For Heads-of · Practitioner
Third-party model and vendor due diligence
Pre-procurement and ongoing due-diligence policy for the selection and contractual oversight of third-party AI models and datasets.
- directive
- vendor-risk
- supply-chain
- policy
What it does
A pre-procurement and ongoing due-diligence policy covering training data provenance, licensing, and update behaviour for any third-party model or dataset.
Where it fits
Directive control: sets the standard vendor onboarding and review must meet before a third-party model or dataset variant is trusted in production.
Risks this mitigates
The risks this control addresses, ranked by effectiveness.
Training data bias and discriminatory outcomes
Historical or sampling bias in training data is reproduced or amplified in model outputs and decisions.
Third-party model and dataset provenance
A model, dataset, or plugin is adopted from an external source without verifying provenance, licensing, or update history.
Inadequate AI vendor due diligence
An AI vendor is onboarded without due diligence proportionate to how material the service is, including its own AI-specific risk controls.
Sub-outsourcing visibility gap
An AI vendor sub-contracts part of the service without the originating organisation having visibility or contractual control over that layer.
Cross-border AI data transfer risk
Personal data processed by an AI system, including via a cloud or model provider, is transferred outside the UK without an adequate transfer mechanism.
LLM application supply chain vulnerabilities
Vulnerable or unvetted components — base models, adapters, datasets, plugins, deployment platforms — enter an LLM application through its supply chain.
Framework and clause references
| Framework | Clause | Title |
|---|---|---|
| EU AI Act | Chapter V | General-purpose AI model obligations |