All case studies

Project 04

AI Vendor Risk Assessment

A due-diligence method extending established third-party risk thinking to AI suppliers.

Purpose

This independent case study extends established third-party risk principles to an AI supplier. The objective is to determine whether the organisation has enough evidence, contractual leverage and operational control to make an informed decision.

Due-diligence domains

Intended use and product boundaries

Document what the product is approved to do, prohibited uses, user groups, dependencies, decision consequence and whether the vendor can change models or subprocessors without notice.

Data and privacy

  • Data categories, purposes, lawful basis and retention.
  • Prompt, output and telemetry use for model training or service improvement.
  • Data locations, transfers, access and deletion verification.
  • DPIA support, data-subject rights and sensitive-data handling.

Security and resilience

  • Access control, encryption, isolation, secure development and vulnerability management.
  • Prompt injection, data leakage, model extraction and abuse protections.
  • Recovery objectives, service dependencies, capacity and exit arrangements.
  • Independent test evidence and timely remediation of material findings.

Model and training transparency

Request model identity and versioning, intended-purpose evidence, evaluation methods, known limitations, training-data governance where applicable, safety measures and meaningful change notices. The level of evidence should be proportionate to the use-case risk.

Supply chain

Map model providers, cloud services, data suppliers, human-review providers and other subcontractors. Concentration and fourth-party dependency can create material exposure even when the direct supplier appears resilient.

Scoring method

| Dimension | Weight | Decision question | |---|---:|---| | Use-case consequence | 20% | What happens if output is wrong, biased, unavailable or misused? | | Data and privacy | 20% | Can data use, access, retention and rights be controlled? | | Security | 15% | Is protection proportionate to threat and sensitivity? | | Model evidence | 15% | Are performance, limits and changes sufficiently transparent? | | Compliance | 10% | Can applicable obligations be evidenced across the value chain? | | Resilience and exit | 10% | Can service failure, concentration and termination be managed? | | Incident cooperation | 10% | Will the supplier detect, notify, investigate and remediate? |

A weighted score informs triage but does not automate approval. A single critical weakness—such as prohibited data use or no incident-notification commitment—can override the aggregate score.

Contract and control requirements

  • Approved-use, data-use and model-training restrictions.
  • Subprocessor transparency and material-change notification.
  • Audit and evidence rights proportionate to risk.
  • Defined security, availability and incident obligations.
  • Assistance with regulatory enquiries, complaints and data rights.
  • Data portability, deletion, continuity and exit support.

Ongoing monitoring

Review material model changes, new subprocessors, service incidents, security posture, control attestations, performance against agreed thresholds and changes in the organisation’s own use. Vendor approval expires unless renewed with current evidence.

Decision principle

The core question is: Can the organisation remain accountable for this AI-enabled service? If essential evidence or leverage is unavailable, the residual risk should be escalated, the use narrowed or the supplier rejected.