendor holding an ISO/IEC 42001 certification has had its management system audited by an accredited third party. The buyer still has to assess the tool in its own context, for its own use case, and the certificate does not discharge the buyer's obligations.
Audit rights and exit terms
The contract is where most of that visibility is secured. Two clause types do different jobs.
| Clause | What it gets you | When it operates |
|---|---|---|
| Audit and information rights | The vendor's performance data, or the right to commission an independent review, even over the vendor's trade-secret objections. | Throughout the relationship. |
| Exit and portability terms | Data return, transition assistance, and protection against lock-in. | Only on leaving. |
Audit and information rights prevent a specific impasse: the customer suspects a vendor's model has degraded, and the vendor refuses to show any performance data. They have to be negotiated before signing, because once a dispute has begun the vendor has no reason to grant them.
A third term belongs alongside them. A breach and incident notification clause with a defined notice deadline obliges the vendor to report a problem within a stated number of days, and to help investigate and remediate it. Without a deadline in the contract, a customer can learn about a vendor-side incident long after it needed to act.
Diligence proportionate to risk
Governance resources are finite, so the depth of due diligence should be proportionate to the risk a use case creates rather than uniform across every tool an organization evaluates.
The system's legal effect on people sets the depth. Take a résumé-screening tool. It shapes who gets access to employment, which nondiscrimination law regulates closely: the EU AI Act classifies AI used in employment and worker management as high-risk under Annex III. It warrants the most rigorous diligence in a procurement portfolio even if it is one of the cheapest tools in it. A high-spend internal system that affects no one directly may warrant much less.
Proportionality governs how deep the diligence goes. Trustworthy-AI principles such as fairness still apply to every system.
Acme, an insurance company, runs its AI program on the NIST AI RMF and an insurance-sector set of AI principles. Acme's policy requires supporting documentation whenever it buys a product with AI in it.
Alecia, Acme's assistant chief AI officer, is asked to fast-track the purchase of a third-party platform called Diaspro. She requests documentation of Diaspro's model development and fine-tuning practices. Diaspro will not provide it. Instead it offers contract warranties, indemnification, and last year's third-party audit results, while withholding the underlying audit work papers as confidential. Alecia does not believe any regulation specifically requires Diaspro to hand over what she asked for. Her question is whether what is on offer is sufficient for Acme.
This is not Alecia's call to make alone. Acme's own AI governance policy should already say who has authority to accept a documentation gap of this kind. An organization needs clear third-party risk policies so that accountability runs end to end. It also needs to expect vendors and products to keep changing, so documentation that is an acceptable substitute today may not be next year.
That completes the foundations of AI governance: what AI is, who governs it, and the policies, risks and contracts that govern it across a system's life. Next up: a new domain, and the laws all of this has to satisfy, starting with the privacy laws that applied long before AI arrived.
Remember
- The defining problem of third-party AI risk is that deployers and users lack full visibility into, and control over, the vendor's system.
- A third-party AI policy has to reach procurement, the supply chain, human resources, and acceptable use. The organization's own acceptable use policy governs employee behavior, and is a different document from the vendor's.
- Pre-contract due diligence and ongoing monitoring are both required, calibrated to the system's assigned risk level. A questionnaire before signing does not satisfy the obligation on its own.
- A vendor's ISO/IEC 42001 certificate attests its management system. The buyer still has to assess the tool in its own context.
- Audit and information rights give visibility during the relationship and must be negotiated up front. Exit and portability terms govern leaving it, and a breach notification clause with a defined deadline governs being told when something has gone wrong.
- Depth of diligence should be proportionate to the risk, set by the system's legal effect on people rather than by its cost.
Practise this topic
Domain I is free in the app, including its practice questions and flashcards, with progress tracking and no card details.
Previous: Categories of AI risk, and risk assessment and calculation
Back to the AIGP study guide.
AI Governance Study is an independent study aid. It does not represent a government entity: it is not affiliated with, endorsed by or authorised by any government, government agency or regulatory authority, and it does not provide government services or legal advice. Laws and frameworks are described in our own words — the official texts are listed at official sources. It is also not affiliated with, endorsed by, or sponsored by the IAPP. The AIGP name is used only to identify the exam this material helps you prepare for.